发表机构
University of Padova; National Interuniversity Consortium for Telecommunications (CNIT)(帕多瓦大学; 国家大学间电信联盟)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对OFDM系统中基于M-CSI的认证,提出一种双设备协同欺骗攻击,推导了认证检验统计量的闭式分布并验证,发现攻击者可破解该认证机制。
AI 中文摘要
我们考虑如下场景:合法用户(Alice)通过传输正交频分复用(OFDM)导频向认证方(Bob)进行认证,认证方从中提取微信道状态信息(Micro-CSI,M-CSI)指纹,并通过基于似然检验(LT)的测试将其与存储的参考指纹进行比对。我们提出一种新型欺骗攻击:两个对抗设备协同,先联合估计Alice和Bob的M-CSI指纹,再构造伪造信号,该信号能以高概率破解认证机制,仅受估计过程中噪声效应的限制。我们推导了合法假设与欺骗假设下认证检验统计量的近似闭式分布,从而可闭式推导虚警概率与漏检概率。随后,我们将分析结果与从实验数据中提取的M-CSI指纹进行验证。结果表明,给定充足的导频观测次数,或Bob与攻击者间存在等效噪声统计,攻击者总能将检验统计量推向随机分类器,使基于M-CSI的认证的安全性消失。
英文摘要
We consider a scenario where a legitimate user (Alice) authenticates itself to an authenticator (Bob) by transmitting orthogonal frequency division multiplexing (OFDM) pilots, from which the authenticator extracts the Micro-CSI (M-CSI) fingerprint and compares it against a stored reference via a likelihood test (LT)-based test. We introduce a new spoofing attack, where two adversarial devices collude to first jointly estimate the M-CSI fingerprints of Alice and Bob and then construct a forged signal able to break the authentication mechanism with high probability, limited only by noise effects on the estimates. We derive approximate closed-form distributions of the authentication test statistic under both the legitimate and spoofing hypotheses, enabling the derivation of false alarm and misdetection probabilities in closed-form. We then validate our analytical results against M-CSI fingerprints extracted from experimental data. The results reveal that, given sufficient pilot observations or an equivalent noise statistic between Bob and the attackers, the latter can always drive the test statistics to a random classifier, vanishing the security of M-CSI-based authentication.