Ranging and localisation have become critical for many applications and services. The Wi-Fi (IEEE 802.11) standard is a natural candidate for providing these functions across diverse environments, given its widespread deployment. The IEEE 802.11az amendment, finalised in 2023, introduces "Next Generation Positioning" mechanisms to secure and harden the existing insecure Wi-Fi Fine Timing Measurement (FTM) ranging solution. Moreover, the recent IEEE 802.11bk amendment increases the available bandwidth with the goal of approaching the centimetre-level ranging accuracy of ultra-wideband (UWB) systems. This paper examines to what extent these promises hold from a security and deployability perspective. We analyse the core mechanisms of secure Wi-Fi ranging as defined in IEEE 802.11az and IEEE 802.11bk at both the logical and physical layers, combining standards analysis with simulations and measurements on commercial and development hardware. At the logical layer, we show how common deployment choices can result in unauthenticated ranging, downgrade attacks, and simple denial-of-service attacks, making it difficult to securely realise many high-stakes use cases. At the physical layer, we study the predictability of secure ranging waveforms, the security impact of symbol repetition, and how waveform design choices affect compliance with spectral masks under realistic RF behaviour. Our results show that secure Wi-Fi ranging is highly sensitive to configuration choices and is non-trivial to implement on existing hardware. This is also evidenced by the currently limited support for secure Wi-Fi ranging in commodity devices. This paper provides practical guidelines for using secure FTM safely and recommendations to vendors and standardisation bodies to improve its robustness and deployability.
Industrial 5G networks must support missioncritical applications that demand both high performance and reliable communication. Environment-aware communication, enabled by radio environment maps (REMs), is a promising approach to enhance reliability. In this work, we propose a lightweight method for REM construction based solely on reference signal received power (RSRP), which is readily available in commercial 5 G devices. We introduce the concept of relative line-of-sight (RLOS) and relative non-line-of-sight (RNLOS) maps, where each location is classified by comparing measured path loss with the free-space path loss model. Locations exhibiting significant excess loss are marked as RNLOS, while the rest are classified as RLOS. Using data from an indoor industrial 5G deployment, we demonstrate that RSRP alone suffices to generate a static binary REM. The proposed RLOS/RNLOS maps can be integrated into network optimization tasks such as scheduling and resource allocation, thereby improving the reliability of industrial 5G communication with minimal measurement overhead.
The sixth generation (6G) of wireless networks must ensure high reliability, availability, and fairness, even in dynamic and challenging environments. Environmental-aware knowledge, such as that obtained from Radio Environment Maps (REMs), offers predictive insights into channel conditions and can guide more effective scheduling decisions. This paper proposes a scalable deep reinforcement learning (DRL) framework that exploits such knowledge to optimize multi-user scheduling under limited resources, in order to enhance reliability and availability while maintaining fairness. Unlike standard deep Q-network (DQN), which evaluates Q-values per action, we propose a novel learning method that estimates per-user Q-values, enabling user selection with per-decision complexity that scales linearly with the number of users. Simulation results show that the proposed approach consistently balances reliability and availability while maintaining fairness, outperforming Round Robin (RR) and Proportional Fair (PF) schedulers, especially in environments with high clutter density and frequent non-line-of-sight conditions. In particular, the proposed method improves reliability by over 400% with only a 2% drop in availability, compared to the RR scheduler. Relative to PF, it improves availability and fairness by 23% and 40%, respectively, without sacrificing reliability. These improvements are observed under balanced propagation conditions, where the probabilities of line-of-sight and non-line-of-sight are equal due to a clutter density of 50%. These results highlight the potential of the proposed environmental-aware DRL scheduler to support trustworthy 6G communication in complex and dynamic environments.
In wireless communications, trustworthiness computation has emerged as a crucial aspect of safeguarding modern systems against cybersecurity threats, ensuring reliable data transmission and upholding user trust. However, there is no unified definition of trustworthiness computation in the literature, and it is often presented as a specifically tailored adaptation of attack detection mechanisms. In contrast, this work introduces a general method for trustworthiness computation in wireless networks. It leverages key system characteristics, such as the channel, timing, and packet information to identify measurable Quality of Service (QoS) features with sufficient sensitivity across varying operational conditions. Building on these features, a novel three-step approach is applied. It employs changepoint detection to identify potential trustworthiness issues, calculates indicators based on the observed features, and finally combines them into a quantitative representation of trustworthiness. This systematic method effectively distinguishes between regular statistical variations in QoS features and actual trustworthiness issues. The applicability of the presented approach is demonstrated using a typical IEEE 802.11 wireless link, where different QoS features and scenarios are defined. These scenarios include network attacks, system malfunctions, and typical operational conditions. Our trustworthiness computation method correctly alerts the system to all trustworthiness issues that we challenge it with.
Trustworthiness assessment is an essential step to assure that interdependent systems perform critical functions as anticipated, even under adverse conditions. In this paper, a holistic trustworthiness assessment framework for ultra-wideband self-localization is proposed, including the attributes of reliability, security, privacy, and resilience. Our goal is to provide guidance for evaluating a system's trustworthiness based on objective evidence, i.e., so-called trustworthiness indicators. These indicators are carefully selected through the threat analysis of the particular system under evaluation. Our approach guarantees that the resulting trustworthiness indicators correspond to chosen real-world threats. Moreover, experimental evaluations are conducted to demonstrate the effectiveness of the proposed method. While the framework is tailored for this specific use case, the process itself serves as a versatile template, which can be used in other applications in the domains of the Internet of Things or cyber-physical systems.
AbstractThanks to low complex and affordable hardware, low power consumption, and pulse-based communication, ultra-wideband (UWB) technology has brought the possibility of positioning in wireless networks for various applications with high precision. Nowadays, the widespread use of this technology for location-based applications together with the integration of this technology in smartphones, motivates more research on the use of this technology for localisation systems. Current research results emphasize that artificial intelligence (AI) algorithms can help to improve the positioning performance of UWB technology due to the use of large amounts of data. In this work, we provide an overview of the challenges and their AI-based solutions in UWB-based localisation systems. This is followed by an overview of related work and an application example.
While ultra-wideband (UWB) technology provides additional connectivity and location awareness to the Internet of Things (IoT), its complexity requirements severely limit its application. To enable wider use of UWB in IoT applications, we are advancing angle of arrival (AoA) estimation for this technology. A hardware-efficient AoA estimation method for UWB devices is presented and experimentally evaluated. Instead of using N parallel receive chains, the antenna signals are connected to linearly increasing delay lines and summed afterward. Hereby, compressive sampling is key to using only a single transceiver and passive components to obtain AoA estimates. As proof of concept, a prototype array and combiner network utilizing the Qorvo DW1000 UWB transceiver was developed, and the linear model is estimated based on a reference measurement in an anechoic chamber. Experiments conducted in a real-world environment, resulting in a root mean square error of 5.9 degrees within an 80 degrees field of view, demonstrated that this hardware-efficient method is practically feasible.
The constraints imposed by the computational and energy capabilities of Internet of Things (IoT) devices are challenging for ensuring secure communication between these devices. One promising solution to address these security challenges is leveraging Physical Layer Security (PHYSEC) principles. This paper investigates in the area of PHYSEC, particularly focusing on the utilization of channel reciprocity for generating a secret key, commonly referred to as Physical Layer Secret Key Generation (PSKG), in Ultra-Wideband (UWB) technology. PSKG usually contain an Information Reconciliation (IR) stage to improve the probability for identical keys, which comes with substantial computational and communication cost. The primary objective of this paper is to eliminate this IR stage and its associated costs while still achieving a high probability for identical keys. To accomplish this goal, we propose a Pre-Processing (PP) stage involving a Discrete Fourier Transform (DFT)-based approach. This approach extracts reciprocal randomness from the Channel Impulse Response (CIR). By exploiting the CIR and our proposed PP stage, we were able to slightly improve the key generation rate while reducing the probability of successful attacks by a significant 87% in dynamic environments compared to the state-of-the-art. Notably, our approach does not require a training phase, making it more efficient for IoT devices.
A joint angle-of-arrival (AoA) and ranging estimation scheme for ultra-wideband devices is presented and experimentally evaluated. Instead of using N parallel receive chains, antenna elements are sequentially switched to the receiver, i.e., time-multiplexed. To obtain time-multiplexed measurements, a special messaging scheme is proposed that extends the conventional double-sided two-way-ranging scheme by a number of response packets that is equivalent to the number of antenna elements. Thereby, each response packet—switched through a different receive antenna—is used to record the complex-valued channel impulse response, which contains the phase information later utilized for AoA estimation. Ranging is jointly obtained through recorded receive and transmit timestamps. As the time-multiplexing introduces significant delays between phase measurements, even small synchronization errors would cause significant AoA errors. Hence, the critical building block is the clock drift compensation. The experimental evaluation with a DW1000 UWB chip and four switched λ/2 spaced antennas shows an angular accuracy of 5.5° RMSE and the capability of accurate 2-D localization.
We present a trustworthiness score for double-sided two-way ranging on ultra-wideband devices. It serves as quantitative measure for assessing the reliability and security aspects of ranging. Leveraging the trustworthiness score, we propose two localization schemes that utilize the weighted non-linear least squares approach. The computation of the trustworthiness score relies on an autoencoder model trained on trustworthy data. To evaluate the performance of our trustworthiness score, we conduct indoor localization experiments that include channel manipulations such as line-of-sight obstructions and timestamp attacks resembling the well-known Cicada attack. The incorporation of trustworthiness led to an improvement in localization accuracy, reducing the root mean square error (RMSE) by up to 50% in the dynamic scenario.
Contact tracing is an accepted means to keep track of human infection chains during epidemics. Contact tracing smartphone apps such as deployed during the recent COVID-19 pandemic are widely based on distance estimation by privacy-preserving use of Bluetooth Low Energy (BLE). Yet, the BLE received signal strength indicator used for distance estimation is too weakly correlated with the distance in real scenarios. Major impacting factors are varying body shielding and signal propagation characteristics of the environment. We present a method that adjusts the common BLE pathloss model with a context factor, which can be experimentally derived based on phone carry position and environment detection. Experiments with a smartphone testbed show that the distance estimation error can be reduced to about 1 m for four major carry positions in short-distance indoor and outdoor settings. This result is an encouraging first step towards reliable privacy-preserving contact tracing.
The computation of data trustworthiness during double-sided two-way-ranging with ultra-wideband signals between IoT devices is proposed. It relies on machine learning based ranging error correction, in which the certainty of the correction value is used to quantity trustworthiness. In particular, the trustworthiness score and error correction value are calculated from channel impulse response measurements, either using a modified k-nearest neighbor (KNN) or a modified random forest (RF) algorithm. The proposed scheme is easily implemented using commercial ultra-wideband transceivers and it enables real time surveillance of malicious or unintended modification of the propagation channel. The results on experimental data show an improvement of 47% RMSE on the test set when only trustworthy measurements are considered.
A stepwise feature labeling method for UWB ranging is presented, which allows better separation of LOS and NLOS components in the training data. The packet-by-packet range error evaluation is used as input of the labeling function instead of the conventionally used double-sided two-way ranging result which relies on a cycle of three packets. To assess the packet-wise error, a two-step synchronization scheme is proposed. First, the clock model between anchor and tag is estimated by a least-squares approach. Second, the remaining bias is corrected by determining the time-shift between the channel impulse responses recorded by both nodes. The evaluation of measurement data shows a significant improvement in classification between LOS and NLOS, as well as slightly improved ranging accuracy when used to train a binary classifier.
In this paper, we show that our recently proposed method to enhance distance bounding (DB) by time difference of arrival (TDOA) measurements improves the security of current DB protocols by reducing their uncertainty area (UA). DB protocols are employed such that a verifier node can authenticate a prover node and at the same time ensure that the prover is close enough to the verifier. TDOA-Enhanced DB increases the security of existing DB protocols by the use of passively listening verifiers, that are employed additionally to the DB primary verifier. We verify our proposed method with measurements in a laboratory setup with hardware that is equipped with Qorvo DW1000 Ultra-Wideband transceivers. We also derive the Crámer-Rae Lower Bound for TDOA with different noise sources and compare it with the measurements to calculate the TDOA-Enhanced UA. By performing a TDOA-Enhanced location verification, we show that an UA reduction is possible in 78% of positions in a 20m x 20m square. This significantly reduces the probability of a successful attack at the physical layer of DB protocols.
This paper proposes two deep-learning (DL)-based approaches to a physical tamper attack detection problem in orthogonal frequency division multiplexing (OFDM) systems with multiple receiver antennas based on channel state information (CSI) estimates. The physical tamper attack is considered as the unwanted change of antenna orientation at the transmitter or receiver. Approaching the tamper attack scenario as a semi-supervised anomaly detection problem, the algorithms are trained solely based on tamper-attack-free measurements, while operating in general scenarios that may include physical tamper attacks. Two major challenges in the algorithm design are environmental changes, e.g., moving persons, that are not due to an attack and evaluating the trade-off between detection performance and complexity. Our experimental results from two different environments, comprising an office and a hall, show the proper detection performances of the proposed methods with different complexity levels. The optimal proposed method achieves a 93.32% true positive rate and a 10% false positive rate with a suitable level of complexity.
This letter proposes a deep learning approach to detect a change in the antenna orientation of transmitter or receiver as a physical tamper attack in OFDM systems using channel state information. We treat the physical tamper attack problem as a semi-supervised anomaly detection problem and utilize a deep convolutional autoencoder (DCAE) to tackle it. The past observations of the estimated channel state information (CSI) are used to train the DCAE. Then, a post-processing is deployed on the trained DCAE output to perform the physical tamper detection. Our experimental results show that the proposed approach, deployed in an office and a hall environment, is able to detect on average 99.6% of tamper events (TPR = 99.6%) while creating zero false alarms (FPR = 0%).
We propose to add a monitoring system consisting of so-called path-and guard nodes to industrial wireless sensor networks (IWSNs), to increase the security level by using receive signal strength indicator (RSSI) measurements. Via these measurements, the monitoring system determines the presence of a mobile sensor node in a predefined area, which can be used to handle access rights and to increase automation capabilities in industrial applications. We add this monitoring system to an IWSN based on the EPhESOS protocol, which has a high degree of flexibility to meet industrial requirements in different applications throughout the lifetime of a sensor node while enabling energy-autonomous operation. Two practical machine learning algorithms for RSSI-based presence detection are presented, namely a support vector machine and a neural network algorithm. They are evaluated in an automotive example and tested for their robustness against malicious attacks. Additionally, a method to find the best node locations of the monitoring system is presented.
Cooperative localization increases the accuracy of location estimates especially in networks with sparse anchor deployment. In this work, its implementation in low-cost low-power wireless sensor networks is presented. A WSN hardware platform with ultra-wideband ranging and communication is shown and the application of a belief propagation based cooperative localization algorithm discussed. With a simple channel access scheme and a standard ranging method, the main sources of error are discussed and indoor evaluations of the system are conducted.
In this paper, a new method to secure non-ideal distance bounding techniques using time difference of arrival measurements is presented. Accurate and secure localization is crucial for many applications of real life wireless sensor networks, and extensive research has been dedicated to this topic in recent years. Distance bounding protocols are employed such that a verifier node can authenticate a prover node and at the same time ensure that the prover is close enough to the verifier. In order to increase the robustness of existing distance bounding protocols to attacks such as “early detect” or “late commit the use of passively listening verifiers that are employed additionally to the distance bounding primary verifier is studied. In such a way an extended set of measurements is obtained. The proposed approach is able to prevent those attacks. We study the presence of some vulnerabilities in our method and we show a way to prevent them.
A new algorithm for determining soft range information in network localization is proposed. It applies a variant of neural networks called mixture density networks. When used in particle-based Bayesian localization procedures, it has a similar low computational complexity and provides comparable localization accuracy as existing methods. This property enables the proposed algorithm to be implemented on low-power wireless sensor network (WSN) nodes that are equipped with commercial ultra-wideband transceivers. The proposed algorithm is validated in indoor network localization experiments.