scieee AI-readable full text Open interactive document viewer

D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization

NXP

Abstract

This deliverable D5.2 describes refined concepts and findings on the hardware fingerprinting concept and link-level simulation platform development. The concepts and application to RAN physical layer security have been worked out and form an initial base for further developments in the field. Several key enablers have been investigated and documented to see how this can lead to increased trustworthiness of future 6G system and network developments.

Full text

© COREnext 2023-2025 D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 2 | 74 Revision v1.3 Work package WP5 Task T5.2 Dissemination level SEN – Confidential to COREnext project and Commission Services Deliverable type R — Document, report (excluding periodic and final reports) Due date 30-09-2025 Submission date 29-09-2025 Deliverable lead NXP Version v1.4 Authors Dick van den Broeke (NXP), Florent Torres (EAB), Jonas Lindstrand (EAB), Fredrik Tillman (EAB), Mamoun Guenach (IMEC) Contributors All Task partners (see below) Reviewers Thomas BOHN (NOK), Ross STATON (NOK); Laurent PETIT (RAD) Abstract This deliverable D5.2 describes refined concepts and findings on the hardware fingerprinting concept and link-level simulation platform development. The concepts and application to RAN physical layer security have been worked out and form an initial base for further developments in the field. Several key enablers have been investigated and documented to see how this can lead to increased trustworthiness of future 6G system and network developments. Keywords Trustworthiness, fingerprinting, RAN, security, analogue techniques and components, reliability D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 3 | 74 Document Revision History Version Date Description of change Contributor(s) v1.2 17-09-2025 version for review Dick van den Broeke (NXP) & al. v1.3 22-09-2025 Recovered from corrupted v1.2 Dick van den Broeke (NXP) & al. v1.4 29-09-2025 Final version Dick van den Broeke (NXP) & al. Contributing Partners Abbreviation Company name CHAL CHALMERS TEKNISKA HOGSKOLA CEA COMMISSARIAT AL ENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES EAB ERICSSON IFAG INFINEON TECHNOLOGIES AG IMEC INTERUNIVERSITAIR MICRO-ELECTRONICA CENTRUM NXP NXP SEMICONDUCTORS RAD RADIALL IMS INSTITUT POLYTECHNIQUE DE BORDEAUX NOK NOKIA NETWORKS GERMANY NNF NOKIA NETWORKS FRANCE IFAT INFINEON TECHNOLOGIES Disclaimer The information, documentation and figures available in this deliverable are provided by the COREnext project’s consortium under EC grant agreement 101092598 and do not necessarily reflect the views of the European Commission. The European Commission is not liable for any use that may be made of the information contained herein. Copyright Notice ©COREnext 2023-2025 D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 4 | 74 Executive Summary Building on the earlier explorations reported in D5.1, this document describes three concepts at different levels to improve the trustworthiness of radio links at the physical layer. In the first concept, the User Equipment is challenged by the network Access Point to generate an active Fingerprint. Unlike passive Fingerprint extracted from the standard transmission signal, the actively generated Fingerprint contains circuit specific signal-distortions resulting from a predefined signal that can be identified more easily as coming from a trusted or non-trusted source. The second concept comprises the architecture of the receiver analogue and digital front-end, that is optimized to extract the data to be passed to the Machine Learning algorithm for detecting the Fingerprint. The receiver architecture was developed from considering what types and levels of distortion can be expected from legitimate of fake Base Stations and how those signals are affected by Over-The-Air transmission. The concept of the receiver architecture is complementary to the first concept of generating an active Fingerprint, as the receiver can be used to detect the actively inserted Fingerprint generated by the transmitter. The third concept exploits the properties of massive MIMO systems that are capable of transmitting or receiving actively steered radio beams. Once an Eavesdropper has been detected using (actively) generated Fingerprint and the proposed receiver architecture, a MIMO-capable device may disturb the Eavesdropper by sending Active Noise into the direction of the Eavesdropper, while leaving the signal quality into the direction of the legitimate target unaffected. In addition to the concepts, this document also describes test platforms to be used for validation in WP6. The digital building blocks provided by WP4 are agnostic to their precise function and can be used to implement one or more of the three concepts. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 5 | 74 Table of Contents 1 Introduction ............................................................................................................................................ 13 2 Summary of Results from D5.1 .......................................................................................................... 14 2.1 Concepts of Fingerprinting ............................................................................................................................................... 14 2.2 Sources of Distortion in the RF Transmitter ............................................................................................................. 15 2.3 Fingerprinting on In-band and Out-band signal ..................................................................................................... 15 2.4 Generating Transmitter IQ data for WP4 ................................................................................................................... 15 2.5 Dband Link Level Simulator ........................................................................................................................................... 15 2.6 Beamforming and Jamming Against Eavesdropper Attacks .............................................................................. 16 2.7 Random Variations from Production ........................................................................................................................... 17 3 Active Fingerprinting ............................................................................................................................ 18 3.1 Introduction ............................................................................................................................................................................ 18 3.2 Ericsson Hardware Experimentation Platform Details ......................................................................................... 19 3.3 Experimental Data Definition ......................................................................................................................................... 21 3.4 Software Defined Radio Characteristics .................................................................................................................... 23 3.5 Influence of SDR Settings on RF Fingerprint ML Algorithm ............................................................................. 26 3.6 RFF Enhancement Technique ........................................................................................................................................ 29 3.7 Application of These Refined RFF Concepts Towards Validation ................................................................... 32 3.8 Additional Concepts around RFF for PLS .................................................................................................................. 33 3.9 Future Research Directions ............................................................................................................................................. 35 3.10 Conclusions ............................................................................................................................................................................ 36 4 Receiver Architecture to Extract Fingerprint from Base Station ............................................... 37 4.1 Architecture and Requirements of Analog Front-End of Base Station ......................................................... 37 4.2 Typical Architecture of Fake Base Station (Software Defined Radio) .......................................................... 40 4.3 Signal Impairments in Legitimate and Fake Base Stations ................................................................................ 42 4.4 Signal Impairments and Noise in Link from Base Station to User Receiver ............................................... 45 4.5 Architecture of a Receiver with Hooks to Identify Fingerprint ......................................................................... 47 4.6 Capture of Transmit Signals from Base Station Analog Front-end or Full Transmit Chains ............... 49 4.7 Conclusions ............................................................................................................................................................................ 53 5 Sub-THz Beamforming for High-Throughput and Secure Radio Links ................................... 54 5.1 Sensitivity Analysis and (sub) THz Link Robustness to RF HW Nonidealities ........................................... 54 5.1.1 Introduction ............................................................................................................................................................... 54 5.1.2 Analog Beamforming Inaccuracies ................................................................................................................... 54 D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 6 | 74 5.1.3 Power Amplifier Distortion .................................................................................................................................. 59 5.1.4 Conclusions ................................................................................................................................................................ 64 5.2 Towards Robust (sub) THz Beamforming Against Eavesdropper Attacks ................................................... 65 5.2.1 System Model ........................................................................................................................................................... 65 5.2.2 Performance Analysis ............................................................................................................................................ 66 5.2.3 Conclusions ................................................................................................................................................................. 71 6 Conclusions ........................................................................................................................................... 72 7 References .............................................................................................................................................. 73 D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 7 | 74 List of Figures Figure 1: UE impersonating other UE. ........................................................................................................................ 14 Figure 2: Fake BS impersonating legitimate BS. .................................................................................................... 14 Figure 3: Preventing Eavesdropper from receiving a proper signal by means of sending a beam with artificial noise. ...................................................................................................................................................................... 16 Figure 4: Hardware platform as described in D5.1. ............................................................................................... 19 Figure 5: Current COREnext hardware experimental platform. ..................................................................... 21 Figure 6: Example of transmitted signal after recording (one 5G NR slot, for illustration purpose) 22 Figure 7: Illustration of transmitted signals, built from 65 5G NR PUSCH slots. .................................... 22 Figure 8: USRP B210 and B205 mini-i architecture with focus on their RFE .......................................... 23 Figure 9: PCB integration of USRP B210 and B205 mini-i SDRs ................................................................. 24 Figure 10: TX performance at 2.5 GHz for both the USRP B210 and B205-mini-i. ............................. 25 Figure 11: TX frequency response, gain set to 87 dB for B210 and 86 dB for B205 mini-i. ............... 26 Figure 12: 2D view of the influence of frequency and gain SDR settings on RF Fingerprint ML algorithm mean accuracy .............................................................................................................................................. 27 Figure 13: 3D view of the influence of frequency and gain SDR settings on RF Fingerprint ML algorithm mean accuracy .............................................................................................................................................. 28 Figure 14: Confusion matrix for 2 devices from the same manufacturer and model (USRP B205 mini-i) using frequency and gain sweeping datasets. ........................................................................................ 28 Figure 15: Impairment enhancement waveform concept illustration in the time-domain ................ 29 Figure 16: Recorded RX spectrum without and with IEW for 2 devices. ................................................... 30 Figure 17: The accuracy/loss curves over epochs (left), the confusion matrix (right). The data is with the IEW. Here, devices 3 and 4 represent the two B205 mini-i SDRs. ....................................................... 31 Figure 18: The accuracy/loss curves over epochs (left), the confusion matrix (right). The data is without the IEW. Here, devices 3 and 4 represent the two B205 mini-i SDRs. ...................................... 31 Figure 19: Lab setup for close set experimentation ............................................................................................ 32 Figure 20: Confusion matrix for 3 transmitters from the same manufacturer - Device 1 is a USRP B210, Device 2 and 3 are two distinct USRP B205 mini-i. .............................................................................. 33 Figure 21: Flowchart from one of the processes issued from [31] ................................................................. 34 Figure 22: Lab setup for temperature analysis experiment ............................................................................. 35 Figure 23: Inference classification accuracy versus temperature. Training done at room temperature. ....................................................................................................................................................................... 36 D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 8 | 74 Figure 24: Simplified block diagram of transmitting Macro-cell Base Sation and 2 receiving User Devices. ................................................................................................................................................................................. 38 Figure 25: Simplified block diagram of transmitting Micro-cell Base Sation and 2 receiving User Devices. ................................................................................................................................................................................. 38 Figure 26: Simplified block diagrams of possible Fake Base Sation. ............................................................. 41 Figure 27: Spectra captured from 7 high-performance Base-Station RF transmitters with RFDACs and DPD. Data captured by NXP. ............................................................................................................................... 43 Figure 28: EVM and Complementary Cumulative Distribution Function (CCDF, red curves) simulated using CFR algorithm with deceasing PAR reduction. .................................................................... 43 Figure 29: Spectra calculated from 4 measured low-cost zero-IF transmitters. Data acquisition courtesy of NOK ................................................................................................................................................................ 44 Figure 30: IQ imbalance calculated from 4 measured low-cost zero-IF transmitters. Data acquisition courtesy of NOK ......................................................................................................................................... 44 Figure 31: Example of Amplitude and Phase ripple caused by reflections between Transmitter and Receiver. ................................................................................................................................................................................ 45 Figure 32: Received Signal-to-Noise Ratio as function of range from Transmitter to Receiver. For short ranges, the gain of the first receiver stages is reduced in order to prevent overdriving the ADC and noise from the ADC will dominate over noise from the receiver LNA. ............................................. 46 Figure 33: CCDF of received signal with increasing level of reflected signal (multi-path). In this example, the reflected path was just assumed 10 meters longer than the direct path. ..................... 47 Figure 34: Example Architecture of a receiver capable of identifying RF Fingerprint. ......................... 48 Figure 35: Method to derive a mathematic model of a PAM from circuit simulation and run the PAM model in a system simulation. .................................................................................................................................... 50 Figure 36: Direct measurement in full physical system. .................................................................................... 51 Figure 37: Method to derive a mathematic model of a PAM from circuit measurement and run the PAM/full AFE model in a system simulation. ....................................................................................................... 52 Figure 38: Example of AMAM and AMPM distortions from 6 measured PAMs ...................................... 52 Figure 39: The received energy for a transmit and receive BF errors that are uniformly distributed ~𝑈(0, 𝜙𝑇𝑋,𝑚𝑎𝑥,) and ~𝑈(0, 𝜙𝑅𝑋,𝑚𝑎𝑥,), 𝑁𝑇𝑋 =16, 𝑁𝑅𝑋 = 8 . .......................................................... 56 Figure 40: BER performance of a 64 -QAM modulation resulting from TX and RX BF errors ,~𝑈(0, 𝜙𝑚𝑎𝑥,) for 𝑁𝑇𝑋 =16 and 𝑁𝑅𝑋 = 8. ..................................................................................................... 56 Figure 41: Required BF accuracy for a target maximum SNR loss 𝛾𝑙𝑜𝑠𝑠 = 1dB at a target uncoded 𝐵𝐸𝑅 =10 − 4 of a 64 -QAM modulation. The transmit and receive BF errors are either static (lefthand side figure) or uniformly distributed (right-hand side figure). 𝑁𝑇𝑋 = 2,4,8,16 and 𝑁𝑅𝑋 = 8. .................................................................................................................................................................................................. 57 D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 9 | 74 Figure 42: CDF of the worst SINR in the high SNR regime( 𝐸𝑆𝑁0 = 50dB) for,𝐾 = 8 users and imperfect TX BF with ~𝑈(0, 𝜙𝑚𝑎𝑥,) and perfect RX BF for both PCA and FCA with 𝑁𝑇𝑋 =64 and 𝑁𝑅𝑋 = 8. .............................................................................................................................................................................. 58 Figure 43: Uncoded BER performance for 64-QAM modulation , 𝐾 = 8 users, imperfect TX BF with ~𝑈(0, 𝜙𝑚𝑎𝑥,) and perfect RX BF for both PCA and FCA with 𝑁𝑇𝑋 =64 and 𝑁𝑅𝑋 = 8. ............... 58 Figure 44: Coded BER performance for 64-QAM modulation , 𝐾 = 8 users, imperfect TX BF with ~𝑈(0, 𝜙𝑚𝑎𝑥,) and perfect RX BF for FCA with 𝑁𝑇𝑋 =64 and 𝑁𝑅𝑋 = 8. ............................................. 59 Figure 45: Power amplifier signal distortion with input power backoff (PBO). ........................................ 59 Figure 46: Example of the impact of PA cubic model on a 64-QAM constellation in a LOS channel: left-hand (PBO=0dB), middle(PBO=3dB), right-hand (PBO=+6dB) ........................................................... 60 Figure 47: The average 1/EVM versus the PBO for different PA models with AM-AM and AM-PM distortions assuming 64-QAM constellation in a LOS propagation model and in a high SNR regime 𝐸𝑠/𝑁0 = 50dB. ................................................................................................................................................................... 61 Figure 48: Uncoded BER versus information 𝐸𝑏/𝑁0 for different PA models with AM-PM distortions assuming 64-QAM constellation in a LOS propagation channel. .......................................... 62 Figure 49: Required information 𝐸𝑏/𝑁0 at target uncoded BER=10 − 3 for different PA models with AM-PM distortions assuming 64-QAM constellation in a LOS propagation channel. ............... 62 Figure 50: Coded BER versus 𝐸𝑏/𝑁0 for different PA models with AM-PM distortions assuming 64-QAM constellation in a LOS propagation channel/. ................................................................................... 63 Figure 51: Required 𝐸𝑏/𝑁0 at target coded BER=10 − 5 for different PA models with AM-PM distortions assuming 64-QAM constellation in a LOS propagation channel. .......................................... 64 Figure 52: Communication link with beam leakage to eavesdropper ......................................................... 65 Figure 53: The received energy (BFG) at the regular UE with AoD 𝜙𝑇𝑋 =0° and at EVD with 𝜙𝑇𝑋 ∈ −60°,60° and for different numbers of transmit antennas 𝑁𝑇𝑋. The beamforming is aligned with AoDs and the relative AN power 𝜂/𝜂 = 0. ................................................................................... 66 Figure 54: The SINR in the high SNR regime (𝐸𝑆𝑁0 = 50dB) at the UE with AoD 𝜙𝑇𝑋 =0° and at EVD with 𝜙𝑇𝑋 ∈ −60°,60° and for different numbers of transmit antennas 𝑁𝑇𝑋. The beamforming is aligned with AoDs the relative AN power 𝜂/𝜂 = 0. .......................................................... 67 Figure 55: The SINR in the high SNR regime (𝐸𝑆𝑁0 = 50dB) at the UE with AoD 𝜙𝑇𝑋 =0° and at EVD with 𝜙𝑇𝑋 ∈ −60°,60° and for 𝑁𝑇𝑋 =64. The beamforming is aligned with AoDs the AN relative power is 𝜂𝜂 =1% (left-hand side) and 10% (right-hand side). .................................................... 68 Figure 56: The SINR in a moderate SNR regime (𝐸𝑆𝑁0 = 20dB) at the UE with AoD 𝜙𝑇𝑋 =0° and at EVD with 𝜙𝑇𝑋 ∈ −60°,60° and for 𝑁𝑇𝑋 =64. The beamforming is aligned with AoDs the relative AN power 𝜂𝜂 =1%. ........................................................................................................................................ 68 Figure 57: The received energy (beamforming gain) at the UE (left-hand side) with AoD 𝜙𝑇𝑋 =0° and at EVD (right-hand side) with 𝜙𝑇𝑋 ∈ −60°,60° and for 𝑁𝑇𝑋 =64. The beamforming is optimized for different target BFGs at EVD and the relative AN power 𝜂/𝜂 = 0. ................................. 69 D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 16 | 74 cases, the model describes the transfer function from multiple transmitting antennas into multiple receiving antennas. The Dband simulator is capable of modelling both the partially as well as the fully connected antenna architecture. In the first case, a dedicated subset of antenna elements is required per beam. This is typically used for millimetre wave systems at >20GHz. As an example, NXP developed a 26GHz Analog Beamforming Transmitter/Receiver ICs MMW9014 [25]. 16 of those ICs were assembled into a 64-element antenna panel [26]. In the second case, each antenna element contributes to every beam. This mode is suited for systems operating at lower spectrum, but it is expected to not scale towards higher operating frequencies such as Dband because of higher amount of antenna elements and number of channels (phase shifters) required. In the Dband simulator, the impairments, from e.g. the RF power amplifier, Local oscillator, ...etc., can be controlled via a set of parameters. For example, the spread of the amplifier compression point, spectral shape of the LO phase noise, IQ gain and phase error and LO frequency offset. 2.6 Beamforming and Jamming Against Eavesdropper Attacks In addition to improving authentication through Fingerprinting, trustworthiness can also be improved by optimizing the beamforming and, once an Eavesdropper (EVD) has been detected, actively transmitting jamming signals into the direction of the EVD. Section 3.5.3 specifically addresses in-door use cases with highly sensitive communication links. For instance, the link between the AP and a robot (UE) in automated industrial processes or sensors exchanging vital information on the patient should be most reliable and secure in an early stage without increasing the end-to-end latency. As illustrated in the figure below, it is investigated how beamforming can be used to minimize the amount of power radiated towards an Eavesdropper (EVD) or even feed additional noise beamed towards the EVD while preserving the signal quality towards the legitimate receiver. Figure 3: Preventing Eavesdropper from receiving a proper signal by means of sending a beam with artificial noise. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 17 | 74 2.7 Random Variations from Production An Analogue Front-End (AFE) or RF amplifier does not only consist of an IC in silicon, but rather is mounted in a package, has been mounted on a PCB and contains several external components. Hence, multiple contributions to production spread were identified: • Wafer processing of silicon components • Die or IC assembly in the package and on the board (accuracy of chip position, thickness and thermal conductivity of glue, amount of solder) • Spread of non-silicon components (like circulators, couplers, RF filters, connectors) • Spread of PCB properties (thickness of prepreg and metal layers, width of metal tracks) It was noted that even the spread in linear components like the circulator may impact non-linear distortion as for example reflected power from the circulator back into the RF power amplifier will affect its non-linearity. And as the RF frequencies increase, all contributions become more or less equally relevant: each additional small piece of metal will behave as an inductor and change circuit behaviour. All these deviations may contribute to the uniqueness of a Fingerprint. As all those effects are difficult to simulate, it is important to use data from actual measurements for validation. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 18 | 74 3 Active Fingerprinting 3.1 Introduction In D5.1 we defined the COREnext focus for RF Fingerprinting in the context of physical layer security and applied to Radio Access Network (RAN). The main scenario being the authentication of UE by a radio node (eNB, gNB, access point, etc.) based on its transmitted data (Uplink). We identified challenges such as determining hardware from specific vendors/manufacturers, determining individual instances of this hardware from specific vendor/manufacturer and detect impersonations attack. These are the challenges we focused on for refining the concepts of RF Fingerprinting for physical layer security for RAN. While advancing towards tackling these challenges we also refined the use cases to apply the developed techniques. It appears that RF Fingerprint is particularly well suited for authentication in private networks (e.g. 5G NR private network) in which: - The number of devices is constrained and scalable. - Customizable security policies can be implemented. - Enhanced security can be deployed for critical applications. Deployment scenario of such networks are airports, healthcare, campus or correctional facilities, smart city, mining, manufacturing, etc. If we take the example of private networks in the manufacturing industry, there are between 1000s and 10000s devices on a manufacturing floor (such as sensors, actuators, robots, automatic guided vehicles, security systems, workers wearables, etc.). At the same time, an unauthorized network access by a device can cause multiple disruptions such as: - Malware / ransomware injection and data theft. - Sabotage / disruption of industrial process. - Interference with IoT devices. - Man-in-the-middle attack. - Surveillance / industrial espionage. - Resource drain on NW infrastructure. - Spoofing of legitimate devices. - Bypassing physical access control There are several benefits of RF Fingerprinting in private networks in such a deployment scenario. RFF could be used for device authentication on the network and can enable or reinforce access control to the networks, to specific resources, services or specific areas. It can also detect and/or protect from threats such as network of physical intrusion detection, device impersonation or spoofing detection, fake radio node detection, and replay attack protection. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 19 | 74 It is also worth noting the unique approach COREnext is having towards RF Fingerprinting concepts. Most of the prior art, to the authors knowledge, is focusing on using Bluetooth, LoRa, IOT and WIFI devices/protocols for their low cost – low security paradigms. This is limiting the prior art studies to passive RF Fingerprinting, in which signals are opportunistically captured. Our approach is focused on the use of active RF Fingerprinting, in which signals are requested from the UE, which is a paradigm change compared to the prior art. We also focus on cellular standards, mainly 5G and beyond wireless networks, having way more post processing power and ML capabilities. The following sections are showing the different elements that have been used in WP5 to further develop the RF Fingerprint concept within COREnext and the different resulting studies and concepts, while we refer to D4.4 for the work on the ML development, which is using the data produced in WP5. Validation of the RFF concepts takes place in WP6 and is not described in this deliverable. 3.2 Ericsson Hardware Experimentation Platform Details As it has been mentioned in the deliverable D5.1, we decided to develop a hardware test platform tailored to COREnext studies needs which is capable to fully capture the effect of all the important non-idealities in radio transceivers that cannot be fully captured by a software platform and simulations, such as self-heating, self-interference, memory effect, temperature-induced drifts, manufacturing induced performance drifts, etc. It should also be noted that all hardware experimental platform details will be shown in more detail in the deliverable D6.1. In Figure 4, the first plan for the hardware platform as described in D5.1 is illustrated. We planned to use a PC running GNURadio (open-source software development kit used for software-defined radio applications) on the transmitter side and another PC running GNURadio on the receiver side, using two USRP B205 mini-i as transmitters and one USRP B210 as a receiver. Figure 4: Hardware platform as described in D5.1. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 20 | 74 During early hardware experimentations, it appeared that the setup described in D5.1 would be inefficient for our use and for the creation of large datasets. Using one PC for transmitting and another PC for recording data and two distinct instances of GNURadio running on each PC makes their synchronisation difficult. Also, while GNURadio is an excellent software for such applications, it lacked the flexibility needed for our use case. For this purpose, an in-house Python-based software dashboard was developed and improved flexibility, control-ability, and expand-ability are the main advantages of using this Python-based software dashboard over GNURadio. The in-house Python-based software dashboard can control the different SDRs in a synchronous way while also controlling equipment settings such as RF switches and external components bias/supply levels. This platform also makes it very efficient to create large datasets. The current hardware experimentation platform is illustrated in Figure 5. It consists of: - The Python-based TRX dashboard, - Two USRP B205 mini-i as transmitters, - One USRP B210 as receiver, - A 10MHz clock reference for the TX and RX USRP SDRs (Agilent 3325DA Function/Arbitrary Waveform Generator), - A 2-to-1 RF switch (Keysight L3111D 40GHz 50ohms SPDT switch) - Optional external components, such as external PAs, depending on studies (see corresponding sections for more information). - 30dB attenuator in front of the RX SDR to avoid any damages to the receiver hardware. - A wired radio link. It is worth noting that for some studies we also borrowed a supplementary USRP B210 to use as a transmitter and in this case a second RF Switch is used. This Hardware experimental platform is interfaced with a 5G NR simulator for 5G NR waveform generation. See Section “3.3 Experimental data definition” for more details about 5G NR waveforms used in COREnext. It is also interfaced with the ML dashboard used by the ML team in WP4 who is using the created dataset to develop the RF Fingerprint ML algorithms. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 21 | 74 Figure 5: Current COREnext hardware experimental platform. 3.3 Experimental Data Definition We have at our disposal around 500 5G NR PUSCH signals (each containing 15360 samples), generated with an Ericsson internal tool. All these 5G NR PUSCH slots have the same characteristics (see Table 3-1), however the data is different for all of them and there is no repetition between samples. An example of such a transmitted 5G NR PUSCH (after being recorded) is shown in 6. Table 3-1: 5G NR PUSCH slots characteristics Modulation type OFDM Modulation order 64-QAM Sample rate 15.36MHz To make the creation of large datasets more efficient, several 5G NR PUSCH slots are combined into one transmission, so the SDRs does not need to be restarted for each transmitted PUSCH slots. Empirically each transmission combines 65 PUSCH slots, which is close to 1 million samples for each transmission from an SDR. This is illustrated in Figure 7. It is worth noting than for all the experimentations, ML algorithm and concepts development, the data used for a fair evaluation at inference has never been used at training. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 22 | 74 Figure 6: Example of transmitted signal after recording (one 5G NR slot, for illustration purpose) Figure 7: Illustration of transmitted signals, built from 65 5G NR PUSCH slots. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 23 | 74 3.4 Software Defined Radio Characteristics In this section we show the characteristics of the SDR used as transmitters, only focusing on their radio front end (RFE) operation as this is the hardware element having an impact on RF Fingerprint. The USRP B205 mini-i [29] and the USRP B210 [30], both from NI, are very similar devices. Both models can operate in frequencies between 70MHz and 6GHz and have the same architecture. The main difference between them is that the USRP B210 uses an AD9361 RFE with two TX and two RX channels, while the USRP B205 mini-i uses an AD9364 RFE with one TX and one RX channels. In essence, the AD9361 and AD9364 RFE have the same architecture and using the same elements besides twice the number of channels for the AD9361. This is shown in Figure 8. Figure 8: USRP B210 and B205 mini-i architecture with focus on their RFE It means that even if these two SDR models are different, their RFE architecture is very similar, and their RF Fingerprint will be very close. The main difference between these models resides in their PCB integration. As it can be seen in Figure 9, in which the RFE RFICs are highlighted in yellow and the RF path between RFIC and TX output in red, the USRP B205 mini-i is way smaller than the B210. The RF path to the TX output is substantially shorter and this might have an impact on the RF Fingerprint. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 24 | 74 Figure 9: PCB integration of USRP B210 and B205 mini-i SDRs Finally, the TX performances of both SDR models is shown, from the manufacturer datasheet. In Figure 10, at a fixed frequency of 2.5GHz and different gain settings. In Figure 11, the same metrics are shown for a fixed gain of 87dB (USRP B210) and 86dB (USRP B205 mini-i) over the whole frequency range of operation. It is worth noting that the TX performances are very close for both SDR models, especially when the SDRs are operating close to maximum gain and most of the impairments are smaller in magnitude than the communication signal. The actual numbers when the gain is fixed at 2.5 GHz, the following can be extracted for the USRP B210 and the USRP B205 mini-i Figure 11: - DC Offset: -44 dBc (USRP B210) vs -42 dBc (USRP B205 mini-i). - IQ Imbalance: -50 dBc (USRP B210) vs -53 dBc (USRP B205 mini-i). - IM3 from OIP3: -26 dBc (USRP B210) vs -28 dBc (USRP B205 mini-i) (Calculated with IM3=2 * [OIP3 - Pfund]). - IM2 from OIP2: -50 dBc (USRP B210) vs -37 dBc (USRP B205 mini-i) (Calculated with IM2=Pfund-OIP2). D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 25 | 74 So, it can be concluded at 2.5 GHz with “maximum” gain the DC Offset, IQ Imbalance, and IM2 are the hardest to differentiate and requires a really good SNR, while the IM3 has much larger signal amplitude when compared. Figure 10: TX performance at 2.5 GHz for both the USRP B210 and B205-mini-i. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 32 | 74 devices (device 1 is device 3 and device 2 is device 4 in Figure 17and Figure 18, due to different nomenclature between WP4 and WP5). In contrast, the data without the IEW exhibits slower and less stable convergence, with validation accuracy saturating around 85% after 200+ epochs and a higher level of misclassification between the devices. These results indicate that the data with the IEW provides more consistent and discriminative features for RFF, making it a better dataset for reliable device identification. Clearly, IEW demonstrates a positive impact on model footprint and performance. 3.7 Application of These Refined RFF Concepts Towards Validation While in WP5 we focus on the development of the concepts for RF Fingerprinting to strengthen physical layer security for RAN, validation activities are done in WP6 and will be reported in D6.1. A first step towards validation is the identification of 3 different devices from the same manufacturer, in what we call a close-set scenario. Meaning that the 3 devices are part of the MLA training. More details are available in D4.4. For this purpose, the same hardware platform as depicted previously were used, however this time an additional USRP B210 was used as a transmitter, which add a second RF switch (4 to 1 RF Switch), as illustrated in Figure 19. Transmissions are done at 2.5GHz and 88dB of gain for all SDRs. Figure 19: Lab setup for close set experimentation For the MLA training the same 5G NR data as depicted in the previous sections were used. However, to be more realistic, the inference is done with only one 5G NR PUSCH slot (15360 samples). In other words, during the RF Fingerprint authentication process, if the MLA has been trained for a specific device, this device only needs to transmit one PUSCH slot to be authenticated, for a duration of 1ms. In addition, the RFF enhancement technique depicted in the previous section is also used. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 33 | 74 While more details are available in D4.4, the confusion matrix for this experimentation is available in Figure 20. To note, in this section the device numbering is different, Device 1 corresponds to the USRP B210 while Device 2 and Device 3 are two different USRP B205 mini-i SDRs. Results demonstrates that it is possible to identify with 100% accuracy Device 1, 99% accuracy for Device 2 and 88% accuracy for Device 3. Meaning that differentiating between devices of different models from the same manufacturer leads to 100% accuracy while differentiating the same devices model results in slightly lower accuracy and this is expected. It means that by applying the RF Fingerprint concepts developed in COREnext, it is possible to identify devices from the same manufacturer with more than 80% accuracy – one of the KPI from WP6. Figure 20: Confusion matrix for 3 transmitters from the same manufacturer - Device 1 is a USRP B210, Devices 2 and 3 are two distinct USRP B205 mini-i. 3.8 Additional Concepts around RFF for PLS During the work in WP5, additional challenges were also identified, when it comes to the RF Fingerprinting authentication process, which fuelled the development of additional concepts. In this section an overview of two methods enhancing classical RF Fingerprint authentication mechanisms is shown. In a first solution, being the object of a patent application [31], active RF Fingerprinting is used to strengthen the robustness of RFF authentication methods against impersonation attacks, in which an attacker tries to break the authentication by mimicking a legitimate device. As an example, UE transmission parameters are imposed by the base station to create a challenge response method. In this way, the BS can request additional challenges if necessary, using different transmission parameters. Authentication robustness is increased as it is very unlikely that an attacker can intercept and mimic in real time the requested transmission parameters and their unique RF fingerprint implications. See Figure 21 for an illustration of the method, issued from the patent application material. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 34 | 74 Figure 21: Flowchart from one of the processes issued from [31] In another additional concept, we explore the use of RF Fingerprinting based authentication for UEs containing multiple transmitters. Indeed, in the RFF technical field, the focus has mostly been oriented towards identifying and authenticating a UE composed of a single radio transmitter with the help of a single receiver device. However, many UEs are composed of multiple radio transceivers and for example, a modern smartphone doesn’t rely on just one transmitter. In addition to the main 5G New Radio (NR) transmitter, it also includes one or more transmitters for 4G LTE, Wi-Fi, Bluetooth, etc. To identify such a UE with multiple transmitters, it is then possible to perform RFF not only for one but for multiple transmitters within the UE, potentially by using multiple network nodes. This is strengthening the authentication methods as an attacker will then need to mimic multiple transmitter hardware and associated impairments to break the authentication and impersonate such a UE. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 35 | 74 3.9 Future Research Directions While the results achieved with the concepts developed in COREnext are paving the way to strengthen physical layer security of the RAN, several challenges have been identified, which would require more research to be tackled. One of them is about transmissions over the air. To develop the concepts and fully focus on developing RFF techniques and maximize MLA accuracy a wired radio link has been used. When porting these concepts to wireless radio links the effect of the environment will have to be considered. While it is strongly believed that channel cancelation mechanisms in base stations will be able to remove most of the channel effects, more research is required to adapt the developed concepts to this scenario. Another point is about the temperature of operation. To understand the effect of temperature on the RFF MLA an experiment was performed, using the same 5G NR signals that is described in the previous sections. This time, the transmitters are placed in a temperature-controlled enclosure (see Figure 22). Figure 22: Lab setup for temperature analysis experiment The MLA has been trained on the same data as previously, at room temperature, when multiple datasets at maximum output power are created, the SDRs are becoming warm due to thermal dissipation, mainly in the embedded Power Amplifier. However, inference has been done using a new data issued from the temperature chamber measurements and some datasets have been created in a way that the SDRs are not getting warm (self-heating has a small effect). While using the same RFF techniques than described in the previous sections, it can be seen in Figure 23that the accuracy is maximized around room temperature and over (more than 85% accuracy between 25°C to 40°C). However, when temperature for inference is dropping below 20°C, the accuracy drops to 50% which is the random guess accuracy. These results highlight the importance of domain consistency between training and inference, and this opens the way to new research on how to tackle temperature induced challenges. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 36 | 74 Figure 23: Inference classification accuracy versus temperature. Training done at room temperature. Finally, another area for future research is to apply the RFF concepts to “open set scenario”, in which unknown devices not seen during training are trying to connect to a network and this is particularly relevant for threat detection and mitigation. More details are available in D4.4 when it comes to this scenario. 3.10 Conclusions In WP5 we developed concepts around the use of RF Fingerprinting for physical layer security of the radio access network, particularly well-suited for private networks. For this purpose, we developed a custom-made hardware experimentation platform and used 5G NR signals. In this context we introduced the concept of active RF fingerprinting, in which transmitters are requested to send specific signals using specific characteristics to ensure domain consistency and maximizing RF Fingerprint ML algorithm accuracy. To further enhance the ML performance as well as reducing footprint, we also introduced the concept of impairment enhancement waveform. These techniques have been used in a first step towards validation and show more than 80% accuracy for the identification of devices from the same model from the same manufacturer, validations activities will be taking place in WP6. We also introduced additional concepts issued from the work in COREnext. Finally, we concluded with highlighting research directions for future work, some of them we might explore in WP6 for additional validation. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 37 | 74 4 Receiver Architecture to Extract Fingerprint from Base Station The first objective of this section is to explore practical options for a User Receiver Device (User Equipment in 3GPP terms) to identify a legitimate Macro or Micro-cell Base Sation by means of Fingerprinting in Down-Link. This section starts with describing the different architectures of a Legitimate Base Station and a possible Fake Base Station, along with their intrinsic or expected impairments on quality of the transmitted signals. Such impairments are the essentials feeding any Fingerprinting algorithm. We then look at signal degradations that come from Over-The-Air (OTA) transmission between transmitting Base Sation (BS) and Receiving User Equipment (UE) that may complicate or even prevent from proper identification by Fingerprinting. Next, we zoom in on the Receiving device, identifying how and what type of signals can effectively be retrieved as input to the Fingerprinting identification algorithm. As final step, we look at methods that can be used to capture real data as received by the Receiver. We will end this section by deriving the conclusions. 4.1 Architecture and Requirements of Analog FrontEnd of Base Station In the frequency bands up to 10GHz, two main architectures of Base Stations are widely being employed. The first one is optimized for covering a wide area in rural areas with low density of users, called Marco Cell. The Cell size can extend beyond 30 kilometres. Those stations transmit a high-power beam spreading over only a small vertical angle and typically covering an azimuth (horizontal coverage) of 120 degrees per antenna unit. Three segments are typically employed to cover the full 360 degrees horizon. The transmit amplifiers (one per polarization per segment of 120 degrees) are optimized to deliver high power at optimum efficiency while the beam shaping (mainly focusing over elevation as users are confined at the horizon) is fully achieved in a passive antenna structure. The second one is optimized for covering medium range in Urban areas with high density of users, called Micro Cell. The cell size is typically up to 2 kilometres. Those stations transmit and receive multiple beams per segment, that can be steered independently by having multiple channels driving a full 2D array of antenna elements. Often, the number of channels is 32 or 64. A beam in a certain direction is created by having all the channels driving the same radio signal but each individually phase-adjusted such that the radiated wave adds constructively in the desired beam direction. The capability to transmit or receive multiple beams at the same time is often referred to as massive Multiple Input Multiple Output or mMIMO. More information and mathematics on beamforming can be found in section 5.1.2. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 38 | 74 The relevance for Fingerprinting is that, unlike in Macro-cells, in Micro-cells the user device will receive the mathematical sum of many channels at the same time, such that individual deviations or impairments from the channels will be averaged out. The figures below show the simplified block diagrams of the analogue front ends for both a Macrocell and Micro-cell Base Station. The Macro-cell will contain only a single channel per segment per polarization (Horizontal or Vertical polarization). Figure 24: Simplified block diagram of transmitting Macro-cell Base Sation and 2 receiving User Devices. Figure 25: Simplified block diagram of transmitting Micro-cell Base Sation and 2 receiving User Devices. The Inverse Fast Fourier Transform block (IFFT) is the signal transformation that computes the OFDM waveform from the QAM constellations of the individual symbols that in turn represent the D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 39 | 74 bits to be transmitted. The Cyclic Prefix (CP) block extends each OFDM symbol for robustness in presence of reflections. The Beamformer (BF) is present only in the Micro-cell Base Sation and splits each OFDM signal into multiple signals for the individual channels, each with a dedicated phase offset, such that each OFDM signal is transmitted into the desired direction. The Carrier Aggregation (CA) may aggregate multiple OFDM modulated signals that each cover only a fraction of the bandwidth (for example 20MHz or 100MHz each) into a single composite signal with a larger total bandwidth (for example covering a total of 400MHz). The Crest Factor Reduction (CFR) manipulates the composite OFDM signal to suppress the highest signal peaks (in a graceful way) as those would cause excessive distortions in the PAM or enforce to operate the Power Amplifier Module (PAM) in deeper back-off, hence result in lower power efficiency. In case of Micro-Cell or mMIMO Base Station, the IFFT is complemented by a Beamforming block, that adjusts the phases of individual signals to the channels to direct the signals from the antenna array into specific directions. The Power Amplifier Module (PAM) is the actual RF Power Amplifier and is optimized to achieve a high power-efficiency. Typical figures are around 50%. Per today, the standard amplifier topology for both types of Base Station is Doherty [27], that brings the required efficiency but suffers from quite severe signal distortions. Without any further precautions, Fingerprinting based on unique distortion patterns would be relatively easy, but the distortions would pollute the transmitted radio spectrum well beyond the legitimate FCC level of -13dBm/MHz and also increase the Bit Error Rate for the higher constellations in advanced OFDM modulation schemes of for example 64QAM and 256QAM. This is of course not acceptable. As mitigation, the Digital Pre-Distortion (DPD) blocks are employed to pre-distort the signal to each PAM such that the distortion produced by the PAM is to a large extend suppressed. Suppression factors can be in the order of 30dB. In order to make this work, the output signal of each PAM is monitored by the DPD block in a feedback loop: the DPD block compares the PAM output waveform with the undistorted waveform and calculates what corrections are required. Due to complexity of DPD, this processing is fully done in the digital domain. The RF Digital-to-Analog Converter (RFDAC) that sits between the DPD and PAM serves two functions: it converts the digital to an analogue signal, and it converts the base-band signal to the desired transmit RF frequency. In the past, this last step of frequency conversion was done in subsequent analogue mixer blocks that could suffer from specific signal impairments but state-ofthe-art RFDACs have resolved most of those artifacts (again making Base Station identification based on fingerprinting more difficult). Finaly, behind the PAM, we find a band-pass filter that cleans the transmitted RF spectrum at frequencies further from the RF operating band where DPD is no longer effective. In order to prevent Base Stations of neighbouring cells from interfering with each other or other radio services (like satellite communications, earth observations, etc.) and in order to optimize datathroughput, Base Stations have to meet strict performance figures. The ones most relevant in the context of Fingerprinting are: • Maximum of Total Radiated Power outside operating band: -13dBm/MHz • Maximum Error Vector Magnitude: 3.5% (for 256QAM) D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 40 | 74 As Base Stations (both Micro and Macro) typically radiate a total power of few hundred Watts, to keep distortion products and noise below the -13dBm/MHz with some margin, the first requirement translates into high requirements for linearity, refer to the table with some typical figures below. Table 4-1: limit to Adjacent Channel Power Ratio (ACPR) imposed by FCC out-of-band limit of - 13dBm/MHz. Because of the stringent linearity requirements on linearity, one may think that the second requirement on maximum Error Vector Magnitude (EVM) is automatically met. This is not fully true because the CFR algorithm typically sacrifices the accuracy of the IQ vectors (refer to Figure 28). In addition, IQ imbalance and in-band spurious from for example Local oscillator (LO) pollutions may be present without any impact on out-of-band distortion. Although with state-of-the-art selfcalibrating RFDACs those effects will be small. It should also be noted that a more advanced DPD algorithm would be capable of at least compensating the IQ imbalance (refer to example in Figure 30). The first key message is that legitimate Base Stations will transmit signals of high quality without significant levels of distortion that could facilitate Fingerprinting. The second key message is that unlike Macro-cell, in Micro-cell Base Stations many parallel analogue front-ends contribute to the same radiated beam or signal, such that effects from production spread average out to even lower and presumably undetectable levels in discriminating between different Fingerprints. 4.2 Typical Architecture of Fake Base Station (Software Defined Radio) A legitimate high-power Base Station as described above requires a complex and expensive hardware platform that is unlikely to be available for a hacker. Therefore, it is relevant to consider the characteristics and possible source of signal impairments of a lower cost platform, that is more likely to be used as Fake Base Sation. By restricting the number of channels, limiting the modulation bandwidth and omitting features like Digital-Pre-Distortion, the remaining digital processing may easily be done in software, for example on a laptop (using open-source Software-Defined Radio or SDR). Still, a bit more dedicated RF Analog Front End (AFE) is required to generate actual RF signals. The diagrams below show two typical examples of such an AFE. In the first example, two low-cost Unit Limit on out-of band (on TRP) dBm/MHz -13 Total radiated power 320 ACPR margin dB 3 Distortion-2-Noise ratio (in power) 1 Modulated or occupied bandwidth MHz 20 100 200 400 Modulated Power/MHz dBm/MHz 42.04 35.05 32.04 29.03 ACPR limit dBc 55.04 48.05 45.04 42.03 ACPR with margin dBc 58.04 51.05 48.04 45.03 ACPR from Noise dBc 61.05 54.06 51.05 48.04 ACPR from distortion (after DPD) dBc 61.05 54.06 51.05 48.04 D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 41 | 74 Digital-to-Analog Converters (DACs) convert just base-band I and Q signals rather than a direct RF wave. Unlike RF signals, base-band signals require DACs that run on a low sample rate, several tens of MHz are sufficient. The conversion to the actual RF frequency is done using two simple analogue mixer stages, a summation circuit and some Low Pass Filters (LPF) and Band Pass Filters (BPF). The analogue mixers in such a device will add impairments like IQ imbalance and LO leakage that may be discovered relatively easy by a proper Fingerprinting recognition. The Power Amplifier Module (PAM) is typically rated at low power in the range of 20-30dBm, comparable to what is used as transmitter power in handsets. And there will be no Digital PreDistortion (DPD) to compensate for its non-linearities. The remaining non-linearity may be relatively easy detectable by a proper Fingerprinting algorithm. In the second example, most of the blocks are the same. Except that the Digital-to-Analog Converter (DAC) converts a true RF signal at a relatively low Intermediate Frequency (possibly between 30 and 500MHz). Analog mixers and filters are still required to convert the analogue radio signal from the IF to the target RF frequency, but this topology resolves some of the IQ imbalance issues. As a draw-back, imperfections in the analogue mixers will the produce an image of the wanted signal somewhere else in the frequency spectrum. Note that in both concepts the RF operating frequency can relatively easily be moved to any desired frequency by just changing the LO frequency (and likely using different PAM), which makes the platform flexible for operating at arbitrary bands. This is also why a typical handset (User Equipment) will use very similar topologies for their transmitter. Figure 26: Simplified block diagrams of possible Fake Base Sation. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 48 | 74 Since the received signal strength can vary over a large range as function of the link range and both mixer stages and ADC have limited Dynamic Range (inability to handle both small and large signals at the same time), the gain control around the LNA is an essential feature. After digitization by the ADC, the signal is bandpass filtered to cover exactly the bandwidth of the transmitted and wanted signal (the channel bandwidth of for example 20MHz or 100MHz) and remove any disturbing signals from neighbouring channels. Note that distortion spectra produced by the transmitter outside the modulation or channel bandwidth are also being removed, refer to examples Figure 27. After filtering, they are no longer available for Fingerprinting. Figure 34: Example Architecture of a receiver capable of identifying RF Fingerprint. The filtered signal is then demodulated by the Fast Fourier Transform (FFT), that provides the phases and amplitudes of each OFDM frequency component (so-called subcarrier). After cancelling the phase and amplitude shifts caused by OTA channel effects by the Equalizer, the IQ constellations of all symbols are available. They will still look bit like noisy dots due to presence of noise, but if the SNR is high enough, the de-mapping still succeeds to determine the correct mapping to the bits carried by the individual subcarriers of each symbol. The blocks below the dotted line are not part of a standard receiver but may be added for the sake of Fingerprinting as will be discussed bit further down. The first possible hook for grabbing data for the Fingerprinting algorithm is raw data from the ADC output. In various publications, plain raw IQ is regularly taken as input for Fingerprinting, while emphasis is then on further AI processing [23]. Yet, as we will see, there are other options for grabbing IQ data that make the process of Fingerprinting more effective and simpler. As the ADC typically operates in over-sampled mode, out-of-band data is readily available for analyses. But, since the out-of-band spectrum is more than likely dominated by receiver noise or unpredictable and uncorrelated sources from for example another cell, this signal is expected to be of little use. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 49 | 74 The second possible hook is after the channel filter. There will still be the same receiver noise, but the signal contents will highly correlate with the signal transmitted by the selected Base Station. One may for example be able to detect poor IQ balance from a Fake Base Station (FBS) (refer to example in Figure 30) or Complementary Cumulative Distribution Function (CCDF) of the received signal (refer to Figure 28). But note that the CCDF will be heavily affected in case of OTA-multipath! This effect was discussed in section 4.4. The third and most promising hook would involve some additional processing on both the equalized FFT (representing the best estimate of the distorted transmitted signal with cancellation of additional channel effects like those caused by multi-path OTA) and the de-mapped IQ symbols, representing the best estimate of how an undistorted signal would look like. By recoding both those signals via same IFFT as in the transmitter into an OFDM signal in the time-domain, from the error signal, one can get the best estimate of distortions produced by the transmitter. Data-dependency is largely removed. The estimated distortion will still be very low for a legitimate Base Station, but likely High for a Fake Base Station. The Fingerprinting algorithm is assumed to take both signals as feature inputs and find the best way to combine both signals for most reliable classification of different Base Stations. Alternatively, the concept of remodulation will work equally well for a BS reading the Fingerprint produced by a UE (in the uplink). Results from experiments by NXP using this architecture will be reported in WP6. 4.6 Capture of Transmit Signals from Base Station Analog Front-end or Full Transmit Chains This section describes how signals have been/ can be captured from a full line-up from transmitting Base Sation to Receiving User Device, with either simulations of PAMs that are still in design or measurements on PAMs that have been manufactured. Captured signals may be used in WP4 for digital component development and will be used in WP6.1 for validation. During design phase, the circuit of the PAM can be simulated. Typically, this is done using the tools from Keysight ADS (mostly used for bit more compact designs) or Cadence Virtuoso (mostly used for more advanced complex designs). Either way, those simulations come with some restrictions: • The models used in the simulation have limited accuracy, in particular when 3D RF structures (like bond wires or PCB vias), charge trapping or dynamic thermal effects are involved • Compute power is generally not sufficient to accurately simulate the behaviour with true OFDM-modulated signals The method followed is depicted in the figure below: As first step, the simulation is done using complex (IQ) signals in either the time or the frequency domain that are the one hand driving the PAMs into its various corners, but on the other hand do D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 50 | 74 not result into excessive compute times. Variations of the PAM, caused by spread of components, can be accommodated by generating multiple PAM models. As second step, by means of fitting techniques, a mathematical time-discrete model of the amplifier is created. Some basic examples of models were already described in D5.1 section 3.2.3, but in order to properly capture the behaviour of a wide-band PA (with for example 100 or 400MHz modulation bandwidth) at ACPR levels as low as -50dBc, we concluded that the static AMAM and AMPM models need to be extended with memory effects, using for example Volterra series or advanced Memory Polynomials. Those models capture that the amplifier output does not only depend on its momentary input signal, but also on data that it received a bit earlier. As an example, think of a short peak in the OFDM modulated signal, that can temporarily reduce the supply voltage and so affect the amplifier output signal until the supply voltage has had time to get restored. As third step, the mathematical model of the PAM is used in a system simulator (running in for example MATLAB or Python) that generates true modulated signals and complements the PAM line-up with for example DAC imperfections, IQ imbalance, Digital Predistortion (DPD), filters, Channel Noise, Channel filtering and Receiving Device. Such a system model simulates in just minutes while the set-up can easily be changed. So, many experiments can be done in quick turnaround time. Note that in order to explore the effectiveness of Fingerprinting in a full system, relatively simple models can be used for the transmission channel or receiver. Refer for example to Figure 31 that shows the impact of multi-path channel. Another example is adding thermal receiver noise as shown in Figure 32. Figure 35: Method to derive a mathematic model of a PAM from circuit simulation and run the PAM model in a system simulation. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 51 | 74 When we have a physical PAM/AFE/Full line-up available for measurement, two different methods can be applied. In the first (direct) method, we run just modulated OFDM signals through the PAM/AFE and capture the output data. This may look like an obvious method, but the disadvantage is that such measurements are in practice complicated to execute them accurately and repeatable. For example, temperature needs to be accurately controlled and de-embedding the effects from cables, attenuators, connectors, couplers are highly critical. In addition, multiple pieces of equipment need to be properly configured and synchronized. This makes the direct method less suitable for running many different scenarios (power-levels, modulation types, different imperfects, channel conditions). Figure 36: Direct measurement in full physical system. In the second indirect method, we only measure the PAM with OFDM modulated signals in step one and then extract its mathematical model in step two in the same way as we did for a simulated PAM. The third step is the simulation of the PAM/AFE in the whole system. This indirect method offers the same advantages of flexibility and speed as with a simulated PAM, but now obviously with a more representative PAM. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 52 | 74 Figure 37: Method to derive a mathematic model of a PAM from circuit measurement and run the PAM/full AFE model in a system simulation. As an experiment to verify the approach and get some realistic data, NXP measured 6 manufactured Base Station PAMs. It takes many parameters to accurately characterize each of them, but the simplest ones are the static AMAM (Amplitude to Amplitude Modulation) and AMPM (Amplitude-to Phase Modulation) curves as shown below. Figure 38: Example of AMAM and AMPM distortions from 6 measured PAMs In particular on the AMAM curves, differences can be observed to be in the order of 1dB. This may seem large enough for identifying Base Stations based on Fingerprint, but as stated earlier, DPD is quite capable of eliminating those deviations. In Micro-Cell Base Stations, as explained in section D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 53 | 74 4.1, there is an additional effect that the signals from for example 32 or 64 PAMs blend together in beamforming, further eliminating observable deviations. 4.7 Conclusions Using advanced Digital-Pre-Distortion and high-performance RF Digital-to-Analog Converters, Base Stations are doing a good job in delivering a clean transmit signal in which most circuit-related imperfections fall well below the Receiver Noise Level and Fingerprint detection limit. As consequence, it is expected that Base Stations can hardly be uniquely identified. Possibly the CCDF of legitimate Base Stations can still be discriminatory per model or brand, just because the CCDF is not determined by hardware imperfections (those will be suppressed by DPD) but rather by the relatively complex digital algorithm required for Crest-Factor Reduction (CFR). Yet, a relatively low-cost Fake Base Station is expected to be much more easily discovered as those are unlikely to contain all the advanced and expensive provisions to deliver a clean signal. At the Receiver end, multiple options have been explored for capturing IQ data that can be used for to feed the Fingerprinting algorithm. Complementing the received signal from after the receiver equalization (using the Channel State Information) with remodulation of the decoded symbols (providing the estimate of the undistorted IQ time signal) makes the method resilient against multipath OTA effects and removes data-dependency. Although not the first the objective of this study, since User Equipment (UE, a mobile phone) transmit channel shows a high commonality with Fake Base Station architecture as discussed here, this study also provides some hints how a Base Sation could Identify a transmitting User device (UE). The proposed architecture is expected to work equally well for passive and active Fingerprint as proposed in chapter 3. Further validation will be handled in WP6. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 54 | 74 5 Sub-THz Beamforming for HighThroughput and Secure Radio Links In this section, we will first analyse the robustness of the beamforming to RF non-idealities and quantify the performance degradation. This is particularly important to set the HW requirement towards high-throughput and reliable sub-THz (110-170GHz) communication links. Secondly, we will focus on the design of beamforming to maintain high performance at the regular receivers while at the same time degrading performance of potential EVDs. 5.1 Sensitivity Analysis and (sub) THz Link Robustness to RF HW Nonidealities 5.1.1 Introduction Sub-THz bands can offer a high bandwidth in the order of multiple GHz to support highthroughput requirements in 6G and beyond. However, RF HW non-idealities can significantly degrade the end-to-end performance of a sub-THz communication system. It is essential to analyse such sensitivity, which is crucial for reliable and secure sub-THz links. In this section, we will provide a sensitivity analysis of a downlink sub-THz link to essential hardware (HW) impairments for different use cases. The performance analysis combines semi-analytical derivations as well as end-to-end simulations using the link-level simulator developed in WP5. This is particularly crucial to set the requirements on the RF non-idealities to better control the end-to-end sub-THz performance. We will focus in this section on two main different non-idealities: namely the beamforming (BF) inaccuracies and the power amplifier (PA) distortions. 5.1.2 Analog Beamforming Inaccuracies 5.1.2.1 System Modelling Analog BF (ABF) is in fact in the core of sub-THz communication. Any BF inaccuracies will result in a beam-misalignment that can significantly degrade the performance. The latter essentially depends on the RF architecture including the number of transmit and receive antennas that respectively determine the transmit (TX) and receive (RX) beamwidth. We propose to (semi)- analytically and by simulations, assess the end-to-end performance in terms of signal-tointerference plus noise ratio (SINR) and uncoded/coded bit error ratio (BER). We further explore the different design trade-offs subjected to different stochastic distributions of the TX and RX BF errors, as well different ABF architectures namely partially and fully connected architectures. We consider a downlink multiuser MIMO system with 𝐾 active users and single access point or a base Station (BS) with 𝐾 RF chains (RFC)s beamforming data from 𝑁!" antennas. Each user equipment (UE) consists of a single RFC chain connected to 𝑁#" antennas for receive ABF. We consider the generic multipath channel model from D5.1 that consists of a line-of-sight (LOS) and 𝐿 non-LOS (NLOS) components as D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 55 | 74 In this analysis we consider an orthogonal frequency division multiplexing modulation (OFDM). For the sake of clarity, the subcarrier index will be removed in the following derivations. It can be shown that received signal after receive ABF can be expanded as where 𝐇$,&,&! is the effective analogue channel resulting from the TX and RX ABF and the physical propagation channel, and where 𝐰!",& and 𝐰#",& are the TX and RX ABF that respectively depend on the TX 𝜙 K!",&,and RX 𝜙 K#",&,BF angles. The signal to noise plus interference ratio can be modelled accordingly as The TX (𝐰!",&) and RX (𝐰#",&),,BF depend on the analogue state information that can be generally modelled as The phase errors 𝜙 L!",& and 𝜙 L#",& are used to model the BF errors which can be static errors or uniformly distributed as 𝑈(0, 𝜙 L'(),) for zero-mean and uniformly-distributed errors in [−𝜙 L'(), 𝜙 L'()]. 5.1.2.2 Single User Performance We analyse in this section the required TX and RX BF accuracies in a single user scenario. We consider static errors both at the TX and RX side, a unit-power LOS propagation channel, Uniform linear array with antenna spacing *+ ,= 0.5, 𝑁#" = 8 receive antennas and different TX antennas 𝑁!" = 4,8,16. The AoD and AoA are respectively fixed to 𝜙-./,!" =30° and 𝜙-./,#" =0° . Irrespective of the BF error range 𝜙 L, the BF angle 𝜙 K is always bounded in [− 0 1, + 0 1]. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 56 | 74 Figure 39: The received energy for a transmit and receive BF errors that are uniformly distributed ~𝑈(0, 𝜙 '!",$%&() and ~𝑈(0, 𝜙 ''",$%&(), 𝑁!" =16, 𝑁'" = 8 . In Figure 39 we show the cumulative distribution function (CDF) of the received energy for a system with 𝑁!" =16 and TX and RX BF errors that are respectively uniformly distributed ~𝑈(0, 𝜙 L!",'(),) and ~𝑈(0, 𝜙 L#",'(),). It can be realized that transmit ABF inaccuracies dominate the performance compared to receive ABF inaccuracies which is expected because NTX =2*NRX. Figure 40: BER performance of a 64 -QAM modulation resulting from TX and RX BF errors (~𝑈(0, 𝜙 '$%&() for 𝑁!" =16 and 𝑁'" = 8. Figure 40 depicts the end-to-end BER performance for the𝑁!" =16 and different TX and RX BF errors uniformly distributed. We also include a semi-analytical BER performance in which we combine the distribution of the SINR 𝛾 and the approximate symbol error probability (SER) probability as where the SER is given by D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 57 | 74 First of all, the analytical performance does match the simulations. Besides the worst performance occurs at combined TX and RX BF errors. The one-sided errors with 𝜙 L!",'() =5° and 𝜙 L#",'() = 10° result in 4dB performance loss while the combined errors result in an additional 4dB performance loss. Figure 41: Required BF accuracy for a target maximum SNR loss 𝛾()** = 1dB at a target uncoded 𝐵𝐸𝑅 = 10+, of a 64 -QAM modulation. The transmit and receive BF errors are either static (left-hand side figure) or uniformly distributed (right-hand side figure). 𝑁!" = 2,4,8,16 and 𝑁'" = 8. We further analyse in Figure 41 the transmit and receive BF accuracy trade-offs for a maximum transmit signal to noise ratio (𝐸//𝑁2),loss 𝛾3455 = 1dB at a target uncoded 𝐵𝐸𝑅 =1067 of a 64 - QAM modulation. The transmit and receive BF errors are either static (see left-hand side figure) or uniformly distributed (see right-hand side figure). The figure indicates that the RX BF accuracy depends on the TX BF accuracy and the number of transmit antennas 𝑁!". At increasing number of 𝑁!", tight requirements on both the TX and RX beamforming accuracies are required. For instance Figure 41 suggests that with static TX error 𝜙, Q!" = −4°, the required maximum RX errors 𝜙, Q#" must be in the range [−4°,4°], [−1.5°, 1.5°] for respectively 𝑁!"=4 and 8. However with 𝑁!"=16, the SNR loss is higher than 1dB even with zero RX BF errors. For the uniformly distributed errors in the right-hand side of the same figure, at TX uniform errors with 𝜙 L!",'() = 3(°), the required RX errors correspond to ≤ 𝜙 L#",'() = 6(°) and 3(°) for respectively NTX=8 and 16, while the loss is higher than 1dB for NTX=16. Therefore, stringent BF accuracies are required at increasing number of TX antennas. 5.1.2.3 Multiuser Performance In this section we extend the analysis to multiuser MIMO downlink transmission and consider two BF architectures namely Partially connected architecture (PCA) and fully connected architecture (FCA). We consider a setup of 𝐾 users with AoD equally spaced in a sector as f TX,k = -60 + é 120/(K1) û ·k. The AoA is fixed to 𝜙#",& =0° . We focus next on the transmit ABF state information assuming a uniform TX BF errors and perfect RX BF state information. The system is equipped with 𝑁!" =64 and 𝑁#" = 8. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 64 | 74 Figure 51: Required 𝐸0/𝑁/ at target coded BER=10+2 for different PA models with AM-PM distortions assuming 64-QAM constellation in a LOS propagation channel. In Figure 50 and Figure 51 we show for different PBOs respectively the coded BER versus 𝐸B/𝑁2 and the required 𝐸B/𝑁2 for target coded BER=106C for different PA models. The simulation results reveal the ability of the FEC to reduce the PA distortion effect as well as the performance spread among different PA models as opposed to the uncoded transmission. First of all, the PA models with AM-AM and AM-PM distortion equally perform for PBO≥ 5dB within less than 1dB performance tolerance. Besides the PBO range to achieve the target BER is relatively more relaxed than its uncoded counterpart in Figure 49. Also, the performance gap towards the best PA (cubic model) is further reduced. 5.1.4 Conclusions We have shown that when analysing the impact of RF HW impairments namely beamforming inaccuracies as well PA distortions, it is important to consider end-to-end communication link with all building blocks including protection mechanisms such FEC. For instance, when setting the specifications on the BF accuracy, limiting the analysis to EVM, SINR, or even uncoded BER does not provide the fully and accurate picture on the required BF accuracies. Simulation results indicate that with high number antennas, beam alignment achieving sub-degree BF accuracy is required. In the same way, considering more realistic end-to-end performance with FEC, simulation revealed that all considered PA models yield roughly the same performance within 1dB SNR tolerance at least for the simulated setup. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 65 | 74 5.2 Towards Robust (sub) THz Beamforming Against Eavesdropper Attacks Figure 52: Communication link with beam leakage to eavesdropper 5.2.1 System Model We consider a sub-THz MIMO wireless communication system consisting of transmitter beamforming data from 𝑁!" transmit antennas to a UE with,𝑁#" receive antennas as described in the sensitivity analysis section. We further assume the transmitter equipped with one additional RFC used to beamform artificial noise (AN) to protect the communication against eavesdropper (EVD) attempting to decode communication data as depicted in Figure 52. In the same way, EVD is assumed to own a single RFC connected to 𝑁8 antennas used for receive beamforming. The transmitter respectively beamforms data symbols {𝑑} selected from M-QAM constellation and an AN assumed to be white Gaussian noise that is zero-mean and unit variance i.e. 𝑑],~ℵ(0,1). The received signal can be expressed at the UE as and at EVD as where 𝐰𝐓𝐗 (resp. , 𝐰 _𝑻𝑿), H (resp. ,𝐇 _), 𝐰𝐑𝐗 (resp. 𝐰 _𝑹𝑿) are the transmit beamforming relative to the UE (resp. AN), the downlink channel of the UE (resp. EVD), and the receive beamforming relative to the UE (resp. EVD). There is also a power control step for the data and the AN through the multiplicative scalars 𝜂 and 𝜂]. The transmit beamforming depends on an optimized beamforming angle as 𝐰𝐓𝐗 = 𝒇(𝜙) and 𝐰 _𝑻𝑿 = 𝒇 b(𝜙 b). The SINRs can be respectively formulated for the UE and EVD as D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 66 | 74 that are function of the transmit beamforming angles (𝜙, 𝜙 b) of the data and the AN. To improve the communication link security, we propose an optimization framework in which the SINR of the user is maximized subject to an upper bound 𝜒/ on the EVD beamforming gain (BFG) as By lowering the target upper bound 𝛾]/, the link trustworthy can be improved. In other words, lower 𝛾]/, will result in high BER when the EVD tries to decode the user information bits. 5.2.2 Performance Analysis Figure 53: The received energy (BFG) at the regular UE with AoD 𝜙!" =0° and at EVD with 𝜙 9!" ∈ [−60°,60°] and for different numbers of transmit antennas 𝑁!". The beamforming is aligned with AoDs and the relative AN power 𝜂?/𝜂 = 0. In Figure 53 we show the received energy 𝐸#" (beamforming gain) at the regular UE with AoD 𝜙!" =0° and at EVD with 𝜙 b!" ∈[−60°,60°] and for different numbers of transmit antennas 𝑁!". D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 67 | 74 In this figure the BF is not optimized and is aligned with the AoDs of the UE and EVD. First of all, for a given number of transmit antennas, the link security increases for sufficient angular separation between the UE and EVD ΔJ,J K= 𝜙 b− 𝜙 in particular in massive MIMO. In other words, increasing 𝑁!" results in reduced side lobes and higher spatial resolution thanks to the reduced main beamwidth e.g. see for instance the curves with 𝑁!" =16 and 64. Figure 54: The SINR in the high SNR regime (-! ." =50dB) at the UE with AoD 𝜙!" =0° and at EVD with 𝜙 9!" ∈[−60°,60°] and for different numbers of transmit antennas 𝑁!". The beamforming is aligned with AoDs the relative AN power 𝜂?/𝜂 = 0. With limited angular separation around the boresight (𝜙!" =0°), Figure 53 indicates high security threat as the beamforming gain (BFG) at EVD can be only few dBs below the highest BFG (=1). This is further highlighted in Figure 54 where the SINR at the UE (i.e. 𝛾(𝜙, 𝜙 b, 𝜂])) and EVD (i.e. 𝛾](𝜙, 𝜙 b, 𝜂])) are depicted in the high SNR regime 8" 9# =50dB. A high SINR at EVD means he can safely decode the data hence jeopardizing the link trustworthy. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 68 | 74 Figure 55: The SINR in the high SNR regime (-! ." =50dB) at the UE with AoD 𝜙!" =0° and at EVD with 𝜙 9!" ∈[−60°,60°] and for 𝑁!" =64. The beamforming is aligned with AoDs the AN relative power is 𝜂L M= 1% (left-hand side) and 10% (right-hand side). Figure 56: The SINR in a moderate SNR regime (-! ." =20dB) at the UE with AoD 𝜙!" =0° and at EVD with 𝜙 9!" ∈[−60°,60°] and for 𝑁!" =64. The beamforming is aligned with AoDs the relative AN power 𝜂L M=1%. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 69 | 74 To improve the trustworthiness against EVD attacks, one can use the AN to jam the EVD link. This is shown in Figure 55 where we analyse the impact the relative AN power 𝜂]/𝜂 on the SINR performance for 𝑁!" =64. The figures with 𝜂]/𝜂 =1% and 10% indicate that adding a limited amount of AN beamformed towards EVD can significantly degrade the EVD performance with some side effects on the regular users especially in the strongly overlapping region. Such sensitivity to AN is less severe in practice as wireless communication systems do not operate in a very high SNR regime. To stress this aspect, we show in Figure 56 the resulting SINR at medium SNR regime 8" 9# =20dB. As a matter of a fact 1% relative AN power has limited degradation of the UE SINR compared to the performance in the high SNR regime shown in Figure 55. In the previous figures the BF was aligned with the AoD and was not exploited to increase the security robustness. Following the optimization in the problem (P1), we present next simulation results exploiting the optimization of the BF as an extra degree of freedom on top of the AN. Figure 57: The received energy (beamforming gain) at the UE (left-hand side) with AoD 𝜙!" =0° and at EVD (right-hand side) with 𝜙 9!" ∈[−60°,60°] and for 𝑁!" =64. The beamforming is optimized for different target BFGs at EVD and the relative AN power 𝜂?/𝜂 = 0. In Figure 57 we show the BFG of the UE and EVD for the beamforming along LOS (non-optimized) and the optimized BF based on problem (P1) for different upper bounds 𝜒/. As discussed previously, the LOS-based beamforming yields the highest performance for the UE however the worst security performance especially for small ΔJ,J K. Optimizing the beamforming on the other hand improves the link trustworthy as the target bound 𝜒/ decreases with reduced performance loss of the regular UE. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 70 | 74 Figure 58: The SINR in a moderate SNR regime (-! ." =20dB) at the UE (left-hand side) with AoD 𝜙!" =0° and at EVD (right-hand side) with 𝜙 9!" ∈[−60°,60°] and for 𝑁!" =64. The beamforming is optimized for different target BFGs at EVD and the relative AN power 𝜂L M=1%. As a matter of fact, adding AN on top of the optimized BF can further degrade the SINR at EVD with limited if no degradation on the regular UE at moderate SNR regime as depicted in Figure 58. Figure 59: The SINR in a moderate SNR regime (-! ." =20dB) at the UE and EVD with random AoDs and for 𝑁!" =64 (left-hand side) and 𝑁!" =16 (right-hand side). The beamforming is optimized for different target BFGs at EVD and the relative AN power 𝜂L M= 0. In Figure 59 we further show the stochastic SINR distributions of the UE and EVD for AoDs that are randomly selected from a grid points in a sector i.e. 𝜙!", 𝜙 b!" ∈[−60°,60°]. The worst-case scenario from the security point of view corresponds to high outage probabilities of the EVD SINR. Firstly, without security bound the beamforming along the LOS can result in high EVD SINR especially with limited number of transmit antennas 𝑁!" as the 3dB beamwidth increases at D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 71 | 74 decreasing 𝑁!". For instance, with 𝑁!" =16, the 90% outage SINR is 15dB which is only 5dB below the operating ideal SNR. As the security bound decreases, the EVD SINR can be better controlled and traded off versus the UE SINR. For instance, for 𝜒/= −3 dB and 𝑁!" =16 (resp. 𝑁!" =64), the EVD SINR is below 0dB (resp. -5dB) resulting in rather very limited UE SINR degradation e.g. ≈ 0 dB (resp. ≈ 1dB) in 90% of the cases. 5.2.3 Conclusions From the above discussions, it can be concluded that combining the AN and the sub-THz BF optimization can increase the link robustness to EVD attacks with limited performance loss on the regular users. Overall, the performance depends on the RF architecture, especially the number of transmit antennas, that determine the beamwidth hence the critical overlapping region. However, the proposed technique requires, among other factors, additional hardware resources— namely, extra RF chains to beamform the artificial noise (AN). Nevertheless, considering that the system is not fully always loaded, idle RF chains can be opportunistically utilized for AN beamforming. Additionally, to optimize the beamforming, the eavesdropper (EVD) needs to be localized, a task that can potentially be performed by the sensing infrastructure, especially if integrated with the communication system, enabling joint communication and sensing. Furthermore, while the use of AN introduces a power penalty, numerical analysis in this report indicates that the overall impact is rather limited. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 72 | 74 6 Conclusions D5.2 has addressed three different concepts that can be used in improving trustworthiness of RAN networks. The concept described in Section 3 by EAB enhances the ML performance while reducing its footprint, by introducing the impairment enhancing waveform. User Equipment devices will be challenged to identify themselves by transmitting dedicated waveforms that more clearly expose the unique circuit non-idealities. These techniques have been used in a first step towards validation and show more than 80% accuracy for the identification of devices from the same model from the same manufacturer. A platform based on software-defined radio has been built for validation in WP6. Section 4 analysed architectures of legitimate Base Stations and fake Base Stations and revealed that based on circuit non-idealities and the traces they leave in the transmitted signal, Fake Base Stations are expected to be relatively easily distinguished from legitimate Base Stations. The study resulted in a proposed architecture of a receiver optimized for capturing signals to feed into a Fingerprinting algorithm. The study also defined a method to generate large amount of IQ data for validation in WP6. The digital components defined on WP4 will be the ‘working horses’ to execute the Machine Learning (ML) that takes the captured fingerprints according to one of the methods described and classify the transmitter as being a legitimate or malicious source. Section 5 provides a concept that can be activated once a non-legitimate Base Station or UE has been identified: By using beamforming and Artificial Noise, the SINR of the signal transmitted towards the Eavesdropper can be severely decreased, mitigating its malicious attempts, while the SINR to the legitimate receiver is hardly affected. The study also delivered a system-level simulation platform to be used for validation on this concept in WP6. D5.2 Refined Concepts for Trustworthy Radio Links Through HW Imperfections and Localization 73 | 74 7 References [1] Kaspersky, ICS CERT Landscape Report [2] B. Debaillie et al., "RF Self-Interference Reduction Techniques for Compact Full Duplex Radios," 2015 IEEE 81st Vehicular Technology Conference (VTC Spring), Glasgow, UK, 2015 [3] C. Elgaard et al., "Efficient Wideband mmW Transceiver Front End for 5G Base Stations in 22-nm FD-SOI CMOS," in IEEE Journal of Solid-State Circuits, vol. 59, no. 2, pp. 321-336, Feb. 2024, doi: 10.1109/JSSC.2023.3282696. [4] Anu Jagannath, Jithin Jagannath, Prem Sagar Pattanshetty Vasanth Kumar [2201.00680] A Comprehensive Survey on Radio Frequency (RF) Fingerprinting: Traditional Approaches, Deep Learning, and Open Challenges (arxiv.org) [5] Chen Y, Chen X, Lei Y. Emitter Identification of Digital Modulation Transmitter Based on Nonlinearity and Modulation Distortion of Power Amplifier. Sensors (Basel). 2021 Jun 25;21(13):4362. doi: 10.3390/s21134362. PMID: 34202361; PMCID: PMC8271810. [6] K. J. Ellis and N. Serinken, “Characteristics of radio transmitter fingerprints,” Radio Sci., vol. 36, no. 4, pp. 585–597, Jul. 2001, doi: 10.1029/2000RS002345. [7] https://se.mathworks.com/help/comm/ref/wirelesswaveformgenerator-app.html [8] https://www.ettus.com/all-products/ub210-kit/ [9] https://www.ettus.com/all-products/usrp-b205mini-i/ [10] https://www.gnuradio.org [11] HEXA-X-II D5.3, 2024 (https://cordis.europa.eu/project/id/101095759) [12] 6Gshine, https://cordis.europa.eu/project/id/101095738 [13] X. Song et al., "Fully-/Partially-Connected Hybrid Beamforming Architectures for mmWave MU-MIMO," IEEE Transactions on Wireless Communications, vol. 19, no. 3, pp. 17541769, 2020. [14] Y. Ertugrul et al., ''Range distribution aware architecture dimensioning for mm-wave systems,'' IEEE WCNC, 2023. [15] M. Akdeniz et al., "Millimeter wave channel modeling and cellular capacity evaluation," IEEE Journal on Selected Areas Communications, vol. 32, no. 6, pp. 1164–1179, June 2014. [16] C. Liu et al., "Adaptive Beam Search for Initial Beam Alignment in Millimetre-Wave Communications," IEEE Transactions on Vehicular Technology, vol.71, no.6, pp.6801-6806, 2022. [17] Y. Feng, M. Guenach, A. Bourdoux, W. Joseph, and E. Tanghe, “D-band Channel Modelling by 3D Ray Tracing for Joint Communications and Sensing,” IEEE JC&S Symposium 2024. [18] A. F. Molisch, “A generic model for MIMO wireless propagation channels in macroand microcells,” IEEE Transactions on Signal Processing, vol. 52, no. 1, pp. 61–71, Jan. 2004.