Secure Wireless Network Using Radiometric Signatures
A network security system for wireless devices derives a fingerprint from the modulation imperfections of the analog circuitry of the wireless transceivers. These fingerprints may be compared to templates obtained when the wireless devices are initially commissioned in a secure setting and used to augment passwords or other security tools in detecting intruders on the network.
1 . A secure network transceiver system for communicating network data with a plurality of mobile transceivers, each mobile transceiver having a digital signal portion communicating with an analog radio portion, the secure network transceiver system comprising:
at least one base transceiver having:
an analog radio portion exchanging radio signals with the mobile transceivers, the analog radio portion including modulation domain outputs reading modulation domain qualities of received radio signals from the mobile transceivers;
a digital signal portion communicating digital data with the analog radio portion related to encoded content of the radio signals;
an electronic computer including a processor and a memory, the electronic computer exchanging network data related to the digital data with the digital signal portion and receiving modulation domain outputs from the analog radio portion, the electronic computer further executing a stored program contained in memory to:
(a) execute an authentication process with mobile transceivers through an exchange of network data, the authentication process employing a networks data authenticator;
(b) characterize received radio signals of mobile transceivers according to the modulation domain qualities indicated by the modulation domain outputs;
(c) compare the characterized radio signals to pre-established characterizations of authorized mobile transceivers; and
(d) generate an output indicating a possible security violation when the characterized radio signals do not match pre-established characterizations to within at least one predetermined criterion.
2 . The secure network transceiver system of claim 1 wherein the electronic computer further executes the stored program contained in memory to:
(e) respond to the output to revoke authorization of mobile transmitters whose characterized radio signals do not match pre-established characterizations to within a predetermined threshold.
3 . The secure network transceiver system of claim 1 wherein the modulation domain qualities are selected from the group consisting of measurements of: symbol phase error, symbol magnitude error, and symbol error vector magnitude.
4 . The secure network transceiver system of claim 3 wherein the modulation domain qualities include each of: symbol phase error and symbol magnitude error
5 . The secure network transceiver system of claim 3 wherein the modulation domain qualities include each of: radio frequency error and frame SYNC correlation error.
6 . The secure network transceiver system of claim 1 wherein the modulation domain qualities are selected from the group consisting of measurements of: carrier frequency offset, symbol clock offset, SYNC correlation.
7 . The secure network transceiver system of claim 6 wherein the transceivers are 802.11 compliant.
8 . The secure network transceiver system of claim 1 wherein the comparison of characterized radio signals provides a multidimensional comparison using multiple different modulation domain qualities.
9 . The secure network transceiver system of claim 1 wherein the comparison of characterized radio signals employs comparison algorithms selected from the group consisting of: k-nearest-neighbor, support vector machines, decision trees, neural networks, Bayesian-based algorithms, polynomial classifiers, regression fitting, hidden Markov models, Gaussian mixture models, radial basis functions, classifier boosting, classifier ensembles.
10 . The secure network transceiver system of claim 9 wherein the comparison of characterized radio signals employs a combination of at least two different comparison algorithms operating independently to make a comparison and then combining the results.
11 . The secure network transceiver system of claim 1 including multiple base transceivers wherein each of the base transceivers uses a different pre-established characterization specific to a given base transceiver receiver.
12 . The secure network transceiver system of claim 1 including multiple base transceivers wherein the multiple base transceivers share pre-established characterizations.
13 . The secure network transceiver system of claim 1 wherein the electronic computer further executes the stored program contained in memory to characterize a new authorized mobile transceiver having a new secure key to produce a pre-established characterization for the new authorized mobile transceiver to be added to the pre-established characterizations of authorized mobile transceivers.
14 . The secure network transceiver system of claim 1 wherein the electronic computer further executes the stored program contained in memory to change a pre-established characterization for a mobile transceiver on a periodic basis using recent transmissions when the characterization of the recent transmissions matches existing characterizations to within a second predetermined threshold.
15 . The secure network transceiver system of claim 1 wherein the electronic computer further executes the stored program contained in memory to change a pre-established characterization for a mobile transceiver on a periodic basis using recent transmissions when the characterization of the recent transmissions matches an original characterization to within a second predetermined threshold.
16 . A method of establishing a secure wireless network using a base transceiver communicating with a plurality of mobile transceivers, the base transceiver having an analog radio portion exchanging radio signals with the mobile transceivers, the analog radio portion including modulation domain outputs reading modulation domain qualities of received radio signals from the mobile transceivers, the method comprising:
(a) executing an authentication process with mobile transceivers through an exchange of network data, the authentication process employing a network data authenticator;
(b) characterizing received radio signals of mobile transceivers according to the modulation domain qualities indicated by the modulation domain outputs;
(c) comparing the characterized radio signals to pre-established characterizations of authorized mobile transceivers;
(d) generating an output indicating a possible security violation when characterized radio signals do not match pre-established characterizations to within a predetermined threshold.
17 . The method of claim 16 further including:
(e) responding to the output to revoke authorization of mobile transmitters whose characterize radio signals do not match pre-established characterizations to within a predetermined threshold until a new security key has been established for those mobile transmitters.
18 . The method of claim 16 further wherein the modulation domain qualities are selected from the group consisting of measurements of: symbol phase error, symbol magnitude error, radio frequency error, frame SYNC correlation error.
19 . The method of claim 16 further including:
(e) allowing the mobile transceivers to use any commercially available 802.11 compatible wireless transceiver.