Security Analysis of RIS-Assisted Physical-Layer Authentication Over Multipath Channels
For wireless security researchers, this work provides theoretical security analysis of RIS-based authentication under a strong attacker model, but the results are incremental as they extend known concepts to a specific RIS scenario.
The paper analyzes security of RIS-assisted physical-layer authentication against a multi-antenna attacker with full channel knowledge. It derives optimal attack strategies and shows that under multipath conditions, a single-antenna attacker cannot achieve channel indistinguishability, but under LOS conditions, impersonation is possible.
In physical layer authentication, verification of a user's identity is based on the characteristics of the transmission channel through which signals are delivered to the authenticator (Bob). In this paper, we assume that the signals received by Bob pass through a \ac{RIS} (controlled by Bob) and that the legitimate transmitter (Alice) is equipped with one antenna. Conversely, the attacker (Trudy) has multiple antennas and uses precoding to deceive Bob's verification. Assuming that Trudy knows all the channel matrices, we first derive her optimal attack strategy. Then, we analyse the conditions under which the channel estimated by Bob is indistinguishable when either Alice or Trudy is transmitting. When Trudy has a single antenna, we show that the indistinguishability condition cannot be met when the channels to the RIS are the result of propagation over multiple paths. For single-path line-of-sight (LOS) conditions, instead, Trudy can impersonate Alice although transmitting from a different position. We verify these results numerically and assess the security of the considered scenario, even when the indistinguishability conditions cannot be met.