Underwater Visible Light Communication (UVLC) is promising due to its relatively strong penetration capability in water and large frequency bandwidth. Visible Light Communication (VLC) is also considered a safer wireless communication paradigm as light signals can be constrained within the area of interest with obstacles such as walls, reducing the chance of potential attack. However, this intuitional security assumption is not true anymore in underwater environment. Recent research shows that the eavesdropping risk of UVLC is more severe than we thought, attributed to the divergence and scattering effects of light beams in water. In this paper, we harness the dynamic nature of underwater environments as a true random resource to extract symmetric keys for UVLC. Specifically, the proposed AquaKey system incorporates instantaneous bidirectional channel probing, computation of relative channel characteristics, and an environment-adaptive quantization algorithm. The above design addresses unique challenges caused by the dynamic underwater environment, including self-interference, high-frequency disturbance, and mismatch, ensuring the practicality and applicability of AquaKey. Additionally, AquaKey has negligible impact on communication and has no effect on the illumination function. Through extensive real-world experiments, we show that AquaKey can achieve reliable key extraction with cheap hardware, generating a 512-bit key in just 0.5-1 seconds.
Underwater Visible Light Communication (UVLC) is promising due to its relatively strong penetration capability in water and large frequency bandwidth. Visible Light Communication (VLC) is also considered a safer wireless communication paradigm as light signals can be constrained within the area of interest with obstacles such as walls, reducing the chance of potential attack. However, this intuitional security assumption is not true anymore in underwater environment. Recent research shows that the eavesdropping risk of UVLC is more severe than we thought, attributed to the divergence and scattering effects of light beams in water. In this paper, we harness the dynamic nature of underwater environments as a true random resource to extract symmetric keys for UVLC. Specifically, the proposed AquaKey system incorporates instantaneous bidirectional channel probing, computation of relative channel characteristics, and an environment-adaptive quantization algorithm. The above design addresses unique challenges caused by the dynamic underwater environment, including self-interference, high-frequency disturbance, and mismatch, ensuring the practicality and applicability of AquaKey. Additionally, AquaKey has negligible impact on communication and has no effect on the illumination function. Through extensive real-world experiments, we show that AquaKey can achieve reliable key extraction with cheap hardware, generating a 512-bit key in just 0.5-1 seconds.
While out-vehicle sensing has achieved great success with the development of vehicle radar and Lidar systems, in-vehicle sensing attracts a lot of attention recently. However, the popular camera-based solutions raise privacy concerns and pose requirement on lighting conditions. Researchers recently utilize wireless signals for sensing. However, besides requiring dedicated hardware, the rich multipath in a small cabin space causes severe interference, degrading the sensing reliability. In this paper, we propose a new sensing modality for in-vehicle sensing, leveraging the leaked EM signals from electric vehicles. The key observation is that the human body can capture the leaked signals, and body motions affect the signal variation patterns. Our solution involves designing conductive cloth tags on the seat to effectively collect body-captured signals and adopting a reference tag to deal with interference. Through extensive experiments conducted over 100 hours, covering a driving distance of 4000 kilometers on various real roads, our system, EVLeSen, can achieve over 90% accuracy in recognizing body motions utilizing just the leaked ambient signals.
Since the first successful wireless transmission across the Bristol Channel in 1897, wireless technologies have revolutionized the way we live, work and interact with the world. Besides the traditional communication function (e.g., Wi-Fi), wireless signals are further utilized for other functions such as localization, sensing and even charging. While promising in many aspects, one critical issue associated with these new functions is that they require dedicated signal transmissions, which interfere the original communication function. Take popular Wi-Fi sensing as the example. 200-1000 dedicated Wi-Fi packets per second need to be transmitted to enable Wi-Fi sensing which significantly decrease the throughput of ongoing Wi-Fi communication. Thus, I ask this question: "can we utilize ambient, non-dedicated wireless signals to realize the aforementioned functions?" For my Ph.D thesis, I harness the pervasive ambient leakage signals traditionally considered detrimental to enhance the performance of wireless communication and enable new functions such as sensing and charging. My thesis is inspired by the key observation that there exist a large amount of leakage RF signals in our surroundings. For example, the powerlines continuously emit out 50/60 Hz electromagnetic (EM) signals due to the alternating current flowing inside. The operation of electric vehicles leaks RF signals in th frequency range of hundreds of hertz. One of the key wireless technologies in the next generation 6G networks, i.e., visible light communication (VLC) which relies on quickly turning ON/OFF the LED light also emit out RF leakages due to the quick ON/OFF state change. In my thesis, through novel designs across both hardware and software, I turn these ambient leakages from foes to friends. Enhancing the security and throughput of wireless communication. Visible Light Communication is considered a key component of the 6G networks owing to its potential high data rates, pervasiveness of commodity LEDs, and minimal interference on existing RF communication. For the first time, we showed that during the transmission of VLC, the transmitter not only emits out visible light signals but also leaks out RF signals [1]. The underlying principle behind this leaked signal is the intensity modulation scheme commonly adopted in VLC systems. As illustrated in Figure 1, in VLC, data bits '0' and '1' are represented by switching 'OFF' and 'ON' the LED, which leads to quick alterations of the current flow. These changing electric currents induce EM signal leakages. We developed a theoretical model to quantify the relationship between the amplitude of these leaked RF signals and the ON/OFF frequency. We show that while LED light signals can be easily constrained within an area of interest (e.g., a room with walls), the leakage RF signal can penetrate through walls. What's more interesting is that the leakage RF signal contains a copy of the data transmitted in the light signals and this finding renders VLC-the generally believed most secure wireless technology-not secure any more as illustrated in Figure 2. Building upon this finding, we further demonstrate a novel utilization of these leaked signals for carrying extra data [2] to double the data rate of existing VLC systems. In this design, data is transmitted through the leaked RF signal without a dedicated active RF front-end, reducing both power and hardware costs. We show through experiment that the free leaked RF signals can be leveraged to transmit extra data at a data rate even higher than the primary VLC channel. Harvesting the leaked energy for far-field charging. Following the successful utilization of VLC leakage signals for communication, we further view the leaked signals as a form of wasted energy and devote our effort to harvesting it [3]. The key observation enabling us to achieve this objective is that the surrounding objects can help significantly boost the amount of energy harvested. What is more exciting is that not just the ordinary objects such as walls and furniture can help enhance energy harvesting, the human body can also increase the amount of harvested energy. When the receiver antenna is in contact with a human body, the amount of harvested energy is increased by more than ten times. Based on this key observation, we propose our system, Bracelet+, which involves human body into the ecosystem of energy harvesting for the first time as depicted in Figure 3. We design the coil antenna as a bracelet so a person can wear it comfortably. The harvested power can reach up to micro-watts, holding promise for powering low-power body sensors and enabling body sensor network. Note that this far-field (i.e., a separation of a few meters between the target and the power source) wireless charging modality is very different from existing near-field wireless charging with the target and power source separated by just a few centimeters. Enabling a novel sensing modality. After we successfully utilized leaked signals for communication and charging, we move forward to utilize the leaked signals (i.e., the powerline leakage) for sensing purposes [4]. This electromagnetic leakage, stemming from alternating current in powerlines, is governed by Maxwell's Equations. However, the ultra-low frequency (60 Hz) of the leakage renders existing wireless sensing models inapplicable. Specifically, current wireless sensing modalities rely on the fact that signal propagation is affected by human's motions and thus by analyzing the induced signal variation, the information of the human motion can be inferred. However, for leaked signal which is extremely low-frequency, the propagation of the signal is not affected by human motions. Owing to the antenna's unique property (i.e., coil shape) for low frequency signals, we design the antenna as a ring and combine the human target and ring antenna together as a "human antenna" as shown in 4(a) to sense the human target's gesture. Although the human target's gesture does not affect the signal propagation, it affects the antenna and accordingly affects the received signal. We can thus utilize the signal variation for sensing. One unique advantage of this sensing modality is that although the ring is only in contact with the target's finger, it can sense the motion of the whole body. This new sensing modality is demonstrated to be able to support a large range of sensing applications such as gesture recognition, sleep posture sensing, and fall detection. Besides powerline leakage, we also leverage the EM leakage from electric vehicles (EVs) to enable in-vehicle sensing [5]. We observe that numerous components within the EVs including battery, powerline, and power inverter, emit EM signals during their operation. We thus use the leakage to sense the body motions of the driver/passenger without any dedicated signal transmitters. To address the unique challenge in car environment, i.e., the interfering car motions, we adopt a reference tag design, making the proposed sensing modality practical in real-world settings. Extensive experiments with a driving distance of 4000 kilometers under diverse real-world road conditions show that the proposed sensing system can achieve an accuracy over 90% in recognizing body motions solely utilizing ambient leakage signals. To summarize, we innovatively utilize pervasive leakage signals for wireless communication, far-field charging, and wireless sensing, achieving the following contributions: center dot We explored different types of leakage signals in our surroundings and demonstrated the application of the "bad" leakage signals in communication, charging and sensing. center dot Through deeply understanding the signal characteristics, we propose models to lay the theoretical foundation for utilizing the leakage signals for communication, charging and sensing.
Wireless sensing has demonstrated its potential of utilizing radio frequency (RF) signals to sense individuals and objects. Among different wireless signals, LoRa signal is particularly promising for through-wall sensing owing to its strong penetration capability. However, existing works view walls as a "bad" thing as they attenuate signal power and decrease the sensing coverage. In this paper, we show a counter-intuitive observation, i.e., walls can be used to increase the sensing coverage if the RF devices are placed properly with respect to walls. To fully understand the underlying principle behind this observation, we develop a through-wall sensing model to mathematically quantify the effect of walls. We further show that besides increasing the sensing coverage, we can also use the wall to help mitigate interference, which is one well-known issue in wireless sensing. We demonstrate the effect of wall through two representative applications, i.e., macro-level human walking sensing and micro-level human respiration monitoring. Comprehensive experiments show that by properly deploying the transmitter and receiver with respect to the wall, the coverage of human walking detection can be expanded by more than 160%. By leveraging the effect of wall to mitigate interference, we can sense the tiny respiration of target even in the presence of three interferers walking nearby.
Radio-Frequency (RF) backscatter has emerged as a low-power communication technique. Backscatter systems either rely on active signal generators (spectrum efficient, but dedicated infrastructure) or existing ambient wireless transmissions (existing infrastructure, but spectrum inefficient). In this paper, we aim to make RF backscatter spectrum efficient and at the same time work with existing infrastructure. We propose to leverage the deployment of LiFi networks built upon LED bulbs for pervasive RF backscatter. We experimentally demonstrate that LiFi, which passively leaks RF signals, can be exploited as a radio carrier generator for low-power RF backscatter. We further design LeakageScatter, the first backscatter system operating in the ISM band and exploiting LiFi-leaked RF signals, without the need to actively generate the carrier wave. We customize the design of the loop at the LiFi transmitter, as well as the coil antennas at the tag and RF backscatter receiver, to optimize the system performance. We propose to opportunistically enable the oscillator of the backscatter tag in the software that could reduce the energy consumption on backscattering by up to 75%. Experimental results show that LeakageScatter achieves a backscattering distance up to 10 m and 18 m in indoor and outdoor scenarios, respectively, without using a dedicated RF carrier generator.
In recent years, wireless sensing has attracted lots of research attention with a large range of applications enabled. However, several critical issues still hinder wireless sensing from being adopted in daily use: (a) requiring dedicated devices and (or) dedicated signals; (b) limited sensing coverage; and (c) affecting the original function of the wireless technology (e.g., communication). In this work, we propose a new sensing modality, i.e., leveraging the pervasive powerline leakage for sensing. The key observation is that human body can capture such leaked signals, and the received signals vary with body gestures. We design a cheap ring antenna to collect the powerline leaked signals at human body and establish a body-empowered model to sense body motions. We prototype the proposed system with designs spanning both hardware and software. Comprehensive experiments show that the proposed sensing modality can realize a large range of applications in a different way from existing sensing methods. We showcase the powerful capability of this sensing modality using three typical sensing applications: body gesture recognition, sleep posture sensing, and fall detection.
Wireless sensing is capable of capturing rich information of human target without requiring sensors attached to the target. Although promising, two critical issues still exist, i.e., (i) limited sensing range, and (ii) severe interference in real-world settings. Recently, LoRa is employed to improve the sensing range. Although LoRa sensing is able to achieve a longer sensing range than WiFi and acoustic sensing, it is still limited to tens of meters. In this paper, we propose ChirpSen, which fully exploits the property of chirp signal to increase the sensing range. ChirpSen adopts a chirp concentration scheme to concentrate the power of all signal samples in a LoRa chirp at one timestamp, improving the signal power and accordingly boosting the sensing range. With a longer sensing range, the interference issue also becomes more severe. We propose a novel scheme to flexibly control the sensing coverage by tuning the LoRa chirp length in software. Real-world experiments show that ChirpSen is able to increase the detection range of a small size drone (12 cm × 10 cm × 8 cm) from 18 m to 160 m. ChirpSen is capable of monitoring a human's respiration rate at 138 m and tracking a human target's walking trajectory 210 m away.
Recent studies show that the transmitters of Visible Light Communication (VLC) - a promising technology for future 6G networks - not only emit visible light signals but also leak RF signals during transmissions. In this work, we aim to harvest energy from these leaked RF signals. We observe that surrounding objects could help harvest significantly more energy. Based on this observation, we design Bracelet+, which involves the human body as part of the antenna to increase the harvested energy. We prototype our antenna as a bracelet that achieves both high harvested power and convenience for wearing. Bracelet+ improves the average harvested energy by 10x more, achieving micro-watt power harvesting and having potential to power up ultra-low-power sensors such as temperature and glucose sensors.
Visible Light Communication (VLC) is widely considered a promising technology for the coming 6G networks. Recent studies show that a VLC transmitter not only emits visible light signals but also leaks RF signals during the transmission. In this work, we devote effort to harvesting the free leaked RF energy from VLC transmissions. We observe that the surrounding objects could help a coil antenna harvest significantly more RF energy. Based on this observation, we propose our system Bracelet+, which involves the human body in the harvesting system to increase the harvested power. After careful analysis of the influence of the human body on the harvested power, we prototype the coil antenna as a bracelet that achieves both high harvested power and convenience for wearing. The average power of the RF energy harvested by our design is 10× larger than that of the conventional coil antenna, without causing any interference to the communication of VLC systems. The harvested power can reach up to micro-watts in our tested scenarios. Such a micro-watt level of harvested energy has the potential to power up ultra-low-power sensors such as temperature sensors and glucose sensors.
Visible Light Communication (VLC) is considered a new paradigm for next-generation wireless communication. Recently, studies show that during the process of VLC transmission, besides the visible light signals, the transmitter also leaks out RF signals through a side channel. What is interesting is that the data transmitted in the VLC channel can be inferred from the leaked RF signals. Fundamentally, it means the leaked RF signals carry a copy of the same data in the VLC channel. In this work, we show for the first time that besides inferring the original VLC data, the leaked side channel can be smartly leveraged to carry new data, significantly increasing the data rate of current VLC systems. To realize this objective, we propose a system named RadioInLight, with designs spanning across hardware and software. Without any dedicated active RF transmission front-end which consumes power and hardware resources, RadioInLight is able to double the data rate of the VLC system by purely manipulating the free passively leaked RF signals without affecting the data rate of the original VLC transmissions.
Visible light communication (VLC) is gaining a significant amount of interest as a new paradigm to meet rapidly increasing demands on wireless capacity required by a digitalized world. VLC is considered as a secure wireless communication scheme because VLC signals can be easily constrained within physical boundaries. In this paper, for the first time, we show that VLC is not as secure as people thought: VLC can be sniffed through walls! The key principle behind this is that in VLC transmissions, a VLC transmitter not only emits visible light signals but also leaks out 'side channel RF signals'. The leaked RF signals can be sniffed by a receiver to decode the VLC transmissions even the receiver is blocked (e.g., by walls) from the VLC transmitter. In this work, we establish a theoretical model to quantify the amplitude of the leaked RF signal and verify the model with comprehensive experiments. We design and implement a VLC sniffing system including receiver coil design, signal processing and frame decoding, spanning across hardware and software. Field studies show that with a cheap receiver design, our system can simultaneously sniff transmissions from multiple VLC transmitters 6.4 meters away with a 14 cm concrete wall in between, where the distance exceeds the communication range of most state-of-the-art VLC systems. By simply twining a wired earphone on the arm, we can sniff the VLC transmission 1.9 meters away.
Visible Light Communication (VLC) is a promising technology for future wireless communications. By modulating the visible light---that has about 10,000x larger frequency band than that of radios---to transmit data, VLC has the potential to provide ultra-high-speed wireless connectivities. However, it also has limitations such as i) surrounding objects can easily block VLC links, and ii) intense ambient light can saturate the photodiodes of VLC receivers. In this work, from a different angle compared with state-of-the-art solutions, we utilize the side channel of VLC---a Radio Frequency (RF) channel created unintentionally during the transmission process of VLC---to break the above-mentioned VLC limitations. The key enabler is that the side RF channel also contains the data information transmitted in the VLC link. When the VLC link is blocked or saturated, we can utilize the side channel, capable of penetrating through blockages and not affected by ambient light, to assist VLC transmissions. Thus a user service relying on VLC transmissions will not be interrupted. Besides the simple Single-Input Single-Output (SISO) case, we consider challenging scenarios where multiple VLC chains are synchronized to form Multiple-Input Multiple/Single-Output (MIMO/MISO) transmission strategies. To make our system practical, we address several challenges spanning from hardware to software. Compared to state-of-the-art design, we reduce the size of the receiving coil by nearly 90%. Experimental evaluations show that our system can decode overlapped RF signals created by a 3X3 MIMO VLC network five meters away, with various blockages in between. Our system also works under intense ambient light conditions (> 100,000 lux).
Investigating the mechanisms of various attacks in vehicular ad hoc networks (VANETs) provides fundamental basis to develop safeguard techniques for network security issues. As they develops, attacking strategies are also needed to be established for people to learn how to defend. Previous works failed to consider multiple victims recovery and minimum road side units (RSUs) deployment issues. In this paper, we approach the attacking strategy from an adversarial point of view and develop a trajectory tracking and recovering attack based on matrix completion (TTRA). By randomly sampling locations of vehicles, TTRA is capable of recovering locations of any user with tolerable deviation. After that, the problem of how to minimize the number of RSUs while tracking all vehicles in the whole region is also considered by converting this problem into set covering problem. A heuristic algorithm based on hierarchical clustering is proposed accordingly. To the best of our knowledge, this is the first attempt of recovering mobile users' trajectories by applying these novel techniques. Finally, simulation analysis is used to show the performance of the proposed scheme. Simulation results demonstrate the merits of the scheme in terms of tracking results, location error, and influences of sampling ratio, among others.