In this paper, we investigate the pertinence of the angle of arrival (AoA) as a feature for robust physical layer authentication (PLA). While most of the existing approaches to PLA focus on amplitude-dependent features of the physical layer of communication channels, such as channel frequency response, channel impulse response, or received signal strength, the use of AoA in this domain has not yet been studied in depth, particularly regarding the ability to thwart spoofing (impersonation) attacks. In this work, we demonstrate that an impersonation attack targeting AoA-based PLA is only feasible under strict conditions on the attacker's location, which highlights the AoA's role as a strong feature for unspoofable PLA, especially when 2D AoA is employed. We extend previous works considering a single-antenna attacker to the case of a multiple-antenna attacker, and we develop a theoretical characterization of the conditions under which a successful impersonation attack can be mounted. Furthermore, we have performed extensive simulations in support of theoretical analyses, to validate the robustness of AoA-based PLA.
Integrated sensing and communication (ISAC) is a promising feature of future communication networks. While spatial sensing can improve network performance and enable external services, it also creates privacy challenges that go beyond the confidentiality of communication content. Future networks using millimeter-wave (mmWave) and sub-terahertz (THz) frequencies may collect or infer detailed information about people, devices, bystanders, passive objects, and environments in a sixth-generation (6G) deployment area. Such sensing can reveal location and environment data, support behavioral profiling such as movement or activity recognition, and, in advanced cases, expose physiological information such as breathing frequency or heart-rate-related data. Thus, the capabilities of spatial sensing must be controlled to satisfy privacy requirements. In this work, we organize privacy-sensitive ISAC data into three sensing levels: location and environment data, behavioral data, and physiological data, and use this classification as the organizing principle throughout the paper. Based on this classification, we discuss internal and external ISAC applications, identify privacy challenges related to consent, transparency, data ownership, profiling, bystander exposure, and sensitive sensing data, review representative solution directions, and outline future research directions for privacy-preserving ISAC.
The advent of multi-user multiple-input multiple-output (MIMO) resulted in space division multiple access (SDMA), enabling concurrent service to multiple users via spatially directed beams. The rise of massive MIMO in fourth generation (4G)/fifth generation (5G) has greatly enhanced SDMA by enabling narrower beams, allowing a larger number of users to be served simultaneously in the same time-frequency slot. As a natural evolution, massive MIMO transitions to extreme MIMO, and larger antenna apertures push typical urban macro cellular areas into the near-field region, invalidating planar wave models and necessitating spherical ones. This shifts multiple access in mobile communications from traditional beamforming to beam focusing. Unlike in the current massive MIMO-based SDMA system, where users are primarily separated by angular bins, in a near-field extreme MIMO system, users can be separated by distance and angular bins. This work advances multiple access strategies by providing the technical foundation for accurate signal focusing within three-dimensional (3D) spatial volumes, called volumetric beam focusing. Specialized near-field beam profiles, notably Bessel beams and the proposed Padé–Bessel beams, facilitate accurate signal focusing within 3D spatial volumes. This work also provides key techniques for implementing volumetric beam focusing with phased antenna arrays and evaluates the performance of Bessel and Padé–Bessel beams across multiple scenarios.
Device identifiers like the International Mobile Equipment Identity (IMEI) are crucial for ensuring device integrity and meeting regulations in 4G and 5G networks. However, sharing these identifiers with Mobile Network Operators (MNOs) brings significant privacy risks by enabling long-term tracking and linking of user activities across sessions. In this work, we propose a privacy-preserving identifier checking method in 5G. This paper introduces a protocol for verifying device identifiers without exposing them to the network while maintaining the same functions as the 3GPP-defined Equipment Identity Register (EIR) process. The proposed solution modifies the PEPSI protocol for a Private Set Membership (PSM) setting using the BFV homomorphic encryption scheme. This lets User Equipment (UE) prove that its identifier is not on an operator's blacklist or greylist while ensuring that the MNO only learns the outcome of the verification. The protocol allows controlled deanonymization through an authorized Law Enforcement (LE) hook, striking a balance between privacy and accountability. Implementation results show that the system can perform online verification within five seconds and requires about 15 to 16 MB of communication per session. This confirms its practical use under post-quantum security standards. The findings highlight the promise of homomorphic encryption for managing identifiers while preserving privacy in 5G, laying the groundwork for scalable and compliant verification systems in future 6G networks.
Side-channel analysis (SCA) exposes vulnerabilities in cryptographic circuits by exploiting physical leakage such as power or electromagnetic emanations. Deep learning (DL) has significantly improved SCA, but most architectures, such as CNNs, struggle to generalize under practical conditions like masking and temporal misalignment. This paper investigates a transformer-based approach that uses a pretrained BERT pathway for plaintext and a linear embedding for traces, fused for masked S-box classification. A dual-path late-fusion architecture combines trace and plaintext embeddings to predict masked AES S-box values. Experiments on ASCAD variable-key datasets show key-rank 0 recovery with only 9 traces in the aligned case and robustness under desynchronization (305 and 444 traces for desynchronization 50 and 100). We further analyze the impact of the size of the training set and the model components, showing that removing positional encoding improves performance by 18.7% and that the optimal profile size lies between 60-90k traces. The results demonstrate that attention-based models can effectively evaluate circuit leakage, providing insight into countermeasure design for secure embedded systems. PoI-optimized methods (e.g., EstraNet) achieve 5-7 traces on selected windows; under our stricter fixed-window, full-key, cross-desync protocol we reach a closely comparable 9 traces (aligned), prioritizing protocol efficiency over PoI-specific tuning.