Voltage Profile-Driven Physical Layer Authentication for RIS-Aided Backscattering Tag-to-Tag Networks
Full text
IEEE INTERNET OF THINGS JOURNAL, VOL. 12, NO. 23, 1 DECEMBER 2025 51099 Voltage Profile-Driven Physical Layer Authentication for RIS-Aided Backscattering Tag-to-Tag Networks Masoud Kaveh , Member, IEEE, Farshad Rostami Ghadi , Member, IEEE, Yifan Zhang , Zheng Yan , Fellow, IEEE, and Riku J¨ antti , Senior Member, IEEE Abstract—This article proposes a novel physical layer authentication (PLA) scheme for backscattering tag-to-tag networks (BTTNs), where a talker tag (TT) communicates passively with a listener tag (LT) in the presence of a potential adversary. Designed for ultralow-power tags without cryptographic capability, the proposed PLA leverages the unique voltage profiles generated by the tags’ energy harvesting and demodulation circuits to form physical-layer signatures for authentication. In addition, to enhance the reliability of voltage measurements, especially under weak signal conditions inherent within BTTNs, an indoor reconfigurable intelligent surface (RIS) is integrated to improve the received signal quality at LT. The proposed approach maintains a high authentication success rate even as the distance between TT and LT increases. A detailed security analysis demonstrates strong resilience against impersonation, man-in-the-middle (MITM), relay, and replay attacks, as long as the RIS controller remains secure. This robustness stems from the adversary’s inability to recreate the exact voltage profiles at LT due to the inherent location-specific channel characteristics and the RIS-assisted signal shaping that the attacker cannot replicate. Furthermore, the simulation results confirm the effectiveness of the proposed RIS-assisted PLA, showing significant gains in authentication performance and secrecy capacity across diverse deployment scenarios. Index Terms—Backscattering tag-to-tag networks (BTTNs), physical layer authentication (PLA), reconfigurable intelligent surfaces (RISs). NOMENCLATURE NNumber of RIS elements. ΦRIS phase shift diagonal matrix. Received 2 January 2025; revised 12 June 2025; accepted 15 September 2025. Date of publication 18 September 2025; date of current version 20 November 2025. The work of Masoud Kaveh, Yifan Zhang, and Riku J¨ antti was supported by the Smart Networks and Services Joint Undertaking through European Union’s Horizon Europe Research and Innovation Programme under Agreement 101192113 (Ambient-6G). The work of Farshad Rostami Ghadi was supported in part by European Union’s Horizon 2022 Research and Innovation Programme through Marie Skłodowska-Curie under Grant 101107993. The work of Zheng Yan was supported in part by the Academy of Finland under Grant 345072 and Grant 350464. (Corresponding author: Masoud Kaveh.) Masoud Kaveh, Yifan Zhang, and Riku J¨ antti are with the Department of Information and Communication Engineering, Aalto University, 02150 Espoo, Finland (e-mail: masoud.ka[email protected]; [email protected]; [email protected]). Farshad Rostami Ghadi is with the Department of Signal Theory, Networking and Communications, University of Granada, 18071 Granada, Spain (e-mail: [email protected]). Zheng Yan is with the School of Cyber Engineering, Xidian University, Xi’an 710071, China (e-mail: [email protected]). Digital Object Identifier 10.1109/JIOT.2025.3611714 PsPower of the RF source. Pinc,iIncident power at LT in modulation state i. kHrv,kDem Coefficients related to circuit response. αPower splitting ratio between Hrv and Dem circuits. ∆VVoltage difference during authentication. IDTIdentity of the talker tag. λWavelength of the RF signal. Gtag Antenna gain of the tag. Γ∗ L,iConjugate reflection coefficient in modulation state i. ZaAntenna impedance. ZLLoad impedance at LT. BL,BTBackscattering coefficient of LT and TT. VHrv,out Output voltage from the energy harvesting circuit at LT. VDem,out Output voltage from the demodulation circuit at LT. τHrv Threshold for the energy harvesting voltage comparison. τDem Threshold for the demodulation voltage comparison. χPathloss exponent. nL,nTNoise at LT and TT. γL,γESNR at LT and Eve. CSInstantaneous secrecy capacity. ¯ CSAverage secrecy capacity. Nsim Number of simulation samples. I. INTRODUCTION IN AN era of rapidly expanding connectivity, the demand for energy-efficient communication systems and zeroenergy devices continues to rise, particularly for applications where regular battery replacement or recharging is impractical [1]. Radio frequency identification (RFID) technology has become a prime example of this advancement, as it allows the identification and tracking of tags using electromagnetic fields, all without the need for an internal power source [2]. These tags draw energy from the reader’s transmitted signals and respond by backscattering a modulated signal containing the relevant data [3]. A breakthrough in this field is the development of backscatter communication (BC), which ©2025 The Authors. This work is licensed under a Creative Commons Attribution 4.0 License. For more information, see https://creativecommons.org/licenses/by/4.0/
51100 IEEE INTERNET OF THINGS JOURNAL, VOL. 12, NO. 23, 1 DECEMBER 2025 enables devices to communicate by reflecting existing RF signals rather than generating new transmissions. This approach significantly lowers power consumption, making it well-suited for passive RFID systems [4],[5]. Nevertheless, despite the benefits of RFID and BC systems, they face notable limitations, particularly in enabling direct communication between individual tags. In traditional RFID and BC setups, communication typically occurs between a reader and a tag, which hinders scalability and flexibility in certain scenarios [6]. For example, many applications, such as large-scale inventory management and smart environments, require tags to exchange information directly without needing constant intervention from a central reader. This has led to the development of backscattering tag-to-tag networks (BTTNs), which enable direct communication between tags within an external RF field [7]. BTTNs represent a novel approach in passive RFID systems, facilitating communication between tags such as a talker tag (TT) and a listener tag (LT), with the help of an external RF source [8]. In this system, TT modulates the RF field by adjusting its load impedance, thus altering the characteristics of the backscattered signal directed at LT. The LT then demodulates this backscattered signal using its envelope detector. In addition, both tags incorporate energy harvesting circuits that convert RF energy into electrical power, ensuring continuous operation without the need for external power sources [9]. However, BTTNs face several significant challenges that must be overcome to ensure efficient and reliable operation. One of the primary challenges is the requirement for ultralowpower consumption. Since BTTNs rely on only passive tags at both communication endpoints that harvest energy from incident RF signals, it is crucial to minimize the power consumption to extend the operational lifetime of the tags and maintain their functionality. Another challenge is the low spectral efficiency of BC. The process of modulating and reflecting the RF signal inherently limits the bandwidth available for communication, resulting in lower data rates compared to active transmission methods. This issue is exacerbated in BTTNs compared to BC and RFID systems, as the receiver is not a powerful reader but another tag with comparatively fewer processing resources. Furthermore, BTTNs are constrained by very short communication ranges. The passive nature of the tags and the reliance on backscattered signals result in a limited communication distance, which can be a significant drawback in applications requiring long-range interactions. Last but not least, since current BTTNs are inherently vulnerable to security threats, it is crucial that tags authenticate each other to ensure secure communication. A. Related Works The exploration of PLA has emerged as an effective alternative to cryptographic methods for authentication in BC by utilizing the unique physical properties of backscattered signals. Over recent years, diverse strategies have been proposed to enhance the security of BC systems by leveraging PLA. In [10], a PLA technique was introduced to identify UHF RFID tags, focusing on security and reliability in BC systems by exploiting the unique inherent physical properties of each tag. Voigt et al. [11] proposed a watermarking-based PLA scheme for BC, leveraging chip-level manipulations in IEEE 802.15.4 protocols. Their method enables low-power tags to embed authentication information in packet chip sequences. Luo et al. [12] introduced an on-body backscatter authentication technique that exploits body-induced channel variations to distinguish legitimate tags from attackers, where a central reader extracts and classifies propagation signatures. In [13], a lightweight cryptographic RFID authentication protocol is presented for low-cost tags. Their method is rooted in cryptographic primitives and applies to traditional RFID systems with reader-tag interactions. GenePrint [14] proposed a versatile PLA framework applicable to various RFID systems, with the aim of improving security and operational efficiency. Similarly, Mehmood et al. [15] addressed identity attack vulnerabilities in BC systems by proposing a PLA mechanism to fortify the system security and maintain the integrity of the data. Wang et al. [16] introduced a replay-resistant authentication approach that combined signal randomization and tag coupling to counteract replay, signal compensation, and brute-force attacks. Danev et al. [17] conducted an extensive study on PLA of RFID devices, presenting multiple methods to derive physical layer fingerprints and demonstrating high accuracy in identifying RFID transponders according to their physical characteristics. To address active attack vulnerabilities in BDs, Luo et al. [18] developed ShieldScatter, a low-cost system that generates unique multipath propagation signatures, allowing sensitive source identification and threat detection. BCAuth, proposed by Wang et al. [19], implemented a multistage authentication and attack tracing scheme. It utilized the spatial information of BDs for initial and reauthentication processes, enhancing security for both static and mobile BDs. Li et al. [20] explored PLA for ambient BC-aided NOMA systems, introducing three schemes based on multiplexing forms: shared authentication tags, space-division multiplexing tags, and time-division multiplexing tags. The study also examined detection probabilities and false alarm rates under channel estimation errors. Yang et al. [21] developed BatAu, a batch authentication framework for smart home networks, leveraging physical-layer attributes in multiplexed signals to authenticate multiple BDs simultaneously. Zhang et al. [22] introduced FedScatter, a lightweight cross-domain PLA system for BC environments. FedScatter constructed device identity signatures from passive signal attributes and used federated learning to aggregate cross-domain identity data while preserving user privacy. Chang et al. [23] proposed APAuth, a lightweight authentication scheme designed for access points using backscatter devices. The approach takes advantage of the unique characteristics of the power volumes harvested from the tags to authenticate access points effectively without the need for complex computations. Yang et al. [24] introduced BatchAuth, a PLA scheme for multiple tags in smart environments. This scheme utilizes joint CSI and physical layer features to authenticate a batch of BDs simultaneously to effectively counter impersonation and replay attacks while adapting to the mobility of devices in dynamic environments.
KAVEH et al.: VOLTAGE PROFILE-DRIVEN PLA FOR RIS-AIDED BACKSCATTERING TAG-TO-TAG NETWORKS 51101 TABLE I COMPARISON OF OUR WORK WITH EXISTING PLA SCHEMES FOR BC SYSTEMS B. Research Gaps and Motivations Although various authentication schemes have been proposed for BC and FRID systems, where a reader authenticates a tag or vice versa, the challenge of enabling tag-to-tag authentication remains unexplored. Since tags in BTTNs are ultralow-power devices designed to operate with minimal energy consumption, they often lack the computational capacity to process lightweight cryptographic primitives or even compute physical layer attributes such as received signal strength (RSS) and angle of arrival (AoA). This limitation severely restricts the ability to implement the same traditional PLA frameworks used in BC for BTTNs. Furthermore, the combination of low spectral efficiency and limited processing capability keeps the authentication performance even lower in BTTNs compared to typical BC and RFID systems. The short coverage range of BTTNs compounds these challenges; as the distance between tags increases, the quality of the received signal decreases, making it even more difficult to achieve reliable authentication over longer distances. The combined factors, security vulnerabilities, ultralowpower constraints, low spectral efficiency, and short communication range, make it extremely challenging to conduct secure communication in BTTNs. To date, no effective authentication scheme for BTTNs has been proposed in the literature, largely due to these challenges. Our research aims to address this gap by proposing a lightweight and practical physical layer authentication (PLA) scheme for BTTNs. The proposed PLA scheme takes advantage of the unique behavior of the signals in the internal circuits of the tags to enable efficient and secure authentication without imposing additional computational burdens. In addition, to support reliable authentication under the weak signal conditions inherent in BTTNs, we propose the use of an indoor reconfigurable intelligent surface (RIS) as part of the network architecture. To realize this integration, the RIS is placed between TT and LT within an indoor BTTN setup and acts as a passive beamforming structure that enhances the propagation of the backscattered signal from TT to LT by intelligently adjusting the reflection characteristics of its elements. This integration improves the signal power at LT, enabling more robust physical-layer feature extraction and helping to maintain authentication performance as the distance between tags increases. Table Ipresents the unique aspects of our article compared to related works. C. Contributions This article proposes a novel PLA scheme to overcome the limitations of existing authentication methods in BC to enable secure communication in BTTNs. Using the unique voltage profiles generated by the energy harvesting and demodulator circuits on the tags, our scheme provides a lightweight but robust solution to make the tags authenticate each other without imposing additional computational overhead. Furthermore, we show that the integration of an RIS into the system enhances authentication accuracy and extends the secure communication range, addressing the inherent PLA performance constraints within BTTNs. The key contribution of this article can be presented as follows. 1) While prior PLA schemes in BC focus on authenticating tags through a central reader, our work is, to the best of our knowledge, the first to tackle the challenge of direct tag-to-tag authentication within BC systems. Our approach leverages the unique output voltage profile generated by the energy harvesting and envelope detector circuits in the power and demodulation units embedded in LT. Using existing measurements within these circuits, our scheme creates a distinct signature
51102 IEEE INTERNET OF THINGS JOURNAL, VOL. 12, NO. 23, 1 DECEMBER 2025 for each tag, enabling a straightforward and efficient authentication of TT without imposing any additional computational overhead. 2) To improve the reliability of the created voltage profiles in TT, enhance RSS, and boost the performance of the proposed PLA scheme, we introduce the use of indoor RIS in the BTTN communication system. The addition of RIS can also extend the range of secure communication within BTTNs. 3) We perform a comprehensive security analysis under different threat scenarios, showing that the proposed PLA allows LT to effectively authenticate TT in the presence of an adversary. Furthermore, we show that incorporating RIS into BTTN enhances the security of the authentication process by making it challenging for the adversary to replicate the same output voltage profile at LT. 4) The proposed authentication scheme is evaluated through extensive experiments in various system configurations. The results confirm that our scheme achieves acceptable authentication performance across different settings. In addition, the findings indicate that the inclusion of RIS significantly enhances the authentication performance, particularly over longer distances, compared to BTTN scenarios without RIS. D. Organization and Notations The remainder of this article is organized as follows. Section II provides an overview of BTTNs and the key components within the tags. Section III presents the system and threat models. In Section IV, we elaborate on the proposed authentication scheme. Section Vprovides a comprehensive security analysis of the authentication scheme, examining its robustness against various attack vectors. The simulation results are presented in Section VI, and finally, Section VII concludes this article. In addition, the key notations used throughout this article are summarized in Nomenclature. II. BACKSCATTERING TAG-TO-TAG NETWORKS This section provides a review of the BTTN architecture and discusses the critical components within the BTTN tags that enable efficient and passive communication. A. BTTN Overview The primary components of a BTTN typically include a TT, an LT, and an external RF source, as illustrated in Fig. 1. This system leverages the existing RF environment to facilitate communication between tags by modulating and backscattering RF signals. In a typical BTTN scenario, TT modulates its impedance, which changes the reflection coefficient of the tag antenna, thereby encoding information in the backscattered signal. Then, LT receives this modulated backscattered signal [25],[26]. The signal received at LT is a combination of the unmodulated signal from the RF source and the backscattered signal from TT. The signal received at LT can be expressed as YL=BTpPs(hSThTL +hSL)+nL(1) Fig. 1. BTTN communication system where a TT tries to talk to an LT by modulating and backscattering the signal from the RF source. Fig. 2. Basic circuit block diagram of a tag in BTTN. where BTbackscattering coefficient of TT as a function of coefficient of the antenna at different modulation states; Pspower of the signal emitted by the RF source; hST channel coefficient between the RF source and TT; hTL channel coefficient between TT and LT; hSL channel coefficient between the RF source and the LT; nLshows the additive white Gaussian noise (AWGN) at LT with zero mean and variance σ2 T. This received signal is then processed by LT’s demodulator circuit to extract the information sent by TT. If LT needs to communicate with TT, the process is similar, but, in reverse, LT modulates its impedance to backscatter the RF signal, and TT receives this modulated backscattered signal. Then, the received signal at TT can be expressed as YT=BLpPs(hSLhTL +hST)+nT(2) where BLis the backscattering coefficient of LT and nTshows the noise at TT with zero mean and variance σ2 T. B. BTTN Tag Design This section provides an overview of the fundamental components of a passive BTTN tag, which operates without
KAVEH et al.: VOLTAGE PROFILE-DRIVEN PLA FOR RIS-AIDED BACKSCATTERING TAG-TO-TAG NETWORKS 51103 Fig. 3. Two-stage voltage multiplication circuit for energy harvesting. Fig. 4. Demodulator circuit in a BTTN tag. an active onboard transmitter.As depicted in Fig. 2, a basic BTTN tag comprises an antenna, a power harvesting circuit, an envelope detector (serving as a zero-consumption receiver), a modulator (acting as a low-power passive transmitter), and a low-power MSP microcontroller responsible for data processing. When a tag functions as a transmitter (TT), the modulator adjusts the excitation field by altering the load impedance ZT of the antenna to backscatter signals. Conversely, when a tag operates as a receiver (LT), the envelope detector demodulates the received signal by detecting the voltage difference between the backscattered signals at distinct modulation states. This behavior can be characterized by the following differential radar cross section (RCS) equation: ∆σ=λ2G2 tag 4πˇˇΓ∗ L,1−Γ∗ L,2ˇˇ 2(3) where λis the wavelength of the excitation signal, Gtag is the antenna gain of the tag, and Γ∗ L,iis the conjugate reflection coefficient of the antenna at different modulation states. The reflection coefficient is described as Γ∗ L,i=ZL,i−Z∗ a ZL,i+Z∗ a ,i=on,off(4) where Zadenotes the antenna impedance. The modulator typically consists of a switch that connects to various terminating impedances, depending on the digital modulation used. The power harvesting circuit, illustrated in Fig. 3, includes a voltage multiplier that converts a low input voltage into a higher, regulated voltage suitable for powering the demodulation and decoding circuits. To optimize power transfer from the antenna and minimize reflected power, the voltage multiplier is preceded by an impedance matching network. However, the input impedance of the power harvesting circuit is only matched to the antenna at a specific input power due to its dependence on the received power level. Therefore, the impedance is tuned to match the minimum input power required for operation. At higher input power levels, the mismatch causes some power to be reflected, reducing overall power efficiency. A Fig. 5. System model and security model depicting the tag, reader, and RIS configuration in RIS-aided MBC. voltage regulator follows the voltage multiplier to provide a stable supply voltage for the demodulation and decoding logic circuits.The analog demodulation section, shown in Fig. 4, consists of a voltage multiplier followed by an impedance matching circuit and an envelope detector, which extracts the baseband signal. The subsequent circuitry distinguishes between different voltage levels in the baseband signal, which corresponds to variations in the input power at the antenna. This difference is then digitized by a comparator, typically acting as a data slicer, comparing the baseband signal with its own average for further processing in the digital platform. The codesign of the energy harvesting and demodulation circuits is crucial due to their interdependence. Since both circuits draw power from the same source, the allocation of power to each circuit directly impacts their performance. Therefore, finding the optimal division of power between these two circuits is essential for enhancing the communication range between the tags. For the energy harvesting circuit, the selection of Schottky diodes and the number of stages in the voltage multiplier are key design choices that affect efficiency. While more stages typically yield higher voltages, it has been demonstrated that in low-power environments, fewer stages can be more efficient than having a larger number of stages [27]. To ensure sufficient power for tag operation without requiring a storage element, it has been shown that the input power must be approximately −15 dBm [27]. In the case of the demodulation circuit, determining the appropriate modulation depth in BTTN is essential. To address this, a link budget analysis can be performed, assuming that the excitation signal is evenly distributed and identical throughout the environment. For simplicity, it is assumed that the input power Ptag received by the tags is constant across the environment, and TT is in phase with the excitation signal [28]. III. SYSTEM AND THREAT MODELS In this section, we explain the system, channel, and threat models to determine the security goals for the studied RISaided BTTN. A. System and Channel Model We consider a BTTN setup that includes two tags (TT and LT) and their corresponding RF sources, an attacker (Eve), and
51104 IEEE INTERNET OF THINGS JOURNAL, VOL. 12, NO. 23, 1 DECEMBER 2025 an RIS, as depicted in Fig. 5. In this configuration, both TT and LT serve as semipassive backscatter devices, powered by continuous wave carrier signals emitted by RF sources in an indoor environment. The primary goal of TT is to backscatter its information to LT, with the help of an indoor RIS, which is implemented as a planar surface comprising Ndiscrete passive elements, each capable of introducing a programmable phase shift to the reflected RF wave. These phase shifts are adjusted with a low-power controller that has access to geometric or statistical knowledge of the deployment environment to achieve constructive signal alignment along the cascaded TT–RIS–LT path [29],[30],[31]. This enhancement supports improved voltage profile detection at LT, which is critical for reliable authentication in this article (the impact of RIS is also evaluated under varying experimental conditions in Section VI, including the number of RIS elements and TT–RIS–LT distances). In traditional BTTN operations, TT modifies its load impedance, influencing the reflection coefficient of its antenna to encode data within the backscattered signal, which is subsequently detected by LT [32]. The signal received by LT consists of both the direct unmodulated signal from the RF source and the modulated backscattered signal from TT, which travels through both direct and RIS-assisted paths. Without loss of generality, it is assumed that the RF source transmits unmodulated carrier signals. This allows both tags to apply simple cancellation techniques to mitigate interference originating from the source link [33],[34]. It is further assumed that the RIS has knowledge of the channel state information (CSI) for the cascaded link and the microcontroller-enabled RIS operates under a near-optimal condition, enabling the optimization of the phase shifts of its reflective elements to maximize the signal-to-noise ratio (SNR) at the receiver’s end [35],[36]. For simplicity, TT and LT are considered to be equipped with a single antenna each. Therefore, the signal received at TT is expressed as follows: YT=pPshST +nT.(5) Since the noise caused by the tag’s antenna is significantly lower than the received signal from the source, it is neglected for the remainder of this article [37]. The backscattered signal received by LT can be written as YL=BTS(t)pPshSThTL +hSTHT RLΦHTR+nL(6) whereS(t) represents the unit power information signal backscattered by TT. HTindicates the transpose of matrix H, with HTR being the channel coefficient between TT and RIS, and HRL representing the channel coefficient between RIS and LT. The matrix Φrefers to the phase shift matrix of RIS, which can be defined as Φ=diag([ejφ1,ejφ2,...,ejφN]), where Nis the number of RIS elements. The RIS-aided channel coefficients, HTR and HRL, represent the Ncoefficients from TT to RIS and RIS to LT, respectively. These can be expressed as HTR =d−χ TR.[hTR1e−jδ1,hTR2e−jδ2,...,hTRNe−jδN] and HRL =d−χ RL.[hRL1e−jζ1,hRL2e−jζ2,...,hRLNe−jζN], where j=√−1 and dTR and dRL are the distances between TT and RIS, and RIS and LT, respectively [38].χis the path-loss exponent, hTRnand hRLnare the channel coefficient amplitudes, and e−jδnand e−jζnare the phase shifts for each RIS element, where n∈ {1,2,...,N}. Given the short transmission range nature of BC in BTTNs, it is assumed that all links experience Rician fading. The backscattered signal is then received by the energy and envelope detectors’ circuits at LT to authenticate and retrieve the information transmitted by TT. B. Threat Model Given the absence of cryptographic processing onboard and the open nature of wireless channels, BTTNs are highly susceptible to various security threats. Therefore, security policies must ensure the confidentiality, integrity, and authenticity of the communication between TT and LT while preventing adversarial access to RIS. It is important to note that indoor RISs are typically designed with BC scenarios in mind, making it difficult for adversaries to physically manipulate the microcontroller [30],[39]. As a result, our PLA design operates under the assumption that the RIS is either regarded as a trusted component or is managed by a reliable entity. The primary security goal in BTTNs is to ensure that only legitimate tags (LT and TT) are able to exchange information securely, and any attempts by an adversary (Eve) to interfere, intercept, or impersonate a legitimate tag are detected and thwarted. Eve is regarded as a highly capable adversary with access to the communication channels, enabling her to launch the following common attack strategies against BTTNs. 1) Impersonation Attacks: In an impersonation attack, Eve attempts to act as the TT by transmitting signals that closely mimic the backscattered signals of the legitimate TT. If Eve can generate a backscattered signal similar enough to the legitimate TT’s profile signal, LT might fail to distinguish Eve from TT, enabling Eve to pass the authentication test and leading to a successful impersonation attack. 2) MITM Attacks: A man-in-the-middle (MITM) attack involves Eve positioning herself between TT and LT, intercepting and possibly modifying the communications between the two tags, making it appear as if the altered message came directly from TT. Since BTTNs rely on passive communication and signal backscattering, an MITM attack could exploit the weak and easily intercepted nature of the signals. 3) Replay Attack: In a replay attack, Eve captures a valid transmission from TT to LT and replays it later to deceive LT into believing that the message came from the legitimate TT. Since the replayed signal is identical to the original one, LT could be fooled into authenticating Eve’s transmission as genuine. In the context of BTTNs, replay attacks are especially dangerous because the signals are usually simplistic and lack dynamic cryptographic signatures or timestamps. 4) Relay Attacks: Relay attacks involve Eve acting as an intermediary between TT and LT, relaying signals from TT to LT from a different location. In this attack, Eve may either forward the original message from TT at the same time or block it entirely and then relay it to deceive LT. This type of attack exploits the passive nature of BC as Eve can artificially extend the communication range by relaying messages from a location closer to LT, potentially making the transmission appear legitimate. The primary security goal of this article is to ensure that LT can reliably authenticate the legitimacy of TT (and optionally,
KAVEH et al.: VOLTAGE PROFILE-DRIVEN PLA FOR RIS-AIDED BACKSCATTERING TAG-TO-TAG NETWORKS 51105 vice versa) while preventing impersonation attempts by an adversary. Moreover, the proposed PLA aims to guarantee that the messages exchanged between TT and LT are not tampered with during transmission, protect the content of the messages from being intercepted or overheard by unauthorized parties, and ensure that previously transmitted or relayed signals cannot be reused to gain unauthorized access. IV. PROPOSED PLA FOR RIS-AIDED BTTNS This section elaborates on the proposed RIS-aided PLA design for BTTNs, including output voltage derivation to approximate the measured voltage profiles at tags, the initialization phase, and the authentication phase. A. Output Voltage Derivation Since the proposed authentication scheme relies on the voltage profile signature at LT, this section provides detailed insights, focusing on deriving the output voltages from the energy harvesting and demodulator circuits in RIS-aided BTTNs to establish an accurate representation of the measured voltage profiles. According to (6), the RSS at LT can be determined as γL=ˇˇˇpPshSThTL +hSTHT RLΦHTRˇˇˇ 2 (7) ≈Ps|hST|2|hTL|2 dχ STdχ TL + Ps|hST|2ˇˇˇPN n=1hTRnhRLnejΨnˇˇˇ 2 dχ STdχ TRdχ RL (8) (a) =Ps|hST|2|hTL|2 dχ STdχ TL + Ps|hST|2ˇˇˇPN n=1hTRnhRLnˇˇˇ 2 dχ STdχ TRdχ RL (9) where (a) results from ideal phase shifting in the RIS [40], resulting in Ψn=φn−δn−ζn. The phase information in tags can be measured by a multiphase probing (MPP)-based technique, as described in [32] and [41]. Therefore, we can write the incident power on the LT at modulation state ias follows: Pinc,i=PsΓ∗ L,i0 B @|hST|2|hTL|2 dχ STdχ TL +|hST|2ˇˇˇPN n=1hTRnhRLnˇˇˇ 2 dχ STdχ TRdχ RL 1 C A. (10) The energy harvesting circuit uses a two-stage Dickson charge pump for voltage multiplication, as shown in Fig. 3 [9]. The first stage of the Dickson charge pump rectifies the input RF signal Vrf. The voltage across the capacitor Ccafter the first stage is approximately Vrf −Vd, where Vdis the forward voltage drop of the diodes. The second stage further multiplies the voltage. The output voltage after the second stage, considering the rectification, is approximately 2 ×(Vrf −Vd). Since the circuit has two stages of voltage multiplication, the final output voltage Vois Vo≈2×(2×(Vrf −Vd)) =4×(Vrf −Vd).(11) By redefining the output voltage Voand the rectified voltage Vrf in the energy harvesting circuit for different modulation states as VHrv out,iand VHrv rect,i, respectively, we have VHrv out,i≈4VHrv rect,i−4Vd.(12) The demodulator circuit involves a rectifier followed by a filter and a voltage divider network. The input RF signal Vrf, as shown in Fig. 4, is rectified by the diodes D1and D2, resulting in a peak rectified voltage of Vrf −2Vd, considering the forward voltage drops of the diodes. The rectified voltage is filtered by capacitors C3and C4to smooth out the ripples, providing a dc voltage Vbaseband approximately equal to Vrf −2Vd. The filtered dc voltage is then divided by the resistors R1and R2. The voltage across R2, which we denote as Vo, is given by the voltage divider formula Vo=Vbaseband ·R2 R1+R2 (13) where Vbaseband ≈Vrf −2Vd. Therefore, we have Vo≈(Vrf −2Vd)·R2 R1+R2 .(14) By redefining the output voltage Voand the rectified voltage Vrf in the demodulator circuit for different modulation states as VDem out,iand VDem rect,i, respectively, we have VDem out,i≈VDem rect,i−2Vd·R2 R1+R2 .(15) Let us say that the incident power at the tag is divided between the energy harvesting and demodulator circuits based on the coefficient αas follows, respectively: PHrv inc,i=αPinc,i(16) PDem inc,i=(1−α)Pinc,i.(17) As the squared voltage at the output of the energy harvesting and AM demodulator (typically an envelope detector) within the tag’s integrated circuit (IC) is directly proportional to the power absorbed by the chip [26], the rectified voltage for the energy harvesting and demodulator circuits in the on and off states can be written as VHrv rect,i=qkHrvPHrv inc,i(18) VDem rect,i=qkDemPDem inc,i.(19) By inserting (18) and (16) into (12), we rewrite the output voltage in the energy harvesting circuit as VHrv out,i≈4pkHrvαPinc,i−4Vd.(20) Now, by substituting (10) into (20), we have the output voltage in the energy harvesting circuit as (21), shown at the bottom of the next page. In the same way, by inserting (19) and (17) into (15), we rewrite the output voltage in the demodulator circuit as VDem out,i≈pkDem (1−α)Pinc,i−2VdR2 R1+R2 .(22) Now, by substituting (10) into (22), we have the output voltage in the demodulator circuit as (23), shown at the bottom of the next page.
51106 IEEE INTERNET OF THINGS JOURNAL, VOL. 12, NO. 23, 1 DECEMBER 2025 B. Initialization Phase In practical BTTN deployments, each tag must be registered within the system using a verified and unique identity, making the initialization phase critical to ensure secure communications. This stage mainly involves two key steps: the registration of the tags in the system and the creation of a baseline voltage profile for future authentication. This phase sets up the fundamental parameters and configurations required for the authentication process. 1) Tag Registration: In the registration step of the studied system model in this article, TT and LT register with a trusted central server. The server acts as the authority that manages the identification and initial configuration of the tags. Depending on the application context, this server could be a smart home IoT hub, a smart factory edge server, or a dedicated IoT gateway in other environments [42]. TT and LT transmit their unique identifiers, such as preprogrammed serial numbers, to the server through a secure communication channel by modulating their load impedance and backscattering the RF signal. The server may also configure the RIS by accessing its microcontroller with the relevant settings and ensure that it recognizes TT and LT as legitimate entities in the system. The registration process ensures that both tags are properly authenticated and ready for secure interactions in the RISaided BTTN environment. 2) Baseline Voltage Profile Creation: Following registration, LT establishes a baseline voltage profile to enable future TT authentication. This step begins with TT transmitting a series of known pilot signals while modulating the RF field through distinct modulation states, such as “on” and “off.” To enhance the quality of these signals, RIS is configured adaptively to optimize the RF energy distribution between TT and LT. The RIS microcontroller determines the phase-shifting coefficients adaptively based on the received pilot signals, ensuring maximum signal strength at LT. This configuration requires the availability of CSI for the cascade links, which is either locally estimated at the RIS microcontroller or provided by the server, depending on the system design. If provided by the server, the RIS microcontroller adjusts the reflective elements dynamically according to the CSI updates received. Periodic recalibration may also be performed if environmental conditions change. LT then measures the output voltage generated by its energy harvesting and demodulation circuits for each modulation state, capturing the unique signal characteristics enhanced by Fig. 6. Different steps of the initialization phase. the RIS configuration to establish a robust baseline voltage profile. The measured voltages, denoted as VHrv out,0and VDem out,0, correspond to TT’s unique physical layer signature and can be approximated, as shown, respectively, in (21) and (23), at the bottom of the page. These profiles together with TT’s identifier (IDT) are securely stored in LT’s memory for comparison during future authentication sessions. Optionally, the central server may also maintain a backup of these profiles to ensure system resilience against memory loss or corruption in LT.It should be noted that to prevent adversaries from interfering with the initialization phase, all communications between TT, LT, RIS, and the server must be conducted over a secure channel. In addition, the environment in which the baseline voltage profiles are measured must be free from interference or environmental noise to ensure the integrity of the recorded profiles. The trusted server ensures that all entities, including RIS, operate securely and under legitimate control during this phase. By completion of the initialization phase, TT and LT are securely registered, and LT is equipped with a reliable baseline voltage profile to authenticate TT in subsequent interactions. Fig. 6illustrates the various stages of the initialization phase. C. Authentication Phase Once the initialization phase is complete, TT and LT enter the operational stage, where TT’s identity is verified by LT VHrv out,i≈4v u u u u tkHrvαPsΓ∗ L,i0 B @|hST|2|hTL|2 dχ STdχ TL +|hST|2ˇˇˇPN n=1hTRnhRLnˇˇˇ 2 dχ STdχ TRdχ RL 1 C A−4Vd(21) VDem out,i≈0 B B @ v u u u u tkDem (1−α)PsΓ∗ L,i0 B @|hST|2|hTL|2 dχ STdχ TL +|hST|2ˇˇˇPN n=1hTRnhRLnˇˇˇ 2 dχ STdχ TRdχ RL 1 C A−2Vd1 C C A R2 R1+R2 (23)
KAVEH et al.: VOLTAGE PROFILE-DRIVEN PLA FOR RIS-AIDED BACKSCATTERING TAG-TO-TAG NETWORKS 51107 during each communication session. This phase involves the following key steps. 1) Backscattering Signal by TT: TT initiates the authentication process by backscattering its modulated signal, which encodes its unique identifier IDTalong with session-specific data. To enhance security, TT modulates the RF field in a manner consistent with its registered baseline voltage profile, cycling through predefined modulation states (e.g., on and off) similar to the pilot signals transmitted during initialization. This ensures that the transmitted signal maintains the physical layer characteristics expected by LT. 2) Signal Reception and Voltage Measurement by LT: LT receives the backscattered signal from TT and extracts the transmitted identifier IDT. Simultaneously, LT measures the output voltage generated by its energy harvesting and demodulation circuits for each modulation state. These measured voltages, VHrv out and VDem out , represent TT’s current physical layer signature under operational conditions. The uniqueness of these voltage profiles is intrinsically tied to TT’s locationspecific CSI, ensuring that the physical layer characteristics of the backscattered signal are distinct for a tag at a particular location. In addition, this uniqueness is further influenced by the physical circuitry of LT, including the capacitance and resistance of the capacitors, resistors, and diodes in its energy harvesting and demodulation circuits. During this step, the RIS dynamically adjusts its phase-shifting coefficients (Ψ) to optimize the RSS at LT. By fine-tuning the phase shifts of its reflective elements, the RIS maximizes the SNR at LT, which improves the reliability and precision of the voltage measurements. 3) Profile Comparison and Decision: LT compares the measured voltages VHrv out and VDem out with the baseline profiles VHrv out,0and VDem out,0stored during initialization. The comparison is conducted as follows: ∆VHrv =ˇˇVHrv out −VHrv out,0ˇˇ(24) ∆VDem =ˇˇVDem out −VDem out,0ˇˇ.(25) If ∆VHrv and ∆VDem fall within predefined thresholds τHrv and τDem, respectively, LT authenticates TT as a legitimate tag. Otherwise, the authentication is rejected. Within the tag’s circuitry, this comparison process is facilitated by a simple comparator unit. The comparator takes the measured voltages and baseline profiles as inputs and calculates the voltage differences ∆VHrv and ∆VDem. To determine the legitimacy of TT during the authentication phase, a binary hypothesis test can be conducted based on the deviation of the measured voltages from their corresponding baseline values as follows: (H0:∆VHrv ≤τHrv and ∆VDem ≤τDem H1:∆VHrv > τHrv or ∆VDem > τDem (26) where H0indicates the case that the measured voltage profiles VHrv out and VDem out belong to a legitimate TT while H0indicates that an adversarial attempt might happen. This implementation ensures low-power consumption and quick decision-making, aligning with the resource constraints of passive BTTN tags. 4) Authentication Confirmation: Upon successful authentication, LT can optionally transmit a confirmation message Fig. 7. Different steps of the authentication phase. to TT, allowing secure data exchange to proceed. This confirmation message can include additional session-specific parameters to establish a secure communication session. Following this, TT can authenticate LT in an exact same manner by leveraging the baseline voltage profiles VHrv out,0and VDem out,0established during the initialization phase. TT measures the output voltages generated by its circuits upon receiving backscattered signals from LT and compares them against the baseline profiles stored in its memory. By repeating the same process of voltage profile matching and threshold validation, TT ensures that the backscattered signal originates from LT. This mutual authentication process ensures bidirectional security, safeguarding both tags against impersonation attacks, and establishing a trusted environment for subsequent data exchange. Any authentication failure at any of these stages will cause the tags to discard the received signal and may alert the central server for anomaly detection and system diagnostics. Fig. 7shows different steps in the authentication phase. Remark 1: The effectiveness of the proposed authentication phase is fundamentally dependent on the integrity of the baseline voltage profiles, VHrv out,0and VDem out,0, established during the initialization phase. Reliable physical measurements from the energy harvesting and demodulation circuits are crucial for ensuring accurate and consistent voltage profiles. However, various factors can affect the reliability of these measurements. Environmental conditions, such as temperature fluctuations, humidity, or RF signal obstructions, may introduce noise or distortions, leading to deviations in the recorded profiles. Similarly, hardware limitations or variations in circuit components, including diodes, capacitors, or resistors, can cause nonlinearities that degrade the quality of the measured voltages. Moreover, the uniqueness of the physical layer attributes, which forms the foundation of the authentication scheme, is inherently tied to the CSI of the direct and cascade links. These coefficients encapsulate the unique propagation characteristics of the RF signal between the TT and LT, influenced by factors such as distance, multipath fading and shadowing effects, and obstacles. This dependence ensures that the physical-layer features are specific to the tag’s location and cannot be easily replicated by an adversary from a different location. Remark 2: The RIS configuration plays a critical role in ensuring high-quality signal strength at the LT. A welloptimized and secure RIS controller is essential for enhancing