SEI文献整理2:A Review of Radio Frequency Fingerprinting Techniques(2020)

[1] N. Soltanieh, Y. N., Y. Yang and N. C. Karmakar (2020). “Soltanieh-2020-A Review of Radio Frequency Fingerprinting Techniques.” IEEE Journal of Radio Frequency Identification


      • 摘要
      • 1. 概述
      • 2. 物理层安全
      • 3. 射频指纹的分类
        • A、 基于瞬态的射频指纹识别
        • B. 稳态射频指纹
        • C. 其它方法
      • 4. 射频指纹特征分类
        • A. 位置无关特征
        • B. 位置相关功能
      • 5. 提取特征的分类
      • 6. 结论



1. 概述

Wireless devices are traditionally identified by some unique RF fingerprints caused by radio circuitry. There are several forms of attacks for the wireless network; an impersonation attack is one of the most important and threatening [1]. In this kind of attack, an attacker can copy most of the identification information like the password and Media Access Control (MAC) address to spoof devices [2]. The radio frequency fingerprinting (RFF) from the unique features of electromagnetic waves emitted by the transmitter is unique [35].


[1] Q. Li and W. Trappe, “Detecting spoofing and anomalous traffic in wireless networks via forge-resistant relationships,” IEEE Transactions on Information Forensics and Security, vol. 2, pp. 793-808, 2007.
[2] J. Hall, M. Barbeau, and E. Kranakis, “Radio frequency fingerprinting for intrusion detection in wireless networks,” IEEE Transactions on Defendable and Secure Computing, vol. 12, pp. 1-35, 2005.
[35] S. U. Rehman, K. Sowerby, and C. Coghill, “RF fingerprint extraction from the energy envelope of an instantaneous transient signal,” in 2012 Australian Communications Theory Workshop (AusCTW), pp. 90-95, 2012.

  在这篇综述中,我们重点讨论了通过独特的指纹识别无线设备的方法,称之为物理层设备识别。物理层识别是指由于模拟电路中的硬件缺陷,通过提取特征对无线设备进行指纹识别的过程[6]。这些硬件缺陷出现在制造过程中。物理层设备识别被用于不同的目的,如入侵检测[7-9]、访问控制[3,10]、克隆检测[11,12]和安全定位[13]。使用物理缺陷作为识别签名最重要的优点是,使用其他无线设备很难伪造签名[14-16]。使用物理层进行设备识别的无线平台包括HF RFID转发器、UHF RFID转发器[17]、VHF发射机和IEEE 802.11收发器[18,19]。

[20] A. Candore, O. Kocabas, and F. Koushanfar, “Robust stable radiometric fingerprinting for wireless devices,” in 2009 IEEE International Workshop on Hardware-Oriented Security and Trust, pp. 43-49, 2009.


[21] B. Danev and S. Capkun, “Transient-based identification of wireless sensor nodes,” in Proceedings of the 2009 International Conference on Information Processing in Sensor Networks, pp. 25-36, 2009.



2. 物理层安全

SEI文献整理2:A Review of Radio Frequency Fingerprinting Techniques(2020)_第1张图片

1) 捕获识别信号,

2) 唯一性,表示没有两个设备应该有相同的指纹。
3) 永久性,这意味着指纹应该是时不变和环境不变的。
4) 可收集性,这表明可以用现有设备对指纹进行定量测量。
5) 鲁棒性,这意味着指纹应根据外部环境因素(如信号反射、吸收等)和设备相关因素(如温度、功率和电平)进行评估。

[28] R. M. Bolle, J. H. Connell, S. Pankanti, N. K. Ratha, and A. W. Senior, Guide to biometrics: Springer Science & Business Media, 2013.

3. 射频指纹的分类


[33]M. Leonardi, L. Di Gregorio, and D. Di Fausto, “Air traffic security: aircraft classification using ADS-B message’s phase-pattern,” Aerospace, vol. 4, p. 51, 2017.


[37]X. Li, Y. Zhang, and M. G. Amin, “Multifrequency-based range estimation of RFID tags,” in 2009 IEEE International Conference on RFID, pp. 147-154, 2009.


[38]K. I. Talbot, P. R. Duley, and M. H. Hyatt, “Specific emitter identification and verification,” Technology Review, vol. 113, 2003.

SEI文献整理2:A Review of Radio Frequency Fingerprinting Techniques(2020)_第2张图片
SEI文献整理2:A Review of Radio Frequency Fingerprinting Techniques(2020)_第3张图片

A、 基于瞬态的射频指纹识别


[39]Y. Honglin and H. Aiqun, “Fountainhead and uniqueness of RF fingerprint,” Journal of Southeast University (Natural Science Edition), vol. 39, pp. 230-233, 2009.
[40] Y.-J. Yuan, X. Wang, Z.-T. Huang, and Z.-C. Sha, “Detection of radio transient signal based on permutation entropy and GLRT,” Wireless Personal Communications, vol. 82, pp. 1047-1057, 2015.

S i = { n ( i ) 1 ≤ i ≤ m X ( i ) + n ( i ) n 0 ≤ n ≤ N 0 (1) \tag{1} S_i=\left \{ \begin{matrix} &n(i) &1\le i\le m\\ &X(i)+n(i) & n_0\le n\le N_0 \end{matrix} \right. Si={n(i)X(i)+n(i)1imn0nN0(1)其中, S i S_i Si为第 i i i个样本; X ( i ) X(i) X(i)为离散信号,这里 i < m ii<m n ( i ) n(i) n(i)是信道噪声; n n n是采样数, m m m是瞬态信号的起点。

  基于瞬态的无线设备识别方法可以追溯到90年代早期。在[9,29]中,使用多分辨率小波分析来表征瞬态信号中的特征,识别了来自不同制造商但型号相同的七个VHF FM发射机。利用遗传算法对提取的特征进行分类。为了测量算法的噪声灵敏度,在原始瞬态信号中加入高斯噪声。



Ellis和Serinken[41]分析了VHF FM发射机瞬态的振幅和相位信息。作者使用了来自不同制造商和同一型号的28个发射器,结果表明,来自同一制造商和型号的设备的指纹图谱难以区分,这使得识别过程变得复杂。

Tekbas等人[42,43]测试了10个商用VHF FM发射机在环境温度、电源和附加信道噪声下的传输。采用基于幅值和相位的方法提取暂态特征。采用概率神经网络(PNN)作为分类器,结果表明,在训练过程中通过估计信噪比和调整其水平,可以提高低信噪比暂态信号的分类精度。

Hall等人使用了14种不同的(制造商和型号)IEEE 802.11设备和10种不同的(制造商和型号)蓝牙[43,44]。捕获过程是通过频谱分析仪近距离执行的。作者使用振幅、相位、同相、正交、功率和DWT系数信息来创建每个瞬态信号的剖面。平均分类错误率为8%,与型号和制造商密切相关。


在[45]中,Rasmussen和Capkun使用射频指纹技术识别了来自同一制造商和型号的10个UHF(Mica2/CC1000)传感器设备。每个设备都有一个指纹轮廓,包括瞬态长度、振幅方差、载波信号的峰值数、瞬态功率的归一化平均值和归一化最大值之间的差值以及第一个DWT系数。在[45]中证明了对无线传感器节点的无线电(Chipcon 1000无线电,433MHz)进行指纹识别的可行性。瞬态信号的持续时间、峰值的数量以及峰值的归一化平均值和最大值之间的差值用于为每个信号创建RF指纹。

[45]K. B. Rasmussen and S. Capkun, “Implications of radio fingerprinting on the security of sensor networks,” in 2007 Third International Conference on Security and Privacy in Communications Networks and the Workshops-SecureComm 2007, pp. 331-340, 2007.



Method 1: Bayesian Step Change Detection (BSCD)
Method 2: Bayesian Ramp Change Detection (BRCD)
Method 3: Variance Fractal Dimension Threshold Detection
Method 4: Phase Detection (PD)
Method 5: Mean Change Point Detection (MCPD)
Method 6: Permutation Entropy (PE) and Generalized Likelihood Ratio Test (GLRT) Detector

B. 稳态射频指纹


[11]B. Danev, T. S. Heydt-Benjamin, and S. Capkun, “Physical-layer identification of RFID devices,” in USENIX security symposium, pp. 199- 214, 2009.


[57]I. O. Kennedy, P. Scanlon, F. J. Mullany, M. M. Buddhikot, K. E. Nolan, and T. W. Rondeau, “Radio transmitter fingerprinting: A steady state frequency domain approach,” in 2008 IEEE 68th Vehicular Technology Conference, pp. 1-5, 2008.


[58]W. C. S. II, M. A. Temple, M. J. Mendenhall, and R. F. Mills, “Radio frequency fingerprinting commercial communication devices to enhance electronic security,” International Journal of Electronic Security and Digital Forensics, vol. 1, pp. 301-322, 2008.


[59]P. Scanlon, I. O. Kennedy, and Y. Liu, “Feature extraction approaches to RF fingerprinting for device identification in femtocells,” Bell Labs Technical Journal, vol. 15, pp. 141-151, 2010.

Gerdes等人[60]提出了一种基于稳态的RFF技术,该技术能够识别具有相同型号和相同制造商的卡。ieeeethernet 802.3的前导码部分(16个设备有3种不同的型号)用于提供设备指纹配置文件,这有助于识别从中发出信号的设备。使用匹配滤波器实现和简单的阈值来提供分类。他们已经表明,这些设备的模拟信号的特性是可跟踪的,并且适合于网络访问控制方案。

[60]R. M. Gerdes, T. E. Daniels, M. Mina, and S. Russell, “Device identification via analog signal fingerprinting: a matched filter approach,” in NDSS, 2006.

C. 其它方法


[63]W. C. Suski II, M. A. Temple, M. J. Mendenhall, and R. F. Mills, “Using spectral fingerprints to improve wireless network security,” in IEEE GLOBECOM 2008-2008 IEEE Global Telecommunications Conference, pp. 1-5, 2008.


[62]R. W. Klein, M. A. Temple, and M. J. Mendenhall, “Application of wavelet-based RF fingerprinting to enhance wireless network security,” Journal of Communications and Networks, vol. 11, pp. 544-555, 2009.
[64]R. W. Klein, M. A. Temple, and M. J. Mendenhall, “Application of wavelet denoising to improve OFDM‐based signal detection and classification,” Security and Communication Networks, vol. 3, pp. 71-82, 2010.


[65]S. Chinnappa Gounder Periaswamy, D. R. Thompson, and J. Di, “Fingerprinting RFID tags,” IEEE Transactions on Dependable & Secure Computing, vol. 8, 2011.
[66]S. C. G. Periaswamy, D. R. Thompson, H. P. Romero, and J. Di, “Fingerprinting radio frequency identification tags using timing characteristics,” in Proc. Workshop on RFID Security-RFID-sec Asia, 2010.



[61]S. Jana and S. K. Kasera, “On fast and accurate detection of unauthorized wireless access points using clock skews,” IEEE transactions on Mobile Computing, vol. 9, pp. 449-462, 2009.
[67]T. Kohno, A. Broido, and K. C. Claffy, “Remote physical device fingerprinting,” IEEE Transactions on Dependable and Secure Computing, vol. 2, pp. 93-108, 2005.


[68]D. R. Reising, M. A. Temple, and M. J. Mendenhall, “Improved wireless security for GMSK-based devices using RF fingerprinting,” International Journal of Electronic Security and Digital Forensics, vol. 3, pp. 41-59, 2010.
[69]M. D. Williams, M. A. Temple, and D. R. Reising, “Augmenting bit-level network security using physical layer RF-DNA fingerprinting,” in 2010 IEEE Global Telecommunications Conference GLOBECOM 2010, pp. 1- 6, 2010.
[70]D. R. Reising, M. A. Temple, and M. J. Mendenhall, “Improving intra- cellular security using air monitoring with RF fingerprints,” in 2010 IEEE Wireless Communication and Networking Conference, pp. 1-6, 2010.

4. 射频指纹特征分类


A. 位置无关特征


[71]S. Dolatshahi, A. Polak, and D. L. Goeckel, “Identification of wireless users via power amplifier imperfections,” in 2010 Conference Record of the Forty Fourth Asilomar Conference on Signals, Systems and Computers, pp. 1553-1557, 2010.
[72]Q. Xu, R. Zheng, W. Saad, and Z. Han, “Device fingerprinting in wireless networks: Challenges and opportunities,” IEEE Communications Surveys & Tutorials, vol. 18, pp. 94-104, 2015.


[59]P. Scanlon, I. O. Kennedy, and Y. Liu, “Feature extraction approaches to RF fingerprinting for device identification in femtocells,” Bell Labs Technical Journal, vol. 15, pp. 141-151, 2010.



[73]A. C. Polak, S. Dolatshahi, and D. L. Goeckel, “Identifying wireless users via transmitter imperfections,” IEEE Journal on selected areas in communications, vol. 29, pp. 1469-1479, 2011.



[74]N. T. Nguyen, G. Zheng, Z. Han, and R. Zheng, “Device fingerprinting to enhance wireless security using nonparametric Bayesian method,” in 2011 Proceedings IEEE INFOCOM, pp. 1404-1412, 2011.


B. 位置相关功能


[77]N. Patwari and S. K. Kasera, “Robust location distinction using temporal link signatures,” in Proceedings of the 13th annual ACM international conference on Mobile computing and networking, pp. 111-122, 2007.
[78]R. S. Campos and L. Lovisolo, “Rf fingerprinting location techniques” Handbook of Position Location: Theory, Practice, and Advances, pp. 487- 520, 2011.
[72]Q. Xu, R. Zheng, W. Saad, and Z. Han, “Device fingerprinting in wireless networks: Challenges and opportunities,” IEEE Communications Surveys & Tutorials, vol. 18, pp. 94-104, 2015.

5. 提取特征的分类



[53]Y. Cao, W.-w. Tung, J. Gao, V. A. Protopopescu, and L. M. Hively, “Detecting dynamical changes in time series using the permutation entropy,” Physical review E, vol. 70, p. 046217, 2004.
[80]Z. Prekopcsák and D. Lemire, “Time series classification by class-specific Mahalanobis distance measures,” Advances in Data Analysis and Classification, vol. 6, pp. 185-200, 2012.


[81]G. Baldini and G. Steri, “A survey of techniques for the identification of mobile phones using the physical fingerprints of the built-in components,” IEEE Communications Surveys & Tutorials, vol. 19, pp. 1761-1789, 2017.


[82]B. Widrow and M. A. Lehr, “30 years of adaptive neural networks: perceptron, madaline, and backpropagation,” Proceedings of the IEEE, vol. 78, pp. 1415-1442, 1990.


[83]G. Zhang, W. Jin, and L. Hu, “Resemblance coefficient based intrapulse feature extraction approach for radar emitter signals,” Chinese journal of electronics, vol. 14, pp. 337-341, 2005.


[84]D. R. Reising, M. A. Temple, and J. A. Jackson, “Authorized and rogue device discrimination using dimensionally reduced RF-DNA fingerprints,” IEEE Transactions on Information Forensics and Security, vol. 10, pp. 1180-1192, 2015.

6. 结论


