Authentication using radio frequency fingerprinting

WO2026201331A1PCT designated stage Publication Date: 2026-10-01TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/058653
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2026-10-01

Smart Images

  • Figure EP2025058653_01102026_PF_FP_ABST
    Figure EP2025058653_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a network node (113) configured to perform authentication of a device (110) using radio frequency fingerprinting, and a method performed by the network node (113). In an aspect, a network node (113) is provided configured to perform authentication of a device (110) using radio frequency fingerprinting, the network node (113) comprising a transceiver (117) configured to transmit data signals to, and receive data signals from, the device (110), and a processing unit (114) configured to cause the network node (113) to be operative to transmit (S201), to the device (110) via the transceiver (117), a physical layer configuration for a data signal to be transmitted by the device (110), receive (S202), from the device (110) via the transceiver (117), a data signal (200) complying with said physical layer configuration, wherein the processing unit (114) is configured to extract (S203) a set of radio frequency features from the data signal (200) received from the device (110), wherein the data signal (200) is configured to be present in a sub-channel of a main channel transporting the data signal (200) as specified by the physical layer configuration, the frequency of said sub-channel within the main channel being configured to change over time according to a frequency hopping scheme specified by the physical layer configuration, and at least one other sub-channel of said main channel being configured to transport padding data as specified by the physical layer configuration, wherein the processing unit (114) further is configured to perform (S204) authentication of the device (110) based on the extracted set of radio frequency features.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] P110500W001

[0002] 1

[0003] AUTHENTICATION USING RADIO FREQUENCY FINGERPRINTING

[0004] TECHNICAE FIELD

[0005] The present disclosure relates to a network node configured to perform authentication of a device using radio frequency fingerprinting, and a method of authenticating a device using radio frequency 5 fingerprinting performed by the network node. Further disclosed are computer programs and computer program products.

[0006] BACKGROUND

[0007] For wireless communication devices comprising RF circuitry such as e.g. smart phones, tablets, desktops, gaming consoles, connected vehicles, Intemet-of-Things (loT) devices and so on, imperfections in the device communication hardware may introduce distortions and errors in transmitted signals, which in turn may cause a constellation of the transmitted signal to deviate from its ideal shape. For example, imperfections in transmit or receive filters may cause frequency-dependent distortions in the signal, which in turn can cause the constellation of the signal to become skewed or tilted. Similarly, imperfections in analog-to-digital converters (ADCs) or digital-to-analog converters (DACs) of the 15 device may cause quantization errors, which can cause the constellation of the signal to become distorted or irregular. These imperfections may be the result of manufacturing tolerances or they may be inherent in the components themselves.

[0008] Moreover, nonlinearities in amplifier or mixer devices may cause intermodulation distortion, which commonly introduces additional unwanted signals in the spectrum of the transmitted signal

[0009] 20 Hardware designers aim to mitigate hardware imperfections utilizing various techniques in transmitters such as digital predistortion (DPD), post-distortion, interference cancellation circuits, dynamic biasing of amplification elements, etc. However, even when applying great care in the design, it is impossible to mitigate all these imperfections in transmitters. The imperfections are also unique and vary from one transmitter to another, impacted by (but not limited to) circuit architectures, implementation, technology, etc. Further sources for causing unique hardware impairments include tolerances in manufacturing, operating conditions, operational temperature, aging, memory types being used, etc.

[0010] An approach referred to as Radio Frequency Fingerprinting (RFF) has recently emerged as a promising technique for Physical Layer Security (PLS) for 5G wireless communication networks and 30 beyond to improve the security of wireless communications. RFF can also be used to mitigate threats such as eavesdropping or spoofing. The concept of RFF is to exploit these unique hardware impairments in transmitters to uniquely identify and authenticate radio equipment such as (and not limited to) User Equipment (UEs) and access points, to increase the trustworthiness and security of telecommunications.P110500W001

[0011] 2

[0012] However, during RFF authentication a malicious third party may acquire RF features of a device being authenticated. This third party may then possibly impersonate said device during later RFF authentication, which must be avoided. There is thus room for improvement in the field of RFF authentication.

[0013] 5 SUMMARY

[0014] One objective is to solve, or at least mitigate, the problems in the art and thus to provide an improved approach of a network node of performing authentication of a device using radio frequency fingerprinting.

[0015] This objective is attained in a first aspect by a network node configured to perform authentication of a device using radio frequency fingerprinting. The network node comprises a transceiver configured to transmit data signals to, and receive data signals from, the device, and a processing unit configured to cause the network node to be operative to transmit, to the device via the transceiver, a physical layer configuration for a data signal to be transmitted by the device, receive, from the device via the transceiver, a data signal complying with said physical layer configuration, wherein the processing unit 15 is configured to extract a set of radio frequency features from the data signal received from the device, wherein the data signal is configured to be present in a sub-channel of a main channel transporting the data signal as specified by the physical layer configuration, the frequency of said sub-channel within the main channel being configured to change over time according to a frequency hopping scheme specified by the physical layer configuration, and at least one other sub-channel of said main channel

[0016] 20 beingconfigured to transport padding data as specified by the physical layer configuration; wherein the processing unit further is configured to perform authentication of the device based on the extracted set of radio frequency features.

[0017] This objective is attained in a second aspect by a method of a network node of performing authentication of a device using radio frequency fingerprinting. The method comprises transmitting, to the device via a transceiver of the network node, a physical layer configuration for a data signal to be transmitted by the device, receiving, from the device via the transceiver, a data signal complying with said physical layer configuration; wherein a processing unit of the network node is configured to extracting a set of radio frequency features from the data signal received from the device, wherein the data signal is configured to be present in a sub-channel of a main channel transporting the data signal as 30 specified by the physical layer configuration, the frequency of said sub-channel within the main channel is configured to change over time according to a frequency hopping scheme specified by the physical layer configuration, and at least one other sub-channel of said main channel is configured to transport padding data as specified by the physical layer configuration, wherein the processing unit further is performing authentication of the device based on the extracted set of radio frequency features.P110500W001

[0018] 3

[0019] This objective is attained in a third aspect by a device configured to perform authentication of a network node using radio frequency fingerprinting. The device comprises a transceiver configured to transmit data signals to, and receive data signals from, the network node, and a processing unit configured to cause the device to be operative to transmit, to the network node via the transceiver, a 5 physical layer configuration for a data signal to be transmitted by the network node, receive, from the network node via the transceiver, a data signal complying with said physical layer configuration; wherein the processing unit is configured to extract a set of radio frequency features from the data signal received from the network node, wherein the data signal is configured to be present in a sub-channel of a main channel transporting the data signal as specified by the physical layer configuration, the

[0020] 10 frequency of said sub-channel within the main channel being configured to change over time according to a frequency hopping scheme specified by the physical layer configuration, and at least one other subchannel of said main channel being configured to transport padding data as specified by the physical layer configuration; wherein the processing unit further is configured to perform authentication of the network node based on the extracted set of radio frequency features.

[0021] This objective is attained in a fourth aspect by a method of a device of performing authentication of a network node using radio frequency fingerprinting. The method comprises transmitting, to the network node via a transceiver of the device, a physical layer configuration for a data signal to be transmitted by the network node, receiving, from the network node via the transceiver, a data signal complying with said physical layer configuration; wherein a processing unit of the device is configured to extracting a set of radio frequency features from the data signal received from the network node, wherein the data signal is configured to be present in a sub-channel of a main channel transporting the data signal as specified by the physical layer configuration, the frequency of said sub-channel within the main channel being configured to change over time according to a frequency hopping scheme specified by the physical layer configuration, and at least one other sub-channel of said main channel being 25 configured to transport padding data as specified by the physical layer configuration, wherein the processing unit performing authentication of the network node based on the extracted set of radio frequency features.

[0022] One advantage of the solution described by the above aspects is that the frequency hopping scheme cannot be identified by eavesdropping on the data transferred by the device (being e.g. a UE) to the network node (being e.g. an access point), or the other way around, in accordance with the physical layer configuration agreed upon. The data signal being transmitted in different sub-channels will thus be difficult to detected for an eavesdropper. The data signal may be embodied by an RFF signal.

[0023] One further advantage is that, by transmitting padding data in the remaining sub-channels of the main channel (i.e. other than the sub-channel over which the data signal is transmitted), it is even more 35 difficult for an eavesdropper to identify the data signal within the main channel.P110500W001

[0024] 4

[0025] In an embodiment, the network node or the device is further being operative to, in response to the extracted set of radio frequency features being determined to match a reference set of radio frequency features associated with the device, successfully authenticate the device or the network node, respectively.

[0026] 5 In an embodiment, the network node or the device is further being operative to, in response to the extracted set of radio frequency features being determined to fail to match a reference set of radio frequency features associated with the device or the network node, respectively, reject the device or network node.

[0027] In an embodiment, the network node or the device is further being operative to, upon transmitting a 10 physical layer configuration for a data signal to be transmitted by the device or network node, respectively, request the device or network node to transmit said data signal from which a set of radio frequency features is extracted.

[0028] In an embodiment, the physical layer configuration further indicates one or more of sub-channel bandwidth, main channel bandwidth, sub-channel spacing and transmission modulation scheme.

[0029] In an embodiment, a plurality of other sub-channels within said main channel are configured to transport padding data.

[0030] In an embodiment, the bandwidth of the main channel is configured to be at least the size of the bandwidth of the channel utilized to transport data from the device to the network node or from the network node to the device.

[0031] 20 In a fifth aspect, a computer program is provided comprising computer-executable instructions for causing a network node to perform steps recited in the method of the second aspect when the computerexecutable instructions are executed on a processing unit included in the network node.

[0032] In a sixth aspect, a computer program product is provided comprising a computer readable medium, the computer readable medium having the computer program according to the fifth aspect embodied thereon.

[0033] In a seventh aspect, a computer program is provided comprising computer-executable instructions for causing a device to perform steps recited in the method of the fourth aspect when the computerexecutable instructions are executed on a processing unit included in the device.

[0034] In an eighth aspect, a computer program product is provided comprising a computer readable 30 medium, the computer readable medium having the computer program according to the seventh aspect embodied thereon.

[0035] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element,P110500W001

[0036] 5

[0037] apparatus, component, means, step, etc." are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.

[0038] 5 BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Aspects and embodiments are now described, by way of example, with reference to the accompanying drawings, in which:

[0040] Figure 1 illustrates a wireless communication network in which embodiments may be implemented;

[0041] Figure 2 shows a network node in the form of a radio base station gathering radio frequency features from wireless communication devices;

[0042] Figure 3 shows a flowchart illustrating a method according to an embodiment;

[0043] Figure 4 shows a signalling diagram illustrating a method according to an embodiment; Figure 5 shows a flowchart illustrating a method according to an embodiment;

[0044] 15 Figure 6 shows a signalling diagram illustrating a method according to an embodiment;

[0045] Figure 7 shows a signalling diagram illustrating a method according to an embodiment; Figure 8 illustrates a network node according to an embodiment; and

[0046] Figure 9 illustrates a device according to an embodiment.

[0047] DETAILED DESCRIPTION

[0048] 20 Aspects of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the invention are shown.

[0049] These aspects may, however, be embodied in many different forms and should not be construed as limiting; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and to fully convey the scope of all aspects of invention to those skilled in the art. Like numbers refer to like elements throughout the description.

[0050] Figure 1 illustrates a schematic illustration of a wireless communication system 100 in which embodiments may be implemented. In the wireless communication system 100, a first set of devices 110, 111, 112 in the form of User Equipment (UE), e.g. smart phones, tablets, desktops, gaming consoles, connected vehicles, Intemet-of-Things (loT) devices, etc., are served by a first network node 30 113 which in this example is embodied in the form of a radio base station 113 (RBS). In a 5G wireless communication system, the radio base station is commonly referred to as gNodeB (gNB).P110500W001

[0051] 6

[0052] The network node 113 may be composed of multiple physically separate components (e.g., a gNodeB component and a radio network controller (RNC) component, or a base transceiver station (BTS) component and a base station controller (BSC) component, etc.), which may each have their own respective components. In certain scenarios in which the network nodes 113, 123 comprise multiple 5 separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple gNodeBs. In such a scenario, each unique gNodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 113 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory for different RATs) and some components may be reused (e.g., a same antenna may be shared by different RATs). The network node 113 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 113, for example Global System for Mobile Communications (GSM), Wideband Code Division Multiple Access (W CDMA), Long Term Evolution (LTE), New Radio (NR), sixth generation (6G) wireless

[0053] 15 communication radio networks, WiFi, Zigbee, Z-wave, Long Range Wide Area Network (LoRaWAN), Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within the network node 113. The network node 113 will in the following be exemplified in the form of an RBS.

[0054] The RBS 113 is connected to a core network 130, such has e.g., a 3rd Generation Partnership 20 Project (3GPP) 5thgeneration core (5GC) network, and the 5GC network 130 is typically in turn connected to the Internet, in this example illustrated with the 5GC network connected to a cloud server 150.

[0055] As previously mentioned, the concept of RFF is utilized to exploit unique hardware impairments in radio transmitters to uniquely identify and authenticate UEs and access points comprising this radio 25 transmitters in order to increase the trustworthiness and security of telecommunications.

[0056] Figure 2 illustrates the use of RFF at the RBS 113 for authenticating the three UEs 110-112.There are two types of RFF approaches; passive and active.

[0057] Active RFF involves sending S101 active probing signals or sequence of signals from the RBS 113 to the UEs 110-112 in the form of signals S 101 , SI 03 and SI 04 and measuring the corresponding RF signals in SI 02, SI 04, SI 06 received for each UE to identify unique characteristics and build a reference RF fingerprint database. This is commonly known as the registration phase. This approach can provide more accurate and reliable fingerprints, especially in environments with high levels of noise or interference. However, it may be more intrusive and may require more resources to implement. Thus, an RF fingerprint dataset may be built, which dataset may comprise multi-dimensional vectors extracted by 35 utilizing machine learning (ML). Subsequently, an extracted RF fingerprint of a device can be comparedP110500W001

[0058] 7

[0059] to the sets of reference RF fingerprints in an authentication phase and if the resemblance is sufficiently high, authentication is successful.

[0060] Passive RFF has been studied for decades and involves analysing signals SI 02, SI 04 and SI 06 that are already being transmitted by the UEs 110-112 in an opportunistic way, i.e. without first triggering 5 the UEs 110-112 by sending probing signals in S 101, S 103 and SI 05. The probing signals S101, SI 03 and SI 05 may be the same or different for each of the UEs 110, 111 and 112. Similar to the active approach, a comparison can be made of extracted RF fingerprints with reference RF fingerprints for authentication.

[0061] Both passive and active RFF approaches have issues in terms of trustworthiness in authentication.

[0062] 10 For instance, active RFF approaches are vulnerable to impersonation attacks by adversaries who can generate fake RF features which resemble prestored reference RF features to such an extent that the adversary may be authenticated.

[0063] Hence, a security risk in RFF-based authentication is that a malicious device may eavesdrop on signals during the authentication process. Having retrieved the RF fingerprints, the malicious node can potentially impersonate a legitimate user and gain access to the network for malicious intents such as degrading network performances or extracting sensitive information. RFF-based authentication therefore requires a secure transmission scheme.

[0064] Embodiments addressing this issue will be discussed in the following utilizing a frequency hopping scheme to impede an adversary from identifying a signal carrying the RF features to be used for RFF 20 authentication.

[0065] Frequency hopping is a communication technique where a transmitter regularly changes carrier frequency in accordance with a hopping sequence known to the transmitter and targeted receiver.

[0066] Frequency hopping may thus provide a certain degree of physical layer security; if the hopping sequence is known only to the transmitter and receiver, the possibilities to eavesdrop or jam the channel over which data is transmitted are limited to a single hop.

[0067] Figure 3 shows a flowchart illustrating an embodiment of a method performed by a network node (exemplified by the RBS 113) of authenticating a device (exemplified by the UE 110) using RFF to resolve this issue.

[0068] Figure 4 shows a signalling diagram illustrating the embodiment of the RBS 113 performing 30 authentication of the UE 110 using RFF.

[0069] Initially, in order for the RBS 113 to inform the UE 110 of which data signal(s) the UE 110 is expected to transmit to the RBS 113 for the RBS 113 to be able to perform the RFF authentication, the RBS 113 transmits in S201 a physical layer configuration for the data signal to be transmitted by the UE 110. This transmission may further include a request to the UE 110 to transmit said data signal.P110500W001

[0070] 8

[0071] In response thereto, the UE 110 transmits a data signal 200 complying with said physical layer configuration, which data signal 200 is received by the RBS 113 in S202.

[0072] Now, as shown in more detail in Figure 4, the data signal 200 comprising RF features based on which the RFF authentication subsequently will be undertaken is - as specified by the physical layer 5 configuration known to the RBS 113 and the UE 110 - transmitted in a sub-channel of a main channel having much larger channel bandwidth then the sub-channel, and regularly moves within the main channel according to a frequency hopping scheme also specified by the physical layer configuration. The data signal 200 will in the following by referred to as the “RFF signal”. In the example of Figure 4, the main channel is configured to have a bandwidth (BW) of 25 MHz, while the sub-channel carrying 10 the RFF signal 200 is configured to have a bandwidth of 1.5 MHz.

[0073] The other sub-channels contained in the main channel are in this embodiment filled with padding data having the same characteristics as the RFF signal 200 (in terms of e.g., modulation scheme, amplitude, power, etc.).

[0074] Advantageously, the frequency hopping scheme cannot be identified by eavesdropping on the data transferred by the UE 110 to the RBS 113 in S202 in accordance with the physical layer configuration agreed upon in S201. The RFF signal 200 being transmitted in different sub-channels will thus be difficult to detected for an eavesdropper.

[0075] Further advantageous is that, by transmitting padding data in the remaining sub-channels of the main channel (i.e. other than the sub-channel over which the RFF signal 200 is transmitted), it is even 20 more difficult for an eavesdropper to identify the RFF signal 200 within the main channel.

[0076] Further, by changing parameters such as sub-channel bandwidth, main channel bandwidth, subcarrier spacing and modulation scheme, it is also possible to reduce symbol time and therefore reduce thetime available for an eavesdropper to process the data. These parameters may advantageously be included in the physical layer configuration shared between the RBS 113 and the UE 110 for performing the authentication process.

[0077] Shown in Figure 4 is also that the RFF signal 200 typically is part of data transmission comprising payload data transmitted by the UE 110 via the RBS 113 and further uplink, for instance to the cloud server 150.

[0078] Upon receiving the RFF signal present in a sub-channel of the broader main channel, the RBS 113 30 extracts in S203 a set of RF features from the RFF signal 200, as illustrated in a right-hand side of Figure 4 showing the payload data and the RFF signals 200 being transmitted and proceeds to authenticating the UE 110 in S 104 based on the extracted RF features.

[0079] Advantageously, the proposed embodiment increases the complexity of the data transmission and impedes an adversary from eavesdropping on communication during the authentication process, both byP110500W001

[0080] 9

[0081] disguising the RFF signal 200 within a much larger amount of padding data and by reducing the time available to retrieve the RFF signal among the padding data due to the applied frequency hopping scheme. The risk of having an adversary successfully eavesdropping the RFF signal to impersonate someone is thus reduced.

[0082] 5 As shown in Figure 4, from the perspective of an eavesdropper observing the spectrum of the transmitted data, the RBS 113 appears to perform a bandwidth adaptation to send a large amount of data, thereby concealing the intent of transmitting RFF signals.

[0083] Further, as mentioned above, the padding data being configured to occupy the remaining subchannels of the main channel has the same characteristics as the RFF signal 200. Therefore, it is not possible to detect the RFF signal 200 without decoding the entire main channel. Symbol time of the data being transmitted may also be adapted to further hamper an eavesdropper.

[0084] With reference again to Figure 4, for numerical examples, it may be assumed for instance that - prior to any RFF signals being sent - the UE 110 and the RBS 113 initially are communicating on a 5 MHz channel with 15 kHz sub-carrier spacing, where the symbol rate is 4 MSymbols / s and the slot time 15 is 1 ms.

[0085] Then, upon the RBS 113 requesting RFF authenticating by transmitting the physical layer configuration to the UE 110 in S201, the RBS 113 specifies the following in the physical layer configuration.

[0086] • Sub-channel bandwidth:

[0087] 20 o the sub-channel bandwidth defines the bandwidth allocated to communicate the RFF signal 200,

[0088] o the sub-channel bandwidth is specified taking into account the size of the RFF signal 200 in terms of the bandwidth it occupies, i.e., a larger RFF signal will require more subchannel bandwidth, wherein 1.5 MHz is allocated for the sub-channel in the example of Figure 4.

[0089] • Main channel bandwidth:

[0090] o the main channel bandwidth is larger than that of the sub-channel in order to increase the amount of data that is potentially required toeavesdrop on,

[0091] 30 o allocating a larger channel bandwidth will increase the amount of padding data (and thus make it more difficult to detect the RFF signal 200), but will degrade the spectral efficiency, wherein 25 MHz is allocated for the main channel in the example of Figure 4.

[0092] Sub-carrier spacing and modulation scheme:P110500W001

[0093] 10

[0094] o the symbol time is defined in accordance with sub-carrier spacing; increasing the subcarrier spacing will decrease symbol time and thus decrease the time available for eavesdropping on the transmitted data,

[0095] o with the above numerical example, by increasing the sub-carrier spacing from 15 kHz 5 to e.g. 60kHz, the slot time decreases from 1 ms to 0.25 ms,

[0096] o which modulation scheme is utilized, such as e.g. Frequency Shift Keying (FSK), Phase Shift Keying (PSK), Quadrature Amplitude Modulation (QAM), etc.

[0097] • Frequency hopping scheme:

[0098] o the hopping scheme defines how the sub-channel moves within the main channel, o the frequency aspect is defined in accordance with the ratio between sub-channel and main channel bandwidth,

[0099] o the time aspect is defined in accordance with the slot time.

[0100] An example of configuration based on the above example is summarized as follows:

[0101] 15 • With 4 bits per symbol, the data rate increases from 16.8 Mbps to 83.2 Mbps by increasing the bandwidth. The eavesdropper has 4.9524 more data to decode by expanding the bandwidth, in a time reduced by a factor of 4 by reducing the symbol duration.

[0102] • The sensitive RFF data represents 5 Mbps of the entire dataset. Its position in the frequency 20 domain regularly moves within the channel, so the eavesdropper is forced to decode and read the entire channel to retrieve the sensitive data.

[0103] • With time-sensitive data, (i.e., RFF credentials that expire with time), the eavesdropper must retrieve this 5 Mbps in a fairly limited amount of time.

[0104] While Figure 3 and 4 illustrates the RBS 113 authenticating the UE 110, it is understood that the roles may be reversed, where the UE 110 sends the physical layer configuration to the RBS 113 in S201, the RBS 113 responds with transmitting the RFF signal 200 in compliance with the physical layer configuration in S202, wherein the UE 110 extracts the RF features from the RFF signal 200 in S203 and authenticate the RBS 113 in S 104.

[0105] 30 Figure 5 shows a flowchart illustrating an embodiment of the RBS 113 authenticating the UE 110, wherein after the RBS 113 has extracted the set of RF features in S203 from the received RFF signal, the authentication will be performed by comparing the extracted RF features to prestored reference RF features of the UE 110 (typically acquired in a registration phase) in S204a and if the extracted RF features matches the reference RF features, the UE 100 is successfully authenticated in S204b. If not,P110500W001

[0106] 11

[0107] the UE 110 is rejected in S204c in which case various actions may be taken by the RBS 113, such as reporting the unsuccessful authenticating attempt, blocking the UE, trigger another authentication process, etc.

[0108] As is understood, when determining whether or not a set of extracted RF features of the UE 110 5 matches a corresponding prestored set of reference RF features previously extracted by the RBS 113 in S204a, the RBS 113 may compare the currently extracted set of RF features with the prestored set of RF features, and if the two sets of RF features are sufficiently similar - which may involve an estimated probability exceeding a set threshold value indicating that the currently extracted set of RF features indeed corresponds to the prestored set of RF features for the UE 110 is sufficiently high, e.g. if the 10 measure of similarity between the two sets of RF features is at or above a set similarity threshold value indicating that the two RF feature sets are sufficiently similar to each other, - then there is a match between the two RF feature sets, and the UE 110 is successfully authenticated by the RBS 113 in S204b.

[0109] On the other hand, if a determined measure of similarity indicates a poor resemblance for the two sets of RF features, e.g. if the measure of similarity is below a set similarity threshold value indicating that the two RF feature sets are not sufficiently similar to each other, the UE 110 is rejected.

[0110] Figure 6 illustrates a signalling diagram according to a further embodiment.

[0111] While in Figure 4, the power of the padding data transmitted in the sub-channels are spread over a large bandwidth (i.e. over the complete width of the main channel) thereby providing for inefficient use 20 of the radio spectrum during the authentication process as well as higher power consumption, Figure 6 illustrates that only one further sub-channel (in addition to the sub-channel carrying the RFF signal 200) is allocated for the padding data in the main channel. In other words, one or more sub-channels may be configured for the transmission of the padding data, without completely filling up the main channel. Figure 7 illustrates a signalling diagram according to another embodiment.

[0112] While in Figure 4, the main channel accommodating the sub-channels for transmitting the RFF signal and the padding data is expanded (from 5 MHz to 25 MHz) to impede an eavesdropper from detecting the RF signal 200 thereby providing for inefficient use of the radio spectrum as well as higher power consumption, Figure 7 illustrates that the width of the main channel for transporting the RFF signal 200 and the padding data is not expanded, but maintained to have the same width as the channel transmitting 30 the payload data.

[0113] Figure 8 illustrates a network node in the form of the RBS 113 configured to perform authentication of a device 110 using radio frequency fingerprinting according to an embodiment. The steps of the method performed by the RBS 113 are in practice performed by a processing unit 114 embodied in the form of one or more microprocessors arranged to execute a computer program 115 downloaded to aP110500W001

[0114] 12

[0115] storage medium 116 associated with the microprocessor, such as a Random Access Memory (RAM), a Flash memory or a hard disk drive. The processing unit 114 is arranged to cause the RBS 113 to carry out the method according to embodiments when the appropriate computer program 115 comprising computer-executable instructions is downloaded to the storage medium 116 and executed by the 5 processing unit 114. The storage medium 116 may also be a computer program product comprising the computer program 115. Alternatively, the computer program 115 may be transferred to the storage medium 116 by means of a suitable computer program product, such as a Digital Versatile Disc (DVD) or a memory stick. As a further alternative, the computer program 115 may be downloaded to the storage medium 116 over a network. The processing unit 114 may alternatively be embodied in the form 10 of a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field- programmable gate array (FPGA), a complex programmable logic device (CPLD), etc. The RBS 113 further comprises a transceiver 117 providing a communication interface (wired or wireless) over which the RBS 113 is configured to transmit and receive data.

[0116] While Figure 8 illustrates the network node in the form of the RBS 113 being equipped with the processing unit 114, the computer program 115, the storage medium 116 and the transceiver 117 for authenticating the UE 110 as previously described with reference e.g. to Figures 3-5, it may alternatively be that the UE 110 is equipped with a corresponding processing unit 214, computer program 215, storage medium 216 and transceiver 217 for authenticating the RBS 113 or some other appropriate device, as shown in Figure 9.

[0117] 20 Thus, while various aspects and embodiments have been disclosed herein, other aspects and embodiments will be apparent to those skilled in the art. The various aspects and embodiments disclosed herein are for purposes of illustration and are not intended to be limiting, with the true scope and spirit being indicated by the following claims.

Claims

P110500W00113CLAIMS1. A network node (113) configured to perform authentication of a device (110) using radio frequency fingerprinting, the network node (113) comprising a transceiver (117) configured to transmit data signals to, and receive data signals from, the device (110), and a processing unit (114) configured to cause the 5 network node (113) to be operative to:transmit (S201), to the device (110) via the transceiver (117), a physical layer configuration for a data signal to be transmitted by the device (110);receive (S202), from the device (110) via the transceiver (117), a data signal (200) complying with said physical layer configuration; wherein the processing unit (114) is configured to:10 extract (S203) a set of radio frequency features from the data signal (200) received from the device (110), wherein the data signal (200) is configured to be present in a sub-channel of a main channel transporting the data signal (200) as specified by the physical layer configuration, the frequency of said sub-channel within the main channel beingconfigured to change over time according to a frequency hopping scheme specified by the physical layer configuration, and at least one other sub-channel of said main channel being configured to transport padding data as specified by the physical layer configuration; wherein the processing unit (114) is further configured to:perform (S204) authentication of the device (110) based on the extracted set of radio frequency features.

2. The network node (113) of claim 1, further being operative to:20 in response to the extracted set of radio frequency features being determined (S204a) to match a reference set of radio frequency features associated with the device (110), successfully authenticating (S204b) the device (110).

3. The network node (113) of claims 1 or 2, further being operative to:in response to the extracted set of radio frequency features being determined (S204b) to fail to match a reference set of radio frequency features associated with the device (110), rejecting (S204c) the device (110).

4. The network node (113) of any one of the preceding claims, further being operative to upon transmitting (S201 ), to the device (110) via the transceiver, a physical layer configuration for a data signal to be transmitted by the device (110):30 request the device (110) to transmit said data signal (200) from which a set of radio frequency features is extracted.P110500W001145. The network node (113) of any one of the preceding claims, the physical layer configuration further indicating one or more of sub-channel bandwidth, main channel bandwidth, sub-channel spacing and transmission modulation scheme.

6. The network node (113) of any one of the preceding claims, wherein a plurality of other sub5 channels within said main channel are configured to transport padding data.

7. The network node (113) of any one of the preceding claims, wherein the bandwidth of the main channel is configured to be at least the size of the bandwidth of the channel utilized to transport data from the device (110) to the network node (113).

8. A device (110) configured to perform authentication of a network node (113) using radio frequency fingerprinting, the device (110) comprising a transceiver (217) configured to transmit data signals to, and receive data signals from, network node (113), and a processing unit (214) configured to cause the device (110) to be operative to:transmit (S201), to the network node (113) via the transceiver (217), a physical layer configuration for a data signal to be transmitted by the network node (113);15 receive (S202), from the network node (113) via the transceiver (217), a data signal (200) complying with said physical layer configuration; wherein the processing unit (214) is configured to: extract (S203) a set of radio frequency features from the data signal (200) received from the network node (113), wherein the data signal (200) is configured to be present in a sub-channel of a main channel transporting the data signal (200) as specified by the physical layer configuration, the frequency 20 of said sub-channel within the main channel is configured to change over time according to a frequency hopping scheme specified by the physical layer configuration, and at least one other sub-channel of said main channel is configured to transport padding data as specified by the physical layer configuration; wherein the processing unit (214) further is configured to:perform (S204) authentication of the network node (113) based on the extracted set of radio frequency features.

9. A method of a network node (113) of performing authentication of a device (110) using radio frequency fingerprinting, the method comprising:transmitting (S201), to the device (110) via a transceiver (117) of the network node (113), a physical layer configuration for a data signal to be transmitted by the device (110);30 receiving (S202), from the device (110) via the transceiver (117), a data signal (200) complying with said physical layer configuration; wherein a processing unit (114) of the network node (113) is configured to:extracting (S203) a set of radio frequency features from the data signal (200) received from the device (110), wherein the data signal (200) is configured to be present in a sub-channel of a main channelP110500W00115transporting the data signal (200) as specified by the physical layer configuration, the frequency of said sub-channel within the main channel is configured to change over time according to a frequency hopping scheme specified by the physical layer configuration, and at least one other sub-channel of said main channel is configured to transport padding data as specified by the physical layer configuration; wherein 5 the processing unit (114) further is configured to:performing (S204) authentication of the device (110) based on the extracted set of radio frequency features.

10. A method of a device (110) of performing authentication of a network node (113) using radio frequency fingerprinting, the method comprising:transmitting (S201), to the network node (113) via a transceiver (217) of the device (110), a physical layer configuration for a data signal to be transmitted by the network node (113);receiving (S202), from the network node (113) via the transceiver (217), a data signal (200) complying with said physical layer configuration; wherein a processing unit (214) of the device (110) is configured to:15 extracting (S203) a set of radio frequency features from the data signal (200) received from the network node (113), wherein the data signal (200) is configured to be present in a sub-channel of a main channel transporting the data signal (200) as specified by the physical layer configuration, the frequency of said sub-channel within the main channel is configured to change over time according to a frequency hopping scheme specified by the physical layer configuration, and at least one other sub-channel of said 20 main channel is configured to transport padding data as specified by the physical layer configuration;wherein the processing unit (214) further isperforming (S204) authentication of the network node (113) based on the extracted set of radio frequency features.

11. The method of claim 10, further comprising:in response to the extracted set of radio frequency features being determined (S204a) to match a reference set of radio frequency features associated with the network node (113), the successfully authenticating (S204b) the network node (113).

12. A computer program comprising computer-executable instructions for causing a network node (113) to perform steps recited in claim 9 when the computer-executable instructions are executed on a processing unit (114) included in the network node (113).30 13. A computer program product comprising a computer readable medium, the computer readable medium having the computer program according to claim 12 embodied thereon.P110500W0011614. A computer program comprising computer-executable instructions for causing a device (110) to perform steps recited in claim 10 when the computer-executable instructions are executed on a processing unit (214) included in the device (110).

15. A computer program product comprising a computer readable medium, the computer readable 5 medium having the computer program according to claim 14 embodied thereon.