IP Library Granted Patent US 10,397,080
Granted Patent B2
US 10,397,080 · App. 15/600,220 · Granted Aug 27, 2019

Secure wireless network using radiometric signatures

Inventors: Vladimir Alexander Brik (Madison, WI); Suman Banerjee (Madison, WI)
Assignee: Wisconsin Alumni Research Foundation
H04L43/0835H04L43/028H04L43/04H04L45/742H04L47/20H04L69/22H04L69/12Y02D30/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,397,080
App. No.
15/600,220
Granted
Aug 27, 2019
Kind
B2
Abstract

A network security system for wireless devices derives a fingerprint from the modulation imperfections of the analog circuitry of the wireless transceivers. These fingerprints may be compared to templates obtained when the wireless devices are initially commissioned in a secure setting and used to augment passwords or other security tools in detecting intruders on the network.

Claims (38)

1. A radio frequency (RF) transceiver for securely communicating network data, the RF transceiver comprising:

an analog radio section configured to receive a radio signal from an antenna, the analog radio section having a phase demodulation circuit configured to demodulate the radio signal to produce analog in-phase (I) and quadrature-phase (Q) signals;

a monitor circuit configured to produce digital radiometric data from the analog I and Q signals, the digital radiometric data characterizing a modulation parameter of a transceiver of a device, wherein the modulation parameter provides a measure of a difference between ideal and measured values determined with respect to a constellation producing an error;

an Analog to Digital Converter (ADC) configured to convert the analog I and Q signals to digital I and Q signals;

a digital radio section configured to receive the digital I and Q signals from the ADC, the digital radio section having a decoder configured to match phases of the digital I and Q signals to symbols for decoding network data; and

a processor executing a program stored in a non-transient medium operable to:

receive each of digital radiometric data comprising an error and network data originating from a device;

compare the digital radiometric data comprising the error to a plurality of radiometric templates corresponding to transceivers of a plurality of devices, each radiometric template comprising digital radiometric data characterizing a modulation parameter of a transceiver of a device, wherein the modulation parameter provides a measure of a difference between ideal and measured values determined with respect to a constellation producing an error, wherein the comparison provides a measure of difference between the error of the device and errors of the templates;

authenticate the device when the digital radiometric data matches a radiometric template of the plurality of radiometric templates as determined by the comparison to within a predetermined threshold;

generate an output indicating a possible security violation when the digital radiometric data fails to match a radiometric template of the plurality of radiometric templates as determined by the comparison to within the predetermined threshold.

2. The RF transceiver of claim 1 , wherein the modulation parameter is a symbol phase error, a symbol magnitude error or a symbol error vector magnitude.

3. The RF transceiver of claim 2 , wherein the digital I and Q signals are decoded using Quadrature Phase-Shift Keying (QPSK).

4. The RF transceiver of claim 1 , wherein the digital radiometric data is compared to the plurality of radiometric templates using at least one of: k-nearest-neighbor, support vector machines, decision trees, neural networks, Bayesian-based algorithms, polynomial classifiers, regression fitting, hidden Markov models, Gaussian mixture models, radial basis functions, classifier boosting and classifier ensembles.

5. The RF transceiver of claim 1 , wherein the comparison employs a combination of at least two different comparison algorithms operating independently to make a comparison and then combine the results.

6. The RF transceiver of claim 1 , further comprising, upon the processor matching the digital radiometric data to a radiometric template corresponding to a transceiver of a device, authenticating a network data authenticator assigned to the device.

7. The RF transceiver of claim 6 , wherein the network data authenticator is a password or encryption key.

8. The RF transceiver of claim 6 , further comprising, when the digital radiometric data fails to match a radiometric template of the plurality of radiometric templates, revoking an authorization of the device.

9. The RF transceiver of claim 1 , wherein the analog radio section further includes an amplifier configured to amplify the radio signal from the antenna and a filter configured to remove out-of-band signals from the radio signal.

10. The RF transceiver of claim 1 , wherein the RF transceiver is configured to communicate the network data according to an IEEE 802.11 wireless standard.

11. The RF transceiver of claim 1 , further comprising a Digital to Analog Converter (DAC), wherein the digital radio section further includes an encoder configured to produce digital I and Q signals, wherein the DAC is configured to convert the digital I and Q signals to analog I and Q signals, and wherein the analog radio section further includes a mixer configured to produce a radio signal from the analog I and Q signals.

12. The RF transceiver of claim 1 , wherein the difference is between an ideal vector representing a perfectly modulated quadrature carrier and an actual vector representing a measured point.

13. A method for securely communicating network data using a radio frequency (RF) transceiver having analog and digital radio sections, the method comprising:

receiving a radio signal in the analog radio section from an antenna, the radio signal originating from a device;

demodulating the radio signal in the analog radio section to produce analog in-phase (I) and quadrature-phase (Q) signals;

producing digital radiometric data from the analog I and Q signals, the digital radiometric data characterizing a modulation parameter of a transceiver of a device, wherein the modulation parameter provides a measure of a difference between ideal and measured values determined with respect to a constellation producing an error;

using an Analog to Digital Converter (ADC) to convert the analog I and Q signals to digital I and Q signals;

receiving the digital I and Q signals in the digital radio section from the ADC;

matching phases of the digital I and Q signals to a symbol in the digital radio section for decoding network data; and

receiving each of digital radiometric data comprising the error and the network data at a processor;

comparing the digital radiometric data comprising the error to a plurality of radiometric templates corresponding to transceivers of a plurality of devices, each radiometric template comprising digital radiometric data characterizing a modulation parameter of a transceiver of a device, wherein the modulation parameter provides a measure of a difference between ideal and measured values determined with respect to a constellation producing an error, wherein the comparison provides a measure of difference between the error of the device and error of the templates;

authenticating the device when the digital radiometric data matches a radiometric template of the plurality of radiometric templates as determined by the comparison to within a predetermined threshold; and

generating an output indicating a possible security violation when the digital radiometric data fails to match a radiometric template of the plurality of radiometric templates as determined by the comparison to within the predetermined threshold.

14. The method of claim 13 , wherein the modulation parameter is a symbol phase error, a symbol magnitude error or a symbol error vector magnitude.

15. The method of claim 14 , further comprising the digital I and Q signals being decoded using Quadrature Phase-Shift Keying (QPSK).

16. The method of claim 13 , wherein the digital radiometric data is compared to the plurality of radiometric templates using at least one of: k-nearest-neighbor, support vector machines, decision trees, neural networks, Bayesian-based algorithms, polynomial classifiers, regression fitting, hidden Markov models, Gaussian mixture models, radial basis functions, classifier boosting, and classifier ensembles.

17. The method of claim 16 , wherein the comparison employs a combination of at least two different comparison algorithms operating independently to make a comparison and then combine the results.

18. The method of claim 13 , further comprising, upon the processor matching the digital radiometric data to a radiometric template corresponding to a transceiver of a device, authenticating a network data authenticator assigned to the device.

19. The method of claim 13 , further comprising, when the digital radiometric data fails to match a radiometric template of the plurality of radiometric templates, revoking an authorization of the device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2018
From: BRIK, VLADIMIR; BANERJEE, SUMAN
To: WISCONSIN ALUMNI RESEARCH FOUNDATION
Reel/Frame 047423/0856 →
CONFIRMATORY LICENSE Recorded Nov 14, 2017
From: UNIVERSITY OF WISCONSIN, MADISON
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 044445/0369 →
Continuity (4)
Continuation 12555369 · Sep 8, 2009
Provisional Application 61097406 · Sep 16, 2008
Provisional Application 61095216 · Sep 8, 2008
Related Publication 20170257300A1 · Sep 7, 2017
Cited By (2)
US 12,381,872 US 12,720,046