skip to main content
10.1145/3558482.3590182acmconferencesArticle/Chapter ViewAbstractPublication PageswisecConference Proceedingsconference-collections
research-article
Open access

Wavefront Manipulation Attack via Programmable mmWave Metasurfaces: from Theory to Experiments

Published: 28 June 2023 Publication History

Abstract

Reconfigurable surfaces enable on-demand manipulation of electromagnetic wave properties in a controllable manner. These surfaces have been shown to enhance mmWave wireless networks in many ways, including blockage recovery. In this paper, we investigate the security vulnerabilities associated with the deployment of reconfigurable surfaces, i.e., an adversary may deploy new rogue surfaces or tamper with already-deployed surfaces to maliciously engineer the reflection pattern. In particular, we introduceMetasurface-enabled Sideband Steering (MeSS), a new metasurface-in-the-middle attack in which the spectral-spatial properties of the reflected wavefront are manipulated such that a concealed sideband channel is created in the spectral domain and steered toward the eavesdropper location, while maintaining the legitimate link toward the victim intact. We fabricate a custom reconfigurable surface prototype and evaluate MeSS through theoretical analysis as well as over-the-air experiments at the 60 GHz band. Our results indicate that MeSS significantly reduces empirical secrecy capacity (up to 81.7%) while leaving a small power penalty at the victim that can be masked under normal channel fluctuations.

Supplementary Material

MP4 File (wisec-chen.mp4)
The use of reconfigurable intelligent surfaces is an emerging paradigm in wireless networks as it offers on-demand control over the wireless medium. Such a customized channel control can particularly benefit mmWave networks in which transmissions suffer from inherent propagation losses (e.g., high path loss and penetration loss). Indeed, recent literature studied surface-enhanced mmWave WLANs to improve signal-to-noise-ratio (SNR), expand coverage, increase spatial diversity, and enable blockage recovery via creating non-specular non-line-of-sight (NLOS) paths. Despite their exciting prospects, mmWave WLANs face new physical layer vulnerabilities with the advent of such surfaces, as the wireless medium can now be maliciously controlled by an adversary ? an issue that has not been thoroughly investigated in the literature. In this work, we investigate Metasurface-enabled Sideband Steering (MeSS), a new metasurface-in-the-middle attack in which an adversary manipulates the spectral-spatial properties of the reflected wavefront to create and steer a concealed sideband for eavesdropping. To avoid detection, the adversary keeps a directional link toward Bob at the same time. Although a small power reduction at Bob is inevitable, it can be masked under typical mmWave channel fluctuations caused by environment mobility. We have fabricated a custom reconfigurable surface prototype and evaluated MeSS through theoretical analysis as well as over-the-air experiments at the 60 GHz band. Our results indicate that MeSS significantly reduces empirical secrecy capacity (up to 81.7%).

References

[1]
Hakan Alakoca, Mustafa Namdar, Sultan Aldirmaz-Colak, Mehmet Basaran, Arif Basgumus, Lutfiye Durak-Ata, and Halim Yanikomeroglu. 2023. Metasurface Manipulation Attacks: Potential Security Threats of RIS-Aided 6G Communications. IEEE Communications Magazine, Vol. 61, 1 (2023), 24--30. https://doi.org/10.1109/MCOM.005.2200162
[2]
Joao Barros and Miguel RD Rodrigues. 2006. Secrecy capacity of wireless channels. In 2006 IEEE international symposium on information theory. IEEE, 356--360.
[3]
Ertugrul Basar. 2020. Reconfigurable Intelligent Surface-Based Index Modulation: A New Beyond MIMO Paradigm for 6G. IEEE Transactions on Communications, Vol. 68, 5 (2020), 3187--3196.
[4]
Ertugrul Basar, Marco Di Renzo, Julien De Rosny, Merouane Debbah, Mohamed-Slim Alouini, and Rui Zhang. 2019. Wireless Communications Through Reconfigurable Intelligent Surfaces. IEEE Access, Vol. 7 (2019), 116753--116773. https://doi.org/10.1109/ACCESS.2019.2935192
[5]
Alexander Becher, Zinaida Benenson, and Maximillian Dornseif. 2006. Tampering with Motes: Real-World Physical Attacks on Wireless Sensor Networks. In International Conference on Security in Pervasive Computing. Springer, 104--118.
[6]
Haoze Chen and Yasaman Ghasempour. 2022. Malicious mmWave reconfigurable surface: eavesdropping through harmonic steering. In Proceedings of the 23rd Annual International Workshop on Mobile Computing Systems and Applications. 54--60.
[7]
Kun Woo Cho, Mohammad H Mazaheri, Jeremy Gummeson, Omid Abari, and Kyle Jamieson. 2021. mmWall: A reconfigurable metamaterial surface for mmWave networks. In Proceedings of the 22nd International Workshop on Mobile Computing Systems and Applications. 119--125.
[8]
Tie Jun Cui, Mei Qing Qi, Xiang Wan, Jie Zhao, and Qiang Cheng. 2014. Coding metamaterials, digital metamaterials and programmable metamaterials. Light: science & applications, Vol. 3, 10 (2014), e218--e218.
[9]
Jun Yan Dai, Jie Zhao, Qiang Cheng, and Tie Jun Cui. 2018. Independent control of harmonic amplitudes and phases via a time-domain digital coding metasurface. Light: Science & Applications, Vol. 7, 1 (2018), 1--10.
[10]
Manideep Dunna, Chi Zhang, Daniel Sievenpiper, and Dinesh Bharadia. 2020. ScatterMIMO: Enabling Virtual MIMO with Smart Surfaces. In Proceedings of the 26th Annual International Conference on Mobile Computing and Networking. 1--14.
[11]
Sourjya Dutta, C. Nicolas Barati, David Ramirez, Aditya Dhananjay, James F. Buckwalter, and Sundeep Rangan. 2020. A Case for Digital Beamforming at mmWave. IEEE Transactions on Wireless Communications, Vol. 19, 2 (2020), 756--770. https://doi.org/10.1109/TWC.2019.2948329
[12]
Guojin Feng, Dong Zhen, Xiange Tian, Fengshou Gu, and Andrew D Ball. 2015. A novel method to improve the resolution of envelope spectrum for bearing fault diagnosis based on a wireless sensor node. In Vibration Engineering and Technology of Machinery: Proceedings of VETOMAC X 2014, held at the University of Manchester, UK, September 9--11, 2014. Springer, 765--775.
[13]
Yu Garbovskiy, V Zagorodnii, P Krivosik, J Lovejoy, RE Camley, Z Celinski, A Glushchenko, J Dziaduszek, and R Dka browski. 2012. Liquid crystal phase shifters at millimeter wave frequencies. Journal of Applied Physics, Vol. 111, 5 (2012), 054504.
[14]
Yasaman Ghasempour, Claudio RCM Da Silva, Carlos Cordeiro, and Edward W Knightly. 2017. IEEE 802.11 ay: Next-Generation 60 GHz Communication for 100 Gb/s Wi-Fi. IEEE Communications Magazine, Vol. 55, 12 (2017), 186--192.
[15]
Yasaman Ghasempour, Muhammad Kumail Haider, Carlos Cordeiro, and Edward W Knightly. 2019. Multi-user multi-stream mmWave WLANs with efficient path discovery and beam steering. IEEE Journal on Selected Areas in Communications, Vol. 37, 12 (2019), 2744--2758.
[16]
Yasaman Ghasempour, Muhammad Kumail Haider, and Edward W Knightly. 2018. Decoupling beam steering and user selection for MU-MIMO 60-GHz WLANs. IEEE/ACM Transactions on Networking, Vol. 26, 5 (2018), 2390--2403.
[17]
Muhammad Kumail Haider, Yasaman Ghasempour, and Edward W Knightly. 2018. Search light: Tracking device mobility using indoor luminaries to adapt 60 GHz beams. In Proceedings of the Eighteenth ACM International Symposium on Mobile Ad Hoc Networking and Computing. 181--190.
[18]
Lei Hu, Guyue Li, Hongyi Luo, and Aiqun Hu. 2021. On the RIS Manipulating Attack and Its Countermeasures in Physical-layer Key Generation. In 2021 IEEE 94th Vehicular Technology Conference (VTC2021-Fall). IEEE, 1--5.
[19]
Ke-Wen Huang and Hui-Ming Wang. 2020. Intelligent reflecting surface aided pilot contamination attack and its countermeasure. IEEE Transactions on Wireless Communications, Vol. 20, 1 (2020), 345--359.
[20]
Youngsik Hur, Jongmin Park, W Woo, Kyutae Lim, C-H Lee, HS Kim, and Joy Laskar. 2006. A wideband analog multi-resolution spectrum sensing (MRSS) technique for cognitive radio (CR) systems. In 2006 IEEE International Symposium on Circuits and Systems. IEEE, 4--pp.
[21]
IEEE. [n.,d.]. 802.11ay Task Group. http://www.ieee802.org/11/Reports/tgay_update.htm.
[22]
Ying Ju, Yanzi Zhu, Hui-Ming Wang, Qingqi Pei, and Haitao Zheng. 2020. Artificial Noise Hopping: A Practical Secure Transmission Technique With Experimental Analysis for Millimeter Wave Systems. IEEE Systems Journal, Vol. 14, 4 (2020), 5121--5132. https://doi.org/10.1109/JSYST.2020.2976852
[23]
S. Leung-Yan-Cheong and M. Hellman. 1978. The Gaussian wire-tap channel. IEEE Transactions on Information Theory, Vol. 24, 4 (1978), 451--456. https://doi.org/10.1109/TIT.1978.1055917
[24]
Xuyang Lu, Suresh Venkatesh, Bingjun Tang, and Kaushik Sengupta. 2020. 4.6 Space-time modulated 71-to-76GHz mm-wave transmitter array for physically secure directional wireless links. In 2020 IEEE International Solid-State Circuits Conference-(ISSCC). IEEE, 86--88.
[25]
Bin Lyu, Dinh Thai Hoang, Shimin Gong, Dusit Niyato, and Dong In Kim. 2020. IRS-based wireless jamming attacks: When jammers can attack without power. IEEE Wireless Communications Letters, Vol. 9, 10 (2020), 1663--1667.
[26]
L.zarfati. 2022. Hunting for Vulnerabilities in Low-Cost WiFi Repeaters. https://blog-ssh3ll.medium.com/acexy-wireless-n-wifi-repeater-vulnerabilities-8bd5d14a2990
[27]
Sohrab Madani, Suraj Jog, Jesus O Lacruz, Joerg Widmer, and Haitham Hassanieh. 2021. Practical null steering in millimeter wave networks. In 18th USENIX Symposium on Networked Systems Design and Implementation (NSDI 21). 903--921.
[28]
Vasileios Mavroeidis, Kamer Vishi, Mateusz D Zych, and Audun Jøsang. 2018. The impact of quantum computing on present cryptography. arXiv preprint arXiv:1804.00200 (2018).
[29]
Alfred Ng. 2019. These wi-fi extenders gave hackers complete control. https://www.cnet.com/home/internet/these-wi-fi-extenders-had-vulnerabilities-that-gave-hackers-complete-control/
[30]
Yong Niu, Yong Li, Depeng Jin, Li Su, and Athanasios V Vasilakos. 2015. A Survey of Millimeter Wave Communications (mmWave) for 5G: Opportunities and Challenges. Wireless networks, Vol. 21, 8 (2015), 2657--2676.
[31]
Kun Qian, Lulu Yao, Xinyu Zhang, and Tse Nga Ng. 2022. MilliMirror: 3D Printed Reflecting Surface for Millimeter-Wave Coverage Expansion. In Proceedings of ACM MobiCom.
[32]
Swetank Kumar Saha, Yasaman Ghasempour, Muhammad Kumail Haider, Tariq Siddiqui, Paulo De Melo, Neerad Somanchi, Luke Zakrajsek, Arjun Singh, Owen Torres, Daniel Uvaydov, et al. 2017. X60: A programmable testbed for wideband 60 ghz wlans with phased arrays. In Proceedings of the 11th Workshop on Wireless Network Testbeds, Experimental evaluation & CHaracterization. 75--82.
[33]
Kaushik Sengupta, Xuyang Lu, Suresh Venkatesh, and Bingjun Tang. 2020. Physically secure sub-THz wireless links. In 2020 IEEE International Conference on Communications Workshops (ICC Workshops). IEEE, 1--7.
[34]
Zhambyl Shaikhanov, Fahid Hassan, Hichem Guerboukha, Daniel Mittleman, and Edward Knightly. 2022. Metasurface-in-the-middle attack: from theory to experiment. In Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks. 257--267.
[35]
HE Shanks and RW Bickmore. 1959. Four-dimensional electromagnetic radiators. Canadian journal of physics, Vol. 37, 3 (1959), 263--275.
[36]
Paul Staat, Harald Elders-Boll, Christian Zenger, and Christof Paar. 2021. Mirror Mirror on the Wall: Next-Generation Wireless Jamming Attacks Based on Software-Controlled Surfaces. arXiv e-prints (2021), arXiv--2107.
[37]
Daniel Steinmetzer, Yimin Yuan, and Matthias Hollick. 2018. Beam-stealing: Intercepting the sector sweep to launch man-in-the-middle attacks on wireless IEEE 802.11 ad networks. In Proceedings of the 11th ACM Conference on Security & Privacy in Wireless and Mobile Networks. 12--22.
[38]
Xin Tan, Zhi Sun, Dimitrios Koutsonikolas, and Josep M Jornet. 2018. Enabling Indoor Mobile Millimeter-Wave Networks Based on Smart Reflect-Arrays. In IEEE INFOCOM. IEEE, 270--278.
[39]
Suresh Venkatesh, Xuyang Lu, Hooman Saeidi, and Kaushik Sengupta. 2020. A high-speed programmable and scalable terahertz holographic metasurface based on tiled CMOS chips. Nature electronics, Vol. 3, 12 (2020), 785--793.
[40]
Suresh Venkatesh, Xuyang Lu, and Kaushik Sengupta. 2021a. Spatio-temporal modulated mm-Wave arrays for physical layer security and resiliency against distributed eavesdropper attacks. In Proceedings of the 5th ACM Workshop on Millimeter-Wave and Terahertz Networks and Sensing Systems. 19--24.
[41]
Suresh Venkatesh, Xuyang Lu, Bingjun Tang, and Kaushik Sengupta. 2021b. Secure space--time-modulated millimetre-wave wireless links that are resilient to distributed eavesdropper attacks. Nature Electronics, Vol. 4, 11 (2021), 827--836.
[42]
Suresh Venkatesh, Hooman Saeidi, Xuyang Lu, and Kaushik Sengupta. 2022. Active Tunable Millimeter-wave Reflective Surface across 57--64 GHz for Blockage Mitigation and Physical Layer Security. In 2022 IEEE Radio Frequency Integrated Circuits Symposium (RFIC), In Press. IEEE.
[43]
Chao Wang and Hui-Ming Wang. 2016. Physical Layer Security in Millimeter Wave Cellular Networks. IEEE Transactions on Wireless Communications, Vol. 15, 8 (2016), 5569--5585.
[44]
Menglin Wei, Hanting Zhao, Vincenzo Galdi, Lianlin Li, and Tie Jun Cui. 2022. Metasurface-enabled smart wireless attacks at the physical layer. (2022).
[45]
Kedi Wu, Philippe Coquet, Qi Jie Wang, and Patrice Genevet. 2018. Modelling of free-form conformal metasurfaces. Nature communications, Vol. 9, 1 (2018), 1--8.
[46]
Qingqing Wu and Rui Zhang. 2020. Towards Smart and Reconfigurable Environment: Intelligent Reflecting Surface Aided Wireless Network. IEEE Communications Magazine, Vol. 58, 1 (2020), 106--112. https://doi.org/10.1109/MCOM.001.1900107
[47]
Nan Yang, Lifeng Wang, Giovanni Geraci, Maged Elkashlan, Jinhong Yuan, and Marco Di Renzo. 2015. Safeguarding 5G Wireless Communication Networks Using Physical Layer Security. IEEE Communications Magazine, Vol. 53, 4 (2015), 20--27.
[48]
Jian A. Zhang, Xiaojing Huang, Val Dyadyuk, and Y. Jay Guo. 2015. Massive hybrid antenna array for millimeter-wave cellular communications. IEEE Wireless Communications, Vol. 22, 1 (2015), 79--87. https://doi.org/10.1109/MWC.2015.7054722
[49]
Lei Zhang, Ming Zheng Chen, Wankai Tang, Jun Yan Dai, Long Miao, Xiao Yang Zhou, Shi Jin, Qiang Cheng, and Tie Jun Cui. 2021. A wireless communication scheme based on space-and frequency-division multiplexing using digital metasurfaces. Nature electronics, Vol. 4, 3 (2021), 218--227.
[50]
Lei Zhang, Xiao Qing Chen, Shuo Liu, Qian Zhang, Jie Zhao, Jun Yan Dai, Guo Dong Bai, Xiang Wan, Qiang Cheng, Giuseppe Castaldi, et al. 2018. Space-time-coding digital metasurfaces. Nature communications, Vol. 9, 1 (2018), 1--11.
[51]
Yanzi Zhu, Ying Ju, Bolun Wang, Jenna Cryan, Ben Y Zhao, and Haitao Zheng. 2018. Wireless side-lobe eavesdropping attacks. arXiv preprint arXiv:1810.10157 (2018).
[52]
Yongxu Zhu, Lifeng Wang, Kai-Kit Wong, and Robert W Heath. 2017. Secure Communications in Millimeter Wave Ad Hoc Networks. IEEE Transactions on Wireless Communications, Vol. 16, 5 (2017), 3205--3217. io

Cited By

View all

Index Terms

  1. Wavefront Manipulation Attack via Programmable mmWave Metasurfaces: from Theory to Experiments

        Recommendations

        Comments

        Information & Contributors

        Information

        Published In

        cover image ACM Conferences
        WiSec '23: Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks
        May 2023
        394 pages
        ISBN:9781450398596
        DOI:10.1145/3558482
        This work is licensed under a Creative Commons Attribution International 4.0 License.

        Sponsors

        Publisher

        Association for Computing Machinery

        New York, NY, United States

        Publication History

        Published: 28 June 2023

        Check for updates

        Author Tags

        1. eavesdropping
        2. physical layer security
        3. reconfigurable surfaces

        Qualifiers

        • Research-article

        Funding Sources

        Conference

        WiSec '23

        Acceptance Rates

        Overall Acceptance Rate 98 of 338 submissions, 29%

        Contributors

        Other Metrics

        Bibliometrics & Citations

        Bibliometrics

        Article Metrics

        • Downloads (Last 12 months)436
        • Downloads (Last 6 weeks)55
        Reflects downloads up to 04 Jan 2025

        Other Metrics

        Citations

        Cited By

        View all

        View Options

        View options

        PDF

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader

        Login options

        Media

        Figures

        Other

        Tables

        Share

        Share

        Share this Publication link

        Share on social media