This work presents ENDURE (Efficient aND lightweight group key generation scheme Using sensoR randomnEss), a group key generation scheme for a system consisting of multiple low-resourced sensor-tags attached to an asset to monitor its position and condition. To minimise energy consumption we use broadcast messaging which places more strict constraints on the generation of group keys. Prior group key generation schemes were not appropriate due to shared pseudorandom numbers being accessible to attackers, and their source of randomness being vulnerable to environmental noise and thus infeasible. We generate keys reusing the condition monitoring data already collected by our application and demonstrate that our approach guarantees high entropy. The robustness of the group keys is evaluated via three standard metrics; key generation rate, key disagreement rate (KDR), and entropy, which respectively measure how many bits can be generated, how different the key is from one which can be generated by an attacker overhearing the communication, and how random it is. We implemented ENDURE on resource constrained wireless sensor microcontrollers to generate keys from real sensor data. While typical acceptable KDRs are 20%, our scheme exhibits a strong performance with KDR values up to 65%. for sensing and communication.
Sensing ego-velocity estimation is fundamental to state estimation in visually degraded environments, where camera- and LiDAR-based pipelines can become unreliable. Millimetre-wave radar is well suited to these conditions because it provides direct Doppler velocity sensing and remains robust to poor illumination, textureless scenes, and airborne particulates. However, conventional radar ego-velocity pipelines typically apply constant false alarm rate (CFAR) thresholding to convert dense radar spectra into sparse point clouds, prematurely discarding sub-threshold returns that may still retain useful Doppler motion cues. We present Dense Soft Weighting, an analytic radar front-end that maps every range-Doppler cell to a continuous confidence metric rather than enforcing a binary detection threshold. Ego-velocity is then estimated using a deterministic robust weighted least-squares formulation, while the same weighted measurements provide a closed-form, measurement-derived velocity covariance for integration with a shared inertial back-end. The method requires no platform-specific training data or learning-based uncertainty model, supporting transfer across single-chip radar configurations. Across two public datasets and one self-collected dataset, Dense Soft Weighting reduces mean absolute pose error by 31-45
With the rapid development of integrated sensing and communication (ISAC) as a key enabler for future wireless networks, ensuring the security of both communication and sensing functions has become increasingly important. Current secure ISAC studies focus restrictively either on the communication or the sensing security, but not both. To bridge this gap, this paper investigates security for both, i.e., dual-security, in indoor orthogonal frequency division multiplexing (OFDM) based ISAC systems. Specifically, we consider a scenario in which a sensing user (SU) is authorised for sensing but may eavesdrop on communication data, while a communication user (CU) is authorised for communication but may perform unauthorised sensing. We chose this scenario as the pathological case where an authorised eavesdropper has more information and is more effective than an unauthorised one. To address this case, we propose the use of temporal artificial noise (AN) to prevent malicious CU sensing by enlarging its time-domain sensing error, and simultaneously degrade SU data eavesdropping by reducing its frequency-domain signal-to-noise-plus-interference ratio (SINR) with standard OFDM receiver processing. Meanwhile, our proposed scheme guarantees the sensing performance of the SU and the communication performance of the CU. We present numerical results that demonstrate AN can effectively provide dual protection for sensing and communication in OFDM-ISAC systems while guaranteeing the performance of legitimate users.
What if a jamming attack could be executed without the need to produce radio signals? How could you detect the attack? Reconfigurable Intelligent Surfaces (RISs) are a transformative technology that passively control, or manipulate, radio signals and the channel state through reflection only. Future wireless networks, including sixth-generation (6G) networks, depend upon RIS to improve signal coverage and spectral efficiency by manipulating the channel, but they also enable new security risks, such as passive jamming attacks. In traditional jamming, an attacker actively transmits signals to disrupt a receiver. RIS-based jamming is passive, i.e., the RIS does not transmit a signal but only reflects and manipulates the wireless channel to degrade or deny reception to a receiver. Current approaches to detecting jamming depend upon the active nature of jammers and are not designed to detect a passive adversary. A proposed solution would be to use machine learning (ML) for classification. In order to do machine learning classification, we need training data. In this paper, we present our approach to create artificial jamming data for ML models training. We evaluate the attack effectiveness of the produced jamming data and show that it faithfully reflects power and spectral properties of normal channels and channels under the influence of both an RIS-based jammer and an active jammer. The characteristic differences between active jamming and passive RIS-enabled jamming are analysed across multiple domains (power, spectral, statistical, temporal) providing useful insights into effective features selection for the training of ML-based RIS-enabled anomaly detection models.
Integrated sensing and communication (ISAC) enables the efficient sharing of wireless resources to support emerging applications, but it also gives rise to new sensing-based security vulnerabilities. Here, potential communication security threats whereby confidential messages intended for legitimate users are intercepted, but also unauthorized receivers (Eves) can passively exploit target echoes to infer sensing parameters without users being aware. Despite these risks, the joint protection of sensing and communication security in ISAC systems remains unexplored. To address this challenge, this paper proposes a two-layer dual-secure ISAC framework that simultaneously protects sensing and communication against passive sensing Eves and communication Eves, without requiring their channel state information (CSI). Specifically, transmit beamformers are jointly designed to inject artificial noise (AN) to introduce interference to communication Eves, while deliberately distorting the reference signal available to sensing Eves to impair their sensing capability. Furthermore, the proposed design generates artificial ghosts (AGs) with fake angle-range-velocity profiles observable by all receivers. Legitimate receivers can suppress these AGs, whereas sensing Eves cannot, thereby significantly reducing their probability of correctly detecting the true targets. Numerical results demonstrate that the proposed framework effectively enhances both communication and sensing security, while preserving the performance of communication users and legitimate sensing receivers.
The modernization of logistics through the use of Wireless Sensor Network (WSN) Internet of Things (IoT) devices promises great efficiencies. Sensor devices can provide real-time or near real-time condition monitoring and location tracking of assets during the shipping process, helping to detect delays, prevent loss, and stop fraud. However, the integration of low-cost WSN/IoT systems into a pre-existing industry should first consider security within the context of the application environment. In the case of logistics, the sensors are mobile, unreachable during the deployment, and accessible in potentially uncontrolled environments. The risks to the sensors include physical damage, either malicious/intentional or unintentional due to accident or the environment, or physical attack on a sensor, or remote communication attack. The easiest attack against any sensor is against its communication. The use of IoT sensors for logistics involves the deployment conditions of mobility, inaccesibility, and uncontrolled environments. Any threat analysis needs to take these factors into consideration. This paper presents a threat model focused on an IoT-enabled asset tracking/monitoring system for smart logistics. A review of the current literature shows that no current IoT threat model highlights logistics-specific IoT security threats for the shipping of critical assets. A general tracking/monitoring system architecture is presented that describes the roles of the components. A logistics-specific threat model that considers the operational challenges of sensors used in logistics, both malicious and non-malicious threats, is then given. The threat model categorizes each threat and suggests a potential countermeasure.
LoRaWAN deployments follow an ad hoc deployment model that has organically led to overlapping communication networks, sharing the wireless spectrum, and completely unaware of each other. LoRaWAN uses ALOHA-style communication where it is almost impossible to schedule transmission between networks belonging to different owners properly. The inability to schedule overlapping networks will cause internetwork interference, which will increase node-to-gateway message losses and gateway-to-node acknowledgment failures. This problem is likely to get worse as the number of LoRaWAN networks increases. In response to this problem, we propose IRONWAN, a wireless overlay network that shares communication resources without modifications to underlying protocols. It utilizes the broadcast nature of radio communication and enables gateway-to-gateway communication to facilitate the search for failed messages and transmit failed acknowledgments already received and cached in overlapping network’s gateways. IRONWAN uses two novel algorithms: 1) a real-time message interarrival predictor, to highlight when a server has not received an expected uplink message and 2) the interference predictor, to ensure that extra gateway-to-gateway communication does not negatively impact the communication bandwidth. We evaluate IRONWAN on a 1000-node simulator with up to ten gateways and a 10-node testbed with 2-gateways. The results show that IRONWAN can achieve up to 12% higher packet delivery ratio (PDR) and total messages received per node while increasing the minimum PDR by up to 28%. These improvements save up to 50% node’s energy. Finally, we demonstrate that IRONWAN has comparable performance to an optimal solution (wired and centralized) but with 2–32 times lower communication costs. IRONWAN also has up to 14% better PDR when compared to FLIP, a wired-distributed gateway-to-gateway protocol in certain scenarios.
Wide Area Cyber-Physical Systems (WA-CPSs) are a class of control systems that integrate low-powered sensors, heterogeneous actuators, and computer controllers into large infrastructure that span multi-kilometre distances. Current wireless communication technologies are incapable of meeting the communication requirements of range and bounded delays needed for the control of WA-CPSs. To solve this problem, we use a Control Communication Co-design approach for WA-CPSs, that we refer to as the C3 approach, to design a novel Low-Power Wide Area (LPWA) MAC protocol called Ctrl-MAC and its associated event-triggered controller that can guarantee the closed-loop stability of a WA-CPS. This is the first article to show that LPWA wireless communication technologies can support the control of WA-CPSs. LPWA technologies are designed to support one-way communication for monitoring and are not appropriate for control. We present this work using an example of a water distribution network application, which we evaluate both through a co-simulator (modeling both physical and cyber subsystems) and testbed deployments. Our evaluation demonstrates full control stability, with up to 50% better packet delivery ratios and 80% less average end-to-end delays when compared to a state-of-the-art LPWA technology. We also evaluate our scheme against an idealised, wired, centralised, control architecture, and show that the controller maintains stability and the overshoots remain within bounds.
This paper presents the LoRaWAN at the Edge Dataset (LoED), an open LoRaWAN packet dataset collected at gateways. Real-world LoRaWAN datasets are important for repeatable sensor-network and communications research and evaluation as, if carefully collected, they provide realistic working assumptions. LoED data is collected from nine gateways over a four month period in a dense urban environment. The dataset contains packet header information and all physical layer properties reported by gateways such as the CRC, RSSI, SNR and spreading factor. Files are provided to analyse the data and get aggregated statistics. The dataset is available at: doi.org/10.5281/zenodo.4121430
Industrial Control Systems (ICS) are evolving with advances in new technology. The addition of wireless sensors and actuators and new control techniques means that engineering practices from communication systems are being integrated into those used for control systems. The two are engineered in very different ways. Neither engineering approach is capable of accounting for the subtle interactions and interdependence that occur when the two are combined. This paper describes our first steps to bridge this gap, and push the boundaries of both computer communication system and control system design. We present The Separator testbed, a Cyber-Physical testbed enabling our search for a suitable way to engineer systems that combine both computer networks and control systems.
Wireless communication protocols are often used in critical applications, e.g., urban water supply networks or healthcare monitoring within the Internet of Things. It is essential that control software and protocols for such systems are verified to be both robust and reliable. The effects on the hardware caused by environmental conditions and the choice of parameters used by the protocol are among the largest obstacles to robustness and reliability in wireless systems. In this paper we use formal verification to verify that a wireless sensor network synchronization and dissemination protocol is not adversely affected by these factors.
One of the major challenges for the engineering of wireless sensing systems is to improve the software abstractions and frameworks that are available to programmers while ensuring system reliability and efficiency. The distributed systems community have developed a rich set of such abstractions for building dependable distributed systems connected using wired networks, however after 20 years research many of these elude wireless sensor systems. In this paper we present X Process Commit (XPC) an atomic commit protocol framework that utilizes Synchronous Transmission (ST). We also introduce Hybrid, a technique that allows us to exploit the advantages of the Glossy and Chaos Synchronous Transmission primitives to get lower latency and higher reliability than either. Using XPC and Hybrid we demonstrate how to build protocols for the classical 2-phase and 3-phase commit abstractions and evaluate these demonstrating significantly improved performance and reliability than the use of Glossy or Chaos individually as dissemination primitives. We address how we overcame the timing challenges of bringing Glossy and Chaos together to form Hybrid and through extensive experimentation demonstrate that it is robust to in-network radio interference caused by multiple sources. We are first to present testbed results that show that Hybrid can provide almost 100% reliability in a network of nodes suffering from various levels of radio interference.
The Internet of Things (IoT) promises a revolution in the monitoring and control of a wide range of applications, from urban water supply networks and precision agriculture food production, to vehicle connectivity and healthcare monitoring. For applications in such critical areas, control software and protocols for IoT systems must be verified to be both robust and reliable. Two of the largest obstacles to robustness and reliability in IoT systems are effects on the hardware caused by environmental conditions, and the choice of parameters used by the protocol. In this paper we use probabilistic model checking to verify that a synchronisation and dissemination protocol for Wireless Sensor Networks (WSNs) is correct with respect to its requirements, and is not adversely affected by the environment. We show how the protocol can be converted into a logical model and then analysed using the probabilistic model-checker, PRISM. Using this approach we prove under which circumstances the protocol is guaranteed to synchronise all nodes and disseminate new information to all nodes. We also examine the bounds on synchronisation as the environment changes the performance of the hardware clock, and investigate the scalability constraints of this approach.
The control and monitoring of large infrastructure installations is becoming smarter, cheaper to run and easier to manage through the use of wireless sensor and actuator networks (WSANs). Cyber Physical Systems (CPSs) are the combination of cyber sensing via WSANs and physical control. The problem with the use of WSANs in CPSs is that they make the whole system being controlled exposed to the world and vulnerable to theft or cyber-attacks. In this article we examine the failure of CPS infrastructure due to intelligent radio jamming. The intelligent jammer employs a protocol-aware jamming strategy to learn the transmission period of a sensor device. It then broadcasts noise to disrupt the wireless communication and destabilise the CPS. We present a CPS control and communication approach to counter the threat of intelligent radio jamming. The approach exploits the properties of the event-based control strategy combined with a reservation-based communication protocol that employs obfuscation. We use a physical model of a water distribution network to demonstrate that the approach is resilient to an intelligent jamming attack, it is able to continue normal operation of the system and maintain the desired level of performance while achieving low overheads.
Wireless Sensor Network (WSN) applications range from domestic Internet of Things systems like temperature monitoring of homes to the monitoring and control of large-scale critical infrastructures. The greatest risk with the use of WSNs in critical infrastructure is their vulnerability to malicious network level attacks. Their radio communication network can be disrupted, causing them to lose or delay data which will compromise system functionality. This paper presents Antilizer, a lightweight, fully-distributed solution to enable WSNs to detect and recover from common network level attack scenarios. In Antilizer each sensor node builds a self-referenced trust model of its neighbourhood using network overhearing. The node uses the trust model to autonomously adapt its communication decisions. In the case of a network attack, a node can make neighbour collaboration routing decisions to avoid affected regions of the network. Mobile agents further bound the damage caused by attacks. These agents enable a simple notification scheme which propagates collaborative decisions from the nodes to the base station. A filtering mechanism at the base station further validates the authenticity of the information shared by mobile agents. We evaluate Antilizer in simulation against several routing attacks. Our results show that Antilizer reduces data loss down to 1% (4% on average), with operational overheads of less than 1% and provides fast network-wide convergence.
There is a growing movement to retrofit ageing, large scale infrastructures, such as water networks, with wireless sensors and actuators. Next generation Cyber-Physical Systems (CPSs) are a tight integration of sensing, control, communication, computation and physical processes. The failure of any one of these components can cause a failure of the entire CPS. This represents a system design challenge to address these interdependencies. Wireless communication is unreliable and prone to cyber-attacks. An attack upon the wireless communication of CPS would prevent the communication of up-to-date information from the physical process to the controller. A controller without up-to-date information is unable to meet system's stability and performance guarantees. We focus on design approach to make CPSs secure and we evaluate their resilience to jamming attacks aimed at disrupting the system's wireless communication. We consider classic time-triggered control scheme and various resource-aware event-triggered control schemes. We evaluate these on a water network test-bed against three jamming strategies: constant, random, and protocol aware. Our test-bed results show that all schemes are very susceptible to constant and random jamming. We find that time-triggered control schemes are just as susceptible to protocol aware jamming, where some event-triggered control schemes are completely resilient to protocol aware jamming. Finally, we further enhance the resilience of an event-triggered control scheme through the addition of a dynamical estimator that estimates lost or corrupted data.
Wireless sensors and actuators offer benefits to large industrial control systems. The absence of wires for communication reduces the deployment cost, maintenance effort, and provides greater flexibility for sensor and actuator location and system architecture. These benefits come at a cost of a high probability of communication delay or message loss due to the unreliability of radio-based communication. This unreliability poses a challenge to contemporary control systems that are designed with the assumption of instantaneous and reliable communication. Wireless sensors and actuators create a paradigm shift in engineering energy-efficient control schemes coupled with robust communication schemes that can maintain system stability in the face of unreliable communication. This paper investigates the feasibility of using the low-power wide-area communication protocol LoRaWAN with an event-triggered control scheme through modelling in Matlab. We show that LoRaWAN is capable of meeting the maximum delay and message loss requirements of an event-triggered controller for certain classes of applications. We also expose the limitation in the use of LoRaWAN when message size or communication range requirements increase or the underlying physical system is exposed to significant external disturbances.
This document presents the views expressed in the submissions and discussions at the FAILSAFE workshop about the common problems that plague embedded sensor system deployments in the wild. We present analysis gathered from the submissions and the panel session of the FAILSAFE 2017 workshop held at the SenSys 2017 conference. The FAILSAFE call for papers specifically asked for descriptions of wireless sensor network (WSN) deployments and their problems and failures. The submissions, the questions raised at the presentations, and the panel discussion give us a sufficient body of work to review, and draw conclusions regarding the effect that the environment has as the most common cause of embedded sensor system failures.
The Internet of Things (IoT) promises a revolution in the monitoring and control of a wide range of applications, from urban water supply networks and precision agriculture food production, to vehicle connectivity and healthcare monitoring. For applications in such critical areas, control software and protocols for IoT systems must be verified to be both robust and reliable. Two of the largest obstacles to robustness and reliability in IoT systems are effects on the hardware caused by environmental conditions, and the choice of parameters used by the protocol. In this paper we use probabilistic model checking to verify that a synchronisation and dissemination protocol for Wireless Sensor Networks (WSNs) is correct with respect to its requirements, and is not adversely affected by the environment. We show how the protocol can be converted into a logical model and then analysed using the probabilistic model-checker, PRISM. Using this approach we prove under which circumstances the protocol is guaranteed to synchronise all nodes and disseminate new information to all nodes. We also examine the bounds on synchronisation as the environment changes the performance of the hardware clock, and investigate the scalability constraints of this approach.
Michael Fisher合作论文数Department of Computer Science, The University of Manchester;University of Liverpool4