Physical Layer Authentication via Device Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network authentication methods are inadequate in distinguishing between in-distribution and out-of-distribution devices, particularly in operational technology (OT) networks, which are vulnerable to cyber attacks due to lack of robust intrusion detection and access control systems, and higher-layer approaches can disrupt network operations.
Innovation Solution
A computer-implemented method and system using machine-learned models to generate device fingerprints based on physical communication signal characteristics, processing these fingerprints to classify devices as in-distribution or out-of-distribution, and controlling network access accordingly, thereby enhancing security without disrupting network functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If higher-layer authentication approaches are used, then network security can be improved, but network operations are disrupted
Solution Approach 1:
The patent segments the authentication process by separating physical layer signal analysis from higher-layer network operations. Sensors capture physical layer characteristics (Layer 1) independently, and machine learning models process these signals to generate authentication decisions without interrupting data transmission at upper layers, thus maintaining network productivity while improving security
Solution Approach 2:
The patent introduces machine learning models as intermediaries that translate physical layer signal characteristics into authentication decisions. These models act as a mediator between the physical layer sensors and the network authentication system, enabling security verification without requiring direct intervention in network operations
2Measurement precision
If physical layer authentication is implemented, then device classification accuracy is improved, but system complexity increases
Solution Approach 1:
The patent implements self-service through autonomous machine learning models that automatically process physical layer signals and generate authentication decisions without requiring manual configuration or intervention. The system trains and adapts to device characteristics autonomously, reducing operational complexity despite the advanced technology employed
Solution Approach 2:
The patent changes the authentication parameters from traditional network-layer attributes to physical layer signal characteristics. By measuring electromagnetic signal properties, timing characteristics, and hardware-induced variations at the physical layer, the system achieves high classification accuracy using fundamentally different measurement parameters that are inherently difficult to spoof
Data Source
AI summary
A network authentication system can be configured for sampling a plurality of signal samples from a device on a network, providing the plurality of signal samples to a first machine-learned model that is configured to determine a device fingerprint based at least in part on the plurality of signal samples, and providing the device fingerprint to a second machine-learned model that is configured to classify the device based at least in part on the device fingerprint.


