论文标题
保持连接,没有痕迹:通过混淆辐射指纹在WiFi中增强安全性和隐私
Stay Connected, Leave no Trace: Enhancing Security and Privacy in WiFi via Obfuscating Radiometric Fingerprints
论文作者
论文摘要
WiFi芯片组的固有硬件缺陷在传输信号中表现出来,从而导致唯一的辐射指纹。该指纹可以用作增强安全性的附加身份验证方法。实际上,最近的作品提出了可以在商业式设备中容易实施的实用指纹解决方案。在本文中,我们通过分析和实验证明了这些解决方案极易受到模仿攻击的影响。我们还证明,可以通过跟踪用户设备来滥用这种独特的基于设备的签名来侵犯隐私,并且截至目前,除了关闭设备之外,用户没有任何防止此类隐私攻击的方法。 我们提出了RF-VEIL,这是一种辐射指纹解决方案,不仅可以抵抗模仿攻击,而且还可以通过掩盖发射机的辐射指纹来保护用户隐私,以保护发射器。具体而言,我们将相位误差的随机模式引入传输信号,以便只有预期的接收器才能提取发射机的原始指纹。在一系列的实验和分析中,我们暴露了采用幼稚随机化进行统计攻击并引入对策的脆弱性。最后,我们通过实验表明RF-Veil在保护用户隐私和增强安全性方面的功效。更重要的是,我们提出的解决方案允许与不使用RF-Veil的其他设备进行通信。
The intrinsic hardware imperfection of WiFi chipsets manifests itself in the transmitted signal, leading to a unique radiometric fingerprint. This fingerprint can be used as an additional means of authentication to enhance security. In fact, recent works propose practical fingerprinting solutions that can be readily implemented in commercial-off-the-shelf devices. In this paper, we prove analytically and experimentally that these solutions are highly vulnerable to impersonation attacks. We also demonstrate that such a unique device-based signature can be abused to violate privacy by tracking the user device, and, as of today, users do not have any means to prevent such privacy attacks other than turning off the device. We propose RF-Veil, a radiometric fingerprinting solution that not only is robust against impersonation attacks but also protects user privacy by obfuscating the radiometric fingerprint of the transmitter for non-legitimate receivers. Specifically, we introduce a randomized pattern of phase errors to the transmitted signal such that only the intended receiver can extract the original fingerprint of the transmitter. In a series of experiments and analyses, we expose the vulnerability of adopting naive randomization to statistical attacks and introduce countermeasures. Finally, we show the efficacy of RF-Veil experimentally in protecting user privacy and enhancing security. More importantly, our proposed solution allows communicating with other devices, which do not employ RF-Veil.