Method and network node for radio frequency fingerprinting- based authentication for single UE with multiple transceivers
The method addresses the challenge of authenticating UEs with multiple transceivers by employing multiple network nodes with diverse transceivers, ensuring secure and efficient authentication through context-aware resource optimization.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
- Filing Date
- 2024-11-08
- Publication Date
- 2026-05-15
AI Technical Summary
Existing Radio Frequency Fingerprinting (RFF) authentication methods primarily focus on single UE single-transmitter scenarios, failing to address UEs with multiple transceivers and network nodes with multiple receivers, which are common in practice.
A method involving multiple network nodes with transceivers operating on different radio access technologies or frequency bands perform RFF authentication on multiple transceivers of a UE, utilizing context awareness and network resource optimization to ensure secure and efficient authentication.
This approach enhances security and resource efficiency by requiring attackers to replicate multiple RFF data across various transceivers, reducing the likelihood of unauthorized access and optimizing network resource utilization.
Smart Images

Figure EP2024081699_15052026_PF_FP_ABST
Abstract
Description
P109253W0011The project leading to this application has received funding from the European Union's Horizon 2020 research and innovation program under grant agreement No 101092598.METHOD AND NETWORK NODE FOR RADIO FREQUENCY FINGERPRINTINGBASED A UTHENTICA TION FOR SINGLE UE WITH MUL TIPLE TRANSCEIVERSTechnical Field
[0001] The present disclosure relates to a method and a network node that performs Radio Frequency Fingerprinting authentication of a User Equipment that has multiple transceivers in a wireless communication system.Background
[0002] Hardware imperfections in a wireless communication device can introduce distortions and errors in a transmitted signal, which can cause the constellation of the transmitted signal to deviate from the ideal shape. For example, imperfections in the transmit or receive filters can cause frequency-dependent distortions in the signal, which can cause the constellation to become skewed or tilted. Similarly, imperfections in the analog-to-digital converter (ADC) or digital-to-analog converter (DAC) can cause quantization errors, which can cause the constellation to become distorted or irregular. Moreover, nonlinearities in the amplifiers or mixers can cause intermodulation distortion, which can introduce additional unwanted signals in the spectrum of the transmitted signal.
[0003] Hardware designers try to mitigate hardware imperfections using many different techniques in transmitters such as digital predistortion (DPD), post-distortion, interference cancellation circuits, dynamic biasing of amplification elements, etc. However, even with a lot of care and resources, it is impossible to mitigate all these imperfections in transmitters. They are also unique and vary from one transmitter to another, impacted by (and not limited to) circuits architectures, implementation, technology, etc. Operating conditions, temperature of operation, aging, as well as memory effects in the circuit are also sources of unique hardware impairments.
[0004] The Radio Frequency Fingerprinting (RFF) technique has recently emerged as a promising technique for Physical Layer Security (PLS) for Fifth Generation (5G) New Radio (NR) and beyond. The concept of RFF is to exploit these unique hardwareP109253W0012 impairments in transmitters to identify and authenticate radio equipment, such as (and not limited to) User Equipment devices (UEs) and network nodes, to increase the trustworthiness and security of telecommunications.
[0005] The basic concept of RFF has been known for some time, but the use of machine learning algorithms for automated RFF recognition is a more recent development. Once the machine learning model (typically operating inside a network node or even a wireless access point) has been trained, the unique fingerprint for each UE is stored in a database. During the inference phase, when a UE transmits a signal, the I / Q samples from the transmitted signal are then fed into the machine learning model, which compares them to the stored fingerprints in the database to determine the identity of the UE.
[0006] In this technical field, the focus has mostly been oriented towards identifying and authenticating a UE composed of a single radio transmitter (generally a software defined radio, in existing work) with the help of a single receiver device (also generally a software defined radio). Most of the focus is also directed towards improvement of the associated algorithms. This scenario is somewhat simplistic and could be improved further.
[0007] An object of the invention is to improve Radio Frequency Fingerprinting (RFF) authentication of a User Equipment device (UE) comprising multiple transceivers at one or more network nodes of a Radio Access Network.
[0008] The present disclosure provides a method for RFF authentication of a UE where the method includes selecting a first network node to perform a first RFF authentication on one or more transceivers of the UE. The method also includes selecting at least one second network node to perform a second RFF authentication on a different transceiver of the UE, wherein the first RFF authentication and the second RFF authentication comprises instructing the one or more first or second network nodes to transmit to the UE values for a set of parameters for acquisition of a Radio Frequency (RF) fingerprint for the UE, the RF fingerprint comprising data characterizing RF impairments induced by specific hardware of the UE on a signal received or transmitted by the UE, the RF impairments being unique to the UE, wherein the one or more first or second network nodes comprise a plurality of transceivers operating according toP109253W0013 different radio access technologies or operating in different frequency bands, wherein the plurality of transceivers of the first or second network nodes correspond to transceivers of the UE. The method includes receiving responses to RFF authentication from the first network node and the at least one second network node selected and granting network access to the UE when a result of the RFF authentication for all the plurality of transceivers of the UE is positive.
[0009] In an embodiment, the method includes selecting the first network node and the at least one second network node from a first group of network nodes based on a position of the UE in relation to the first network node and in relation to the second network node, and selecting the first and second network node such that they comprise transceivers operating according to wireless communication standards that correspond to those of the plurality of transceivers of the UE.
[0010] In an embodiment, the method further includes selecting the first network node and the at least one second network node from a second group of network nodes that have available network resources to perform RFF authentication.
[0011] In an embodiment, the method includes providing, to the selected first network node and the at least one second selected network node, an allocation of network resources to perform the RFF authentication.
[0012] In an embodiment, the method includes identifying the types of Radio Access Network technologies applying to the plurality of transceivers of the UE.
[0013] In an embodiment, selecting the first network node and selecting the at least one second network node is in response to determining that the UE has not already been RFF authenticated.
[0014] In an embodiment, the method includes performing a radio access network level Machine Learning (ML) training and inference RFF authentication based on standalone network node ML inference RFF authentications from each of the first network node and the at least one second network node, wherein the standalone network node ML inference RFF authentications are based on standalone transceiver ML inference RFF authentication from each transceiver of the plurality of transceivers associated with the first network node and the at least one second network node.
[0015] In an embodiment, a network node is provided for performing RFF authentication of a UE. The network node includes a processor configured to cause the network node to select a first network node to perform a first RFF authentication on oneP109253W0014 or more transceivers of the UE. The processor also causes the network node to select at least one second network node to perform a second RFF authentication on a different transceiver of the UE, wherein the first RFF authentication and the second RFF authentication comprises instructing the one or more first or second network nodes to transmit to the UE values for a set of parameters for acquisition of a Radio Frequency (RF) fingerprint for the UE, the RF fingerprint comprising data characterizing RF impairments induced by specific hardware of the UE on a signal received or transmitted by the UE, the RF impairments being unique to the UE, wherein the one or more first or second network nodes comprise a plurality of transceivers operating according to different radio access technologies or operating in different frequency bands, wherein the plurality of transceivers of the first or second network nodes correspond to a plurality of transceivers of the UE. The processor also causes the network node to receive responses to RFF authentication from the first network node and the at least one second network node selected and grant network access to the UE when a result of the RFF authentication for all the plurality of transceivers of the UE is positive.
[0016] In an embodiment, a computer program comprising instructions which, when executed on at least one processor, cause the processor to carry out the method according to any of the methods and embodiments above. In an embodiment, a carrier is provided that contains the computer program of , wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a memory.
[0017] An advantage of the techniques disclosed herein is that the methods enable a flexible and scalable solution where it is possible to apply these methods regardless of the number of chipsets and transceivers embedded in a UE and network nodes with a number of embedded transceivers. Context awareness can also be improved, where the relative positioning information of the UE with respect to a network node as well as the network capacity and resources availability can be considered to tailor the methods to the RAN specific needs at any time. Also, network resources can be utilized in an energy efficient way in order to perform Radio Frequency Fingerprinting on a UE, since network nodes which are nearest to the UE can use less transmit power to perform RF fingerprinting of the UE than if a random first and second network node were selected. By the same token, the UE itself can conserve battery life since it can transmit its response to the RF fingerprinting inquiry from the first and second network node with less transmit power than if the first and second network nodes were selected randomly.P109253W0015One further advantage of the present solution is that the use of network resources during RF fingerprinting can be reduced compared to the situation where the selection of the first and second network nodes for RF fingerprinting would be random.
[0018] Another advantage is the improved security, where formerly it may have been possible for an attacker with enough motivation to replicate the RFF data of one transceiver and break classical RFF-based authentication methods. Now, however, it is extremely unlikely that an attacker could break the proposed method, as the attacker would need to replicate a plurality of RFF data to break several RFF-based authentications at the same time. This would also require an extensive amount of additional hardware. Furthermore, the attacker would need a lot of different transceivers at different frequencies and standards in order to characterize all the transceivers simultaneously. The techniques also enable the association of a device ID with multiple embedded chipsets having their own RFF data which offers more security and flexibility than just associating one transceiver RFF data to a device. This is compatible with existing UE and network node hardware as well as specific enhanced hardware for RFF purposes.Brief Description of the Drawings
[0019] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.
[0020] Figure 1 illustrates an example of a wireless communication system in which the methods disclosed herein can be performed according to some embodiments of the present disclosure;
[0021] Figure 2 illustrates a flowchart of the method for performing Radio Frequency Fingerprinting (RFF) authentication of a User Equipment (UE) according to some embodiments of the present disclosure;
[0022] Figure 3 illustrates a flowchart of a method for an initial exchange between the UE and the network node according to some embodiments of the present disclosure;
[0023] Figure 4 illustrates a flowchart of a method for determining hardware and positioning according to some embodiments of the present disclosure;P109253W0016
[0024] Figure 5 illustrates a flowchart of a method for network node selection according to some embodiments of the present disclosure;
[0025] Figure 6 illustrates a flowchart of a method for RFF authentication according to some embodiments of the present disclosure;
[0026] Figure 7 illustrates a flowchart of a method for granting network access according to some embodiments of the present disclosure;
[0027] Figure 8 illustrates one example of a cellular communications system according to some embodiments of the present disclosure;
[0028] Figure 9 is a schematic block diagram of a network node according to some embodiments of the present disclosure;
[0029] Figure 10 is a schematic block diagram that illustrates a virtualized embodiment of the network node of Figure 9 according to some embodiments of the present disclosure; and
[0030] Figure 11 is a schematic block diagram of the network node of Figure 9 according to some other embodiments of the present disclosure.Detailed Description
[0031] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, those skilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein. It should be understood that these concepts and applications fall within the scope of the disclosure.
[0032] In the following, definitions are given to terms appearing throughout the description and the claims. One such term is network node.As used herein, a "network node" is any node in a Radio Access Network (RAN) of a wireless communications network that operates to wirelessly transmit and / or receive signals or any type of node in a core network or any node that implements a core network function. Some examples of a network node include, but are not limited to, a base station (e.g., a New Radio (NR) base station (gNB) in a Third Generation Partnership Project (3GPP) Fifth Generation (5G) NR network or an enhanced or evolved Node B (eNB) in a 3GPP Long Term Evolution (LTE) network), a Wi-Fi access point, a high-power or macro baseP109253W0017 station, a low-power base station (e.g., a micro base station, a pico base station, a home eNB, or the like), a relay node, a network node that implements part of the functionality of a base station or a network node that implements a gNB Distributed Unit (gNB-DU)) or a network node that implements part of the functionality of some other type of radio access node.
[0033] Another such term is user equipment (UE):One type of UE is a wireless communication device, which may be any type of wireless device that has access to (i.e., is served by) a wireless communications network (e.g., a cellular network, Wi-Fi, etc.) and which has the ability to communicate with other UEs and network nodes in such a wireless communication network. Some examples of a UE include but are not limited to: a wireless device in a 3GPP network, a Machine Type Communication (MTC) device, and an Internet of Things (loT) device. Such UEs may be, or may be integrated into, a mobile phone, smart phone, sensor device, meter, vehicle, household appliance, medical appliance, media player, camera, or any type of consumer electronic device, for instance, but not limited to, a television, radio, lighting arrangement, tablet computer, laptop, or PC. The UE may be a portable, hand-held, computer-comprised, or vehiclemounted mobile device, enabled to communicate voice and / or data via a wireless connection.
[0034] Note that, in the description herein, reference may be made to the term "cell"; however, particularly with respect to 5G NR concepts, beams may be used instead of cells and, as such, it is important to note that the concepts described herein are equally applicable to both cells and beams.
[0035] Some of the challenges for Radio Frequency (RF) Fingerprinting (RFF) authentication of UEs are that the current techniques focus on a single UE singletransmitter network node and on single receiver scenarios that occur in real network implementations. However, UEs with multiple transceivers and networks with multiple network nodes are far more common in practice. Indeed, devices and network nodes (base-stations, routers, enb, gnb etc.) are complex and composed of several radio elements using different standards, freq uency_ba nds and applications. For example, a cell phone does not only contain a WIFI radio, but also a cellular chipset for sub-6GHz frequencies, a 5G chipset for millimeter wave (mmW) frequencies, a Bluetooth chipset, etc. A radio access network may be comprised of a number of different types of network node equipment, such as sub-6GHz base stations, mm wave base stations,P109253W0018WIFI routers, radio dots, etc. To the inventor's knowledge, there is no work proposing to perform RFF-based authentication in the context of a device containing more than one radio transmitter and a RAN with multiple receivers for multiple frequencies, standards, etc.
[0036] The present disclosure provides for an RFF-based authentication method capable of using multiple network nodes (based on context awareness) containing multiple transceivers serving a plurality of wireless communication standards to authenticate a device containing a plurality of transceivers serving a plurality of wireless communication standards. The method disclosed herein includes selecting a first network node to perform a first RFF authentication on one or more transceivers of the UE. The method also includes selecting at least one second network node to perform a second RFF authentication on a different transceiver of the UE, wherein the first RFF authentication and the second RFF authentication comprises instructing the one or more first or second network nodes to transmit to the UE values for a set of parameters for acquisition of a Radio Frequency (RF) fingerprint for the UE the RF fingerprint comprising data characterizing RF impairments induced by specific hardware of the UE on a signal received or transmitted by the UE, the RF impairments being unique to the UE, wherein the one or more first or second network nodes comprise a plurality of transceivers operating according to different radio access technologies or operating in different frequency bands, wherein the plurality of transceivers of the first or second network nodes correspond to transceivers of the UE. The method includes receiving responses to RFF authentication from the first network node and the at least one second network node selected and granting network access to the UE when a result of the RFF authentication for all the plurality of transceivers of the UE is positive.
[0037] Figure 1 illustrates an example of a wireless communications system in which the methods disclosed herein can be performed according to some embodiments of the present disclosure.
[0038] The UE 102 in this embodiment includes a plurality of transceivers 104-1, 104-2, and 104-3 (which collectively can be referred to as transceivers 104) where each of the transceivers 104 uses a different wireless communication standard or frequency. For example, transceiver 104-1 may be an NR associated transceiver, transceiver 104-2 an LTE transceiver, and transceiver 104-3 a WiFi associated transceiver. Other combinations of transceivers implementing other wireless communication standards areP109253W0019 also possible. In another embodiment, transceiver 104-1 may be a sub-6Ghz transceiver, transceiver 104-2 a mm wave transceiver, while transceiver 104-3 may be a WiFi-associated transceiver. In another exemplary embodiment, the transceiver 104-1 may be a sub-6Ghz transceiver operating in the Low Band, while transceiver 104-2 may be a sub-6Ghz transceiver operating in the High Band, while transceiver 104-3 may be a WiFi-associated transceiver. In other embodiments, the transceivers 104-1, 104-2, and / or 104-3 may be transceivers operating in the same band with the same wireless communication standard. Each transceiver 104 can include a transmitter, a receiver, an antenna, or a plurality of other elements such as a CPU, a display or any other additional element not illustrated.
[0039] The network nodes 106-1, 106-2, and 900 can be part of a radio access network (RAN) 105. Each network node 106-1 and 106-2 includes one or more transceivers (e.g. transceivers 108-1, 108-2, 108-3) to provide wireless communication according to a plurality of standards, including for example, NR, LTE, WiFi or other standards.
[0040] In an embodiment, each of the network nodes 106-1, 106-2, and 900, can include a Machine learning engine (MLE) 110-3, 110-5, and 110-6 for training and inference purposes. Each of the transceivers, 108-1, 108-2, and 108-3 can also include respective MLEs 110-1, 110-2, and 110-4.
[0041] With the transceivers included in the network nodes, it is possible to perform several standalone RFF-based authentication methods and apply the proposed method described in the associated flowcharts. For example, transceiver 108-1 in network node 106-1 can perform RFF-based authentication of transceiver 104-1 in UE 102, transceiver 108-2 in network node 106-1 can perform RFF-based authentication of transceiver 104- 2 in UE 102, and transceiver 108-3 in network node 106-2 can perform RFF-based authentication of transceiver 104-3 in UE 102.
[0042] It is to be appreciated that in the scenario depicted in Fig. 1 where UE 102 includes three transceivers operating according to different wireless communication standards, the network node 106-1 including two transceivers and network node 106-2 including one transceiver merely serves as an illustrative example. In other embodiments, the UE can include two or more transceivers and a single network node with two or more transceivers may be present.P109253W00110
[0043] In an embodiment, network node 900 can be another RAN node just like network nodes 106-1 and 106-2. Network node 900 can also be a core network node in other embodiments.
[0044] Figure 2 illustrates a flowchart of the method for performing Radio Frequency Fingerprinting (RFF) authentication of a User Equipment (UE) according to some embodiments of the present disclosure. Each of the steps 202, 206, 208, 210, and 212 of the method in Figure 2 comprises additional steps described in Figures 3, 4, 5, 6, and 7 respectively.
[0045] It is to be appreciated that in the present disclosure, when reference is made to the "network" or the RAN 105 performing one or more of the following steps in the methods depicted in Figures 2-7, any of network nodes 106-1, 106-2, or 900 can perform all or part of the steps of the methods.
[0046] At step 202, there is an initial exchange between the UE 102 and a RAN node 112 that is part of the same wireless communication network as network node 900. In an embodiment, RAN node 112 can be a separate radio access network node, and in other embodiments, RAN node 112 can be one of network nodes 106-1 or 106-2.
[0047] At step 204, if the UE 102 has already been authenticated or authenticated within a defined time period, which is checked in a communication between the RAN node 112 in which coverage area the UE is currently located and the network node 900, the UE 102 is granted access to the network.
[0048] If the UE 102 is not already authenticated, however, at step 206, the network can determine information about the hardware (e.g., types of transceivers and associated standards) of the UE 102, as well as the position or location of the UE 102. This can be done either directly by the RAN node 112 that the UE 102 attempts to connect to or by a communication between the RAN node 112 and the network node 900. The stored RF fingerprints for the UE 102 may, depending on the implementation, be either stored in the network node 900, the RAN node 112 or some other part of the network, which the RAN node 112 is able to communicate with.
[0049] At step 208, the network, based on the information gathered in step 206can select the network nodes (e.g., 106-1 and 106-2) to perform RFF authentication of the UE 102. This step can also include the additional selection criterion that the network nodes selected to be performing the RFF authentication of the UE 102 have sufficient network resources available to perform RFF authentication. Network nodes, such as theP109253W00111 network nodes 106-1 and 106-2 usually perform a host of other actions that require specific resources, such as network scheduling, signaling, power control and, of course, data information transmission and reception. Thus, it is not certain there are always network resources available for performing RFF authentication of a UE. In an embodiment, the selection step 208 includes a step 208-1 of selecting the first network node 106-1, and a second step 208-2 of selecting the second network node 106-2. Step 208-1 includes selecting a first network node 106-1 to perform a first RFF authentication on one or more transceivers 104-1, 104-2 of the UE 102. Step 208-2 includes selecting at least one second network node 106-2 to perform a second RFF authentication on a different transceiver 104-3 of the UE 102, wherein the first RFF authentication and the second RFF authentication comprise instructing the one or more first or second network nodes 106-1 and 106-2 to transmit to the UE 102 values for a set of parameters for acquisition of a Radio Frequency, RF, fingerprint for the UE 102, the RF fingerprint comprising data characterizing RF impairments induced by specific hardware of the UE 102 on a signal received or transmitted by the UE 102, the RF impairments being unique to the UE 802, wherein the one or more first or second network nodes 106-1 and 106-2 comprise a plurality of transceivers 108-1, 108-2, and 108-3 operating according to different wireless communication standards or operating in different frequency bands, wherein the plurality of transceivers 108-1, 108-2, and 108-3 of the first and second network nodes 106-1 or 106-2 correspond to transceivers 104-1, 104-2, and 104-3 of the UE 102.
[0050] At step 210, the method includes receiving responses to the RFF authentication performed by the network nodes 106-1 and 106-2, and then at step 212, the method includes granting network access to the UE 102 based on the responses to the RFF authentication being positive for both network nodes 106-1, 106-2.
[0051] Figure 3 illustrates a flowchart of a method for an initial exchange between the UE and the network node according to some embodiments of the present disclosure.
[0052] The method step 202 can further include additional steps depicted in Figure 3. For example, at step 302, the UE 102 can request a connection to the RAN 105 through RAN node 112, which can be a separate radio access network node in RAN 105 or more of network nodes 106-1 or 106-2.P109253W00112
[0053] At step 304, the RAN node 112 of the RAN 105 can determine if the UE 102 has already been authorized or authenticated at the network. In one embodiment, the RAN node 112 may have performed the authentication itself, and a record or indication of the authentication may be stored at the RAN node 112. In other embodiments, the RAN node 112 can inquire with the network node 900 about whether the UE 102 has been authorized or authenticated. An authentication can expire after a predetermined length of time or if one or more contextual variables of the RFF authentication change. If the UE 102 is determined to already have been authenticated during that length of time or during the contextual change of the one or more variables, the method can stop via step 204. If at step 306 it is determined that the UE 102 has not been authenticated, RAN 105 can request that the UE be authenticated by an RFF-based method.
[0054] Figure 4 illustrates a flowchart of a method for determining hardware and positioning according to some embodiments of the present disclosure.
[0055] The method step 206 may further include additional optional steps depicted in Figure 4.
[0056] At step 402, the RAN 105 detects the UE-embedded hardware and associated transmitters by any known means. In other words, the RAN 105 detects the types of radio transceivers or radio chipsets that are embedded in the UE (e.g. Sub-6GHz radio chipset, mmW radio chipset, WIFI radio chipset).
[0057] Once this is performed, at step 404, the RAN 105 estimates the UE positioning. It can be done by estimating the UE relative position to the network node through which the UE requested access to the RAN. The position can be estimated by any technical means such as angle of arrival data (AoA), time of arrival data (ToA), joint communication and sensing (JCAS), etc.
[0058] It is worth noting that the positioning of the UE could be used for other security purposes, for example, to verify that the UE is at a relevant geographic area. Once this step is performed, the method continues then towards the next step described in Figure 5 In an example case the UE to be RFF authenticated may be determined to have appeared recently at an entirely different part of the network not including any of the network nodes 106-1, 106-2, 112 or 900. This may be an event determined by the network node 112 or network node 900 to be an abnormal event and potentially flagged by the network node. Another example would be the situation whereP109253W00113 network node 112 or network node 900 have determined that the UE has already been RFF authenticated, but has recently been located in an entirely different part of the network not served by any of the network nodes 106-1, 106-2, 122 or 900, which may also be determined to be an abnormal event and potentially flagged.
[0059] Figure 5 illustrates a flowchart of a method for network node selection according to some embodiments of the present disclosure.
[0060] The method at steps 208, 208-1, and 208-2 can further include additional optional steps depicted in Figure 5 by means of dashed lines.
[0061] For example, at step 502, the RAN 105 defines the network nodes 106-1 and 106-2 in the vicinity of the UE 102 that could be selected for RFF-based authentication of the UE 102 based on UE 102 positioning estimation data.
[0062] At step 504, the RAN 105 refines the network node selection by selecting the transceivers 108-1, 108-2, and 108-3 embedded in the selected network nodes 106-1 and 106-2 that are compatible or otherwise operate according to a wireless communication standard or frequency that corresponds with the transceivers 104-1, 104-2, and 104-3 embedded in the UE 102. For example, one network node can have a sub-6GHz receiver capable of performing RFF-based authentication of the sub-6GHz transmitter embedded in the UE. Another network node could contain a mmW receiver capable of performing RFF-based authentication of the mmW transmitter contained in the UE 102.
[0063] At step 506, a test is then performed to determine if the selected network nodes 106-1 and 106-2 and selected embedded transceivers 108-1, 108-2, and 108-3 for RFF-based authentication are available. Causes for non-availability could be related to capacity or other technical limitations. For example, the mmW transmitter of a selected network node could already serve many UEs and then not have enough capability to perform the requested RFF-based authentication.
[0064] If one or several network nodes and / or embedded transceivers are not available, the RAN 105 refines the selection depending on the network operation needs at step 508. For example, if a selected mmW transmitter in a selected network node is close to its maximum capacity threshold it will then be excluded from the selection and another mmW transceiver in the same or another network nodes may be selected instead.P109253W00114
[0065] Once the resources selected are available, the RAN 105 confirms the network nodes 106-1 and 106-2 and the embedded transceivers 108-1, 108-2, and 108-3 for performing RFF-based authentication in step 510.
[0066] At step 512, the RAN 105 allocates these resources to perform the UE RFF- based authentication described in Figure 6.
[0067] Figure 6 illustrates a flowchart of a method for RFF authentication according to some embodiments of the present disclosure.
[0068] The method step 210 may further include additional optional steps depicted in Figure 6.
[0069] At step 602, each transceiver 108-1, 108-2, and 108-3 of network nodes 106- 1 and 106-2 performs standalone active RFF authentication. Standalone RFF authentication, as referred to herein, means that each of the network nodes 106-1 and 106-2 performs an RFF authentication of communications received from the corresponding transceivers 104-1, 104-2, and 104-3 from the UE 102 at each of the network nodes 106-1 and 106-2 independent of each other. Similarly, one or more of transceivers 108-1, 108-2 and 108-3, can perform RFF authentication of communications received from the corresponding transceivers 104-1, 104-2, and 104-3 from the UE 102 at each transceiver 108-1, 108-2, and 108-3 separately from each other. Each allocated transceiver (108-1, 108-2, and 108-3) in each allocated network node (106-1 or 106-2) will perform a standalone active RFF-based authentication on the corresponding transceiver (104-1, 104-2, and 104-3) contained within the UE 102. For example, a network node containing a sub-6GHz TRX will perform an active RFF-based authentication on a sub-6GHz transmitter included in the UE. For this purpose, any known active RFF-based authentication method can be used.
[0070] As all the allocated network nodes and embedded transceivers will perform active standalone RFF-based authentication methods, the set of instructions requested by the network nodes to the UE 102 in these methods can differ one from each other. Accordingly, each of the allocated network nodes or transceivers can generate or identify different fingerprints from different transceivers 104-1, 104-2, and 104-3 from the UE 102, making it nearly impossible for an attacker to replicate. In this step, classical local ML inference can also be performed at the level of each allocated embedded transceiver in each allocated network node by respective ML engines 110-1, 110-2, and 110-4. In addition, in an embodiment, ML engines 110-3 and 110-5 at eachP109253W00115 network node 106-1 and 106-2 can also perform a respective ML inference for each network node at step 606. At step 608, the RAN 105 can perform a global inference at the RAN level (e.g., by ML engine 110-6 at network node 900). The step 608 can include performing a radio access network level ML training and inference RFF authentication based on standalone network node ML inference RFF authentications from each of the first network node 106-1 and the at least one second network node 106-2, wherein the standalone network node ML inference RFF authentications are based on standalone transceiver ML inference RFF authentication from each transceiver 108-1, 108-2, 108-3 of the plurality of transceivers 108 associated with the first network node 106-1 and the at least one second network node 106-2.
[0071] All RFF data are saved to a database 604 which be used by the RAN 105 for other purposes such as ML training.
[0072] Each of the successive inference steps in steps 602, 606, and 608 can be described as collaborative inference. While Figure 6 describes 3 different levels of ML inferences, this could be adapted to different layers of ML inference. For example, if each individual transceiver in each network node does not possess the capability of performing ML inference (e.g. if no ML capabilities), then the ML inference of step 602 could be skipped and performed at a higher level in the corresponding network node in step 606.
[0073] Figure 7 illustrates a flowchart of a method for granting network access according to some embodiments of the present disclosure.
[0074] The method step 212 can further include additional optional steps depicted in Figure 7.
[0075] At step 702, the method includes making a decision about whether the UE 102 is authenticated based on the authentication of multiple UE 102 transceivers 104-1, 104-2, and 104-3 by the transceivers 108-1, 108-2, and 108-3 at network nodes 106-1 and 1062.
[0076] At step 704, if the results of all the UE authentication are positive, the flowchart proceeds to step 706, where the RAN 105 shares UE connection authorization settings with the UE 102. If the results of some or all of the UE authentications are negative, however, the flowchart proceeds to step 708, and the RAN 105 shares the UE connection rejection settings with the UE 102. At 710, the network node connected to the UE 102 or the network node that received the connection request from the UE 102,P109253W00116 either network node 106-1, 106-2, or 900 then applies the settings to the connection with the UE 102..
[0077] The following example described herein is how the method from Figures 2-7 could be applied to a scenario where a UE is attempting to request a connection to a RAN.
[0078] The UE requests a connection to the RAN, for example using a Sub-6GHz transceiver to connect to RAN node 112.
[0079] RAN node 112 determines that the UE was not previously authenticated by the RAN node 112, and also sends an inquiry message to network node 900 to determine if the UE 102 was authenticated by network node 900 or elsewhere in the RAN. In this example, the UE was not already authenticated by any network node in the RAN and thus the RAN requests an RFF-based authentication of the UE.
[0080] The RAN identifies the different radio chipsets and transceivers embedded in the UE: a Sub-6GHz TRX, a mmW TRX and a WIFI TRX.
[0081] The RAN then estimates the position of the UE with respect to the position of network node 1, the network node which the UE request connection to. For this purpose, it can use AoA, ToA or even JCAS methods.
[0082] The RAN determines that an additional network node 2 is in the vicinity of the UE and network node 1 and is selected to be used for RFF-based authentication.
[0083] The RAN determines that network node 1 contains a Sub-6GHz TRX and a mmW TRX compatible with the corresponding UE embedded HW and is able to perform RFF based authentication. Network node 2 contains a WIFI TRX compatible with the WIFI capabilities of the UE. It then selects these resources for RFF-based authentication.
[0084] The RAN then verifies if the resources selected are available for RFF-based authentication. In this case there is no problem with the capacity on the network, so the resources are available.
[0085] The RAN then confirms the selection and allocates these resources for RFF- based authentication.
[0086] Each transceiver in each network node will then perform a standalone RFF- based authentication method on the corresponding UE embedded transceivers.
[0087] It means that the Sub-6GHz transceiver in network node 1 performs an RFF- based authentication method on the Sub-6GHz transceiver embedded in the UE. For thisP109253W00117 purpose, it can use any known method of active RFF-based authentication with a proper set of instructions requested by network node 1 for UE to apply. In parallel, the mmW transceiver contained in network node 1 will perform another standalone RFF-based authentication on the mmW transceiver contained in the UE. It can use the same method as at Sub-6GHz or a different one, and it can use a different set of instructions. Finally, the WIFI TRX in network node 2 also performs an RFF-based authentication method in parallel, this time on the WIFI TRX embedded in the UE. All RFF data are stored in a database for further utilization such as additional training of ML models.
[0088] As all these TRX have ML capabilities integrated, local inference can be run on each of the transceivers, it defines the trustworthiness of each transceiver embedded in the UE at an individual level. Then inference is run at network node level for both network node 1 and network node 2 in parallel.
[0089] Finally, a last step of ML inference is performed by the RAN. At this point it is possible to know the trustworthiness of the UE embedded HW and take a decision for the connection request. For example, if the Sub-6GHz transceiver is defined as trustworthy, the mmW transceiver is defined as untrustworthy and the WIFI transceiver is untrustworthy, then the RAN sees the combination of these transceivers (i.e. the UE) as untrustworthy and then communicates to network node 1 to reject the connection. Network node 1 executes instructions and the UE request is rejected, and the UE reported.
[0090] In this case, it means that the UE has potentially been impersonated by an attacker, with enough resources, that duplicated the RFF data for simple RFF-based authentication methods and tried to connect to network node 1 through the Sub-6GHz standards. In a classic RFF-based authentication method, as the Sub-6GHz data authentication would seem trustworthy the connection could have been authorized. By using the techniques disclosed herein, it is possible to identify the other transceivers as untrustworthy and thus reject the malicious connection. It is extremely unlikely that the attacker would be able to duplicate all the necessary RFF data to dupe all RFF-based authentication methods on all the transceivers.
[0091] Figure 8 illustrates one example of a wireless communications network 800 in which embodiments of the present disclosure may be implemented. In the embodiments described herein, the cellular communications system 800 can be a 5G system (5GS) including a Next Generation RAN (NG-RAN) and a 5G Core (5GC) or anP109253W00118Evolved Packet System (EPS) including an Evolved Universal Terrestrial RAN (E-UTRAN) and an Evolved Packet Core (EPC). In this example, the RAN includes base stations 802-1 and 802-2, which in the 5GS include NR base stations (gNBs) and optionally next generation eNBs (ng-eNBs) (e.g., LTE RAN nodes connected to the 5GC) and in the EPS include eNBs, controlling corresponding (macro) cells 804-1 and 804-2. The base stations 802-1 and 802-2 are generally referred to herein collectively as base stations 802 and individually as base station 802. Likewise, the (macro) cells 804-1 and 804-2 are generally referred to herein collectively as (macro) cells 804 and individually as (macro) cell 804. The RAN may also include a number of low power nodes 806-1 through 806-4 controlling corresponding small cells 808-1 through 808-4. The low power nodes 806-1 through 806-4 can be small base stations (such as pico or femto base stations) or RRHs, or the like. Notably, while not illustrated, one or more of the small cells 808-1 through 808-4 may alternatively be provided by the base stations 802. The low power nodes 806-1 through 806-4 are generally referred to herein collectively as low power nodes 806 and individually as low power node 806. Likewise, the small cells 808-1 through 808-4 are generally referred to herein collectively as small cells 808 and individually as small cell 808. The cellular communications system 800 also includes a core network 810, which in the 5G System (5GS) is referred to as the 5GC. The base stations 802 (and optionally the low power nodes 806) are connected to the core network 810.
[0092] The lower power nodes 806-1 to 806-4 and base stations 802-1 to 802-2 can be examples of the network nodes 106-1 to 106-3 as well as network node 900 and perform the same functionality as described herein. The wireless communications devices 812-1 to 812-5 can be examples of the UE 102 as described above.
[0093] The base stations 802 and the low power nodes 806 provide service to wireless communication devices 812-1 through 812-5 in the corresponding cells 804 and 808. The wireless communication devices 812-1 through 812-5 are generally referred to herein collectively as wireless communication devices 812 and individually as wireless communication device 812. In the following description, the wireless communication devices 812 are oftentimes UEs, but the present disclosure is not limited thereto.
[0094] Figure 9 is a schematic block diagram of a network node 900 according to some embodiments of the present disclosure. Optional features are represented by dashed boxes. The network node 900 may be, for example, a base station 802 or 806P109253W00119 or a network node that implements all or part of the functionality of the base station 802 or gNB described herein including network nodes 106-1 and 106-2. As illustrated, the network node 900 includes a control system 902 that includes one or more processors 904 (e.g., Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), memory 906, and a network interface 908. The one or more processors 904 are also referred to herein as processing circuitry. In addition, the network node 900 may include one or more radio units 910 that each include one or more transmitters 912 and one or more receivers 914 coupled to one or more antennas 916. The radio units 910 may be referred to or be part of radio interface circuitry. In some embodiments, the radio unit(s) 910 is external to the control system 902 and connected to the control system 902 via, e.g., a wired connection (e.g., an optical cable). However, in some other embodiments, the radio unit(s) 910 and potentially the antenna(s) 916 are integrated together with the control system 902. The one or more processors 904 operate to provide one or more functions of a network node 900 as described herein. In some embodiments, the function(s) are implemented in software that is stored, e.g., in the memory 906 and executed by the one or more processors 904.
[0095] Figure 10 is a schematic block diagram that illustrates a virtualized embodiment of the network node 900 according to some embodiments of the present disclosure. This discussion is equally applicable to other types of network nodes. Further, other types of network nodes may have similar virtualized architectures. Again, optional features are represented by dashed boxes.
[0096] As used herein, a "virtualized" radio access node is an implementation of the network node 900 in which at least a portion of the functionality of the network node 900 is implemented as a virtual component(s) (e.g., via a virtual machine(s) executing on a physical processing node(s) in a network(s)). As illustrated, in this example, the network node 900 may include the control system 902 and / or the one or more radio units 910, as described above. The control system 902 may be connected to the radio unit(s) 910 via, for example, an optical cable or the like. The network node 900 includes one or more processing nodes 1000 coupled to or included as part of a network(s) 1002. If present, the control system 902 or the radio unit(s) are connected to the processing node(s) 1000 via the network 1002. Each processing node 1000P109253W00120 includes one or more processors 1004 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory 1006, and a network interface 1008.
[0097] In this example, functions 1010 of the network node 900 described herein are implemented at the one or more processing nodes 1000 or distributed across the one or more processing nodes 1000 and the control system 902 and / or the radio unit(s) 910 in any desired manner. In some particular embodiments, some or all of the functions 1010 of the network node 900 described herein are implemented as virtual components executed by one or more virtual machines implemented in a virtual environment(s) hosted by the processing node(s) 1000. As will be appreciated by one of ordinary skill in the art, additional signaling or communication between the processing node(s) 1000 and the control system 902 is used in order to carry out at least some of the desired functions 1010. Notably, in some embodiments, the control system 902 may not be included, in which case the radio unit(s) 910 communicate directly with the processing node(s) 1000 via an appropriate network interface(s).
[0098] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of network node 900 or a node (e.g., a processing node 1000) implementing one or more of the functions 1010 of the network node 900 in a virtual environment according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).
[0099] Figure 11 is a schematic block diagram of the network node 900 according to some other embodiments of the present disclosure. The network node 900 includes one or more modules 1100, each of which is implemented in software. The module(s) 1100 provide the functionality of the network node 900 described herein. This discussion is equally applicable to the processing node 1000 of Figure 10 where the modules 1100 may be implemented at one of the processing nodes 1000 or distributed across multiple processing nodes 1000 and / or distributed across the processing node(s) 1000 and the control system 902.
[0100] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one orP109253W00121 more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.
[0101] While processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).
[0102] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered within the scope of the concepts disclosed herein.
Claims
P109253W00122Claims1. A method for Radio Frequency Fingerprinting, RFF, authentication of a User Equipment, UE, (102) the method comprising: selecting (208-1) a first network node (106-1) to perform a first RFF authentication on one or more transceivers (104-1, 104-2) of the UE (102); selecting (208-2) at least one second network node (106-2) to perform a second RFF authentication on a different transceiver (104-3) of the UE (102), wherein the first RFF authentication and the second RFF authentication comprises instructing one or more first or second network nodes (106-1 and 106-2) to transmit to the UE (102) values for a set of parameters for acquisition of a Radio Frequency, RF, fingerprint for the UE (102), the RF fingerprint comprising data characterizing RF impairments induced by specific hardware of the UE (102) on a signal received or transmitted by the UE (102), the RF impairments being unique to the UE (102), wherein the one or more first or second network nodes (106-1 and 106-2) comprise a plurality of transceivers (108-1, 108-2, and 108-3) operating according to different wireless communication standards or operating in different frequency bands, wherein the plurality of transceivers (108-1, 108-2, and 108-3) of the one or more first or second network nodes (106-1 and 106-2) correspond to a plurality of transceivers (104-1, 104-2, and 104-3) of the UE (102); receiving (210) responses to RFF authentication from the first network node (106-1) and the at least one second network node (106-2) selected; and granting (212) network access to the UE (102) when a result of the RFF authentication for all the plurality of transceivers (104-1, 104-2, and 104-3) of the UE (102) is positive.
2. The method of claim 1, wherein the selecting the first network node (106-1) and the at least one second network node (106-2) comprises: selecting (502, 504) the first network node (106-1) and the at least one second network node (106-2) from a first group of network nodes based on a position of the UE (102) in relation to the first and second network node (106-1, 106-2) and based on the first and second network node (106-1, 106-2) comprising transceivers (108) operating according to wireless communication standards corresponding to those of the plurality of transceivers (104-1, 104-2, and 104-3) of the UE (102).P109253W001233. The method according to claim 2, further comprising: selecting (506) the first network node (106-1) and the at least one second network node (106-2) from a second group of network nodes that have available network resources to perform the RFF authentication.
4. The method of claims 1 or 2, further comprising: providing (512), to the selected first network node (106-1) and the at least one selected second network node (106-2), an allocation of network resources to perform the RFF authentication.
5. The method according to claim 1, further comprising: identifying (402) the types of wireless communication standards used by the plurality of transceivers (104-1, 104-2, and 104-3) of the UE (102).
6. The method of any of claims 1 to 5, wherein selecting (208-1) the first network node (106-1) and selecting (208-2) the at least one second network node (106-2) is in response to: determining (304) that the UE (102) has not already been RFF authenticated.
7. The method of any of claims 1 to 6, further comprising: performing (608) a Radio Access Network level Machine Learning, ML, training and inference RFF authentication based on standalone network node ML inference RFF authentications from each of the first network node (106-1) and the at least one second network node (106-2), wherein the standalone network node ML inference RFF authentications are based on standalone transceiver ML inference RFF authentication from each transceiver (108-1, 108-2, 108-3) of the plurality of transceivers (108) associated with the first network node (106-1) and the at least one second network node (106-2).P109253W001248. A network node (900) for performing Radio Frequency Fingerprinting, RFF, authentication of a User Equipment, UE, (102), the network node (900) comprising a processor (904) configured to cause the network node (900) to: select (208-1) a first network node (106-1) to perform a first RFF authentication on one or more transceivers (104-1, 104-2) of the UE (102); select (208-2) at least one second network node (106-2) to perform a second RFF authentication on a different transceiver (104-3) of the UE (102), wherein the first RFF authentication and the second RFF authentication comprise instructing one or more first or second network nodes (106-1 and 106-2) to transmit to the UE (102) values for a set of parameters for acquisition of a Radio Frequency, RF, fingerprint for the UE (102), the RF fingerprint comprising data characterizing RF impairments induced by specific hardware of the UE (102) on a signal received or transmitted by the UE (102), the RF impairments being unique to the UE (102), wherein the one or more first or second network nodes (106-1 and 106-2) comprise a plurality of transceivers (108-1, 108-2, and 108-3) operating according to different wireless communication standards or operating in different frequency bands, wherein the plurality of transceivers (108-1, 108-2, and 108-3) of the first or second network nodes (106-1 and 106-2) correspond to a plurality of transceivers (104-1, 104-2, and 104-3) of the UE (102); receive (210) responses to RFF authentication from the first network node (106- 1) and the at least one second network node (106-2) selected; and grant (212) network access to the UE (102) when a result of the RFF authentication for all the plurality of transceivers (104-1, 104-2, and 104-3) of the UE (102) is positive.
9. The network node (900) of claim 8, wherein the processor (904) is further configured to cause the network node (900) to: select (502, 504) the first network node (106-1) and the at least one second network node (106-2) from a first group of network nodes based on a position of the UE (102) in relation to the first network node (106-1) and in relation to the second network node (106-2) and based on the first and second network nodes (106-1, 106-2) comprising transceivers (108) operating according to wireless communication standards that correspond to those of the plurality of transceivers (104-1, 104-2, and 104-3) of the UE (102).P109253W0012510. The network node (900) according to claim 9, wherein the processor (904) is further configured to cause the network node (900) to: select (506) the first network node (106-1) and the at least one second network node (106-2) from a second group of network nodes that have available network resources to perform the RFF authentication.
11. The network node (900) of claims 8 or 9, wherein the processor (904) is further configured to cause the network node (900) to: provide (512), to the selected first network node (106-1) and the at least one second network node (106-2), an allocation of network resources to perform the RFF authentication.
12. The network node (900) according to claim 8, wherein the processor (904) is further configured to cause the network node (900) to: identify (402) the types of wireless communication standards used by the plurality of transceivers (104-1, 104-2, and 104-3) of the UE (102).
13. The network node (900) of any of claims 8 to 12, wherein the network node (900) selecting (208-1) the first network node (106-1) and selecting (208-2) the at least one second network node (106-2) is in response to the processor (904) being configured to cause the network node (900) to: determine (304) that the UE (102) is not already RFF authenticated.
14. The network node (900) of any of claims 8 to 13, wherein the processor (904) is further configured to cause the network node (900) to: perform (608) a Radio Access Network level Machine Learning, ML, training and inference RFF authentication based on standalone network node ML inference RFF authentications from each of the first network node (106-1) and the at least one second network node (106-2), wherein the standalone network node ML inference RFF authentications are based on standalone transceiver ML inference RFF authentication from each transceiver (108-1, 108-2, 108-3) of the plurality of transceivers (108)P109253W00126 associated with the first network node (106-1) and the at least one second network node (106-2).
15. A computer program (918) comprising instructions which, when executed on at least one processor (904), cause the processor (904) to carry out the method according to any of claims 1 to 7.
16. A carrier containing the computer program (918) of claim 15, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a memory (906).