July 06, 2026
In physical layer authentication, verification of a user’s identity is based on the characteristics of the transmission channel through which signals are delivered to the authenticator (Bob). In this paper, we assume that the signals received by Bob pass through a RIS (controlled by Bob) and that the legitimate transmitter (Alice) is equipped with one antenna. Conversely, the attacker (Trudy) has multiple antennas and uses precoding to deceive Bob’s verification. Assuming that Trudy knows all the channel matrices, we first derive her optimal attack strategy. Then, we analyse the conditions under which the channel estimated by Bob is indistinguishable when either Alice or Trudy is transmitting. When Trudy has a single antenna, we show that the indistinguishability condition cannot be met when the channels to the RIS are the result of propagation over multiple paths. For single-path line-of-sight (LOS) conditions, instead, Trudy can impersonate Alice although transmitting from a different position. We verify these results numerically and assess the security of the considered scenario, even when the indistinguishability conditions cannot be met.
Physical Layer Authentication, Reconfigurable Intelligent Surface, Impersonation Attack, Line of Sight.
Authentication is the process by which a receiver can verify the identity of a transmitter. Authentication mechanisms based on cryptographic algorithms remain secure provided that no computational breakthrough occurs, i.e., for new attack algorithms or the introduction of quantum computing. They typically entail high complexity, unsuitable in scenarios with limited power and computational resources, e.g., the Internet of Things. Alternative approaches are based on information-theoretic or physical-layer security, which are not affected by the computational capability of attackers. In PLA, transmitters are differentiated only based on the electromagnetic characteristics of their transmission channels.
PLA has been studied in the literature for quite some time, using various features of received signals, such as CFR and CIR, to distinguish a legitimate user from a potential attacker, [1]. Recently, the AoA of the signal has been shown to be a robust feature for PLA, [2], [3]. In addition, user classification has been done using both classical statistical approaches and modern tools based on machine learning.
In parallel, wireless communications have evolved through the introduction of RISs that, with their ability to shape the propagation environment, improve energy efficiency, reduce hardware complexity, and improve coverage. RISs have also been considered to improve PLA. Variable and random configurations can be set on the RIS to generate challenge-response pairs and propose a challenge-response PLA protocol based on the CSI, [4]–[7]. In [8], the authors consider CFR-based PLA in the presence of a hybrid RIS, also capable of acting as a receiver and estimating the channels of impinging signals; thus, this estimate is exploited for authentication. Authentication in a scenario with an RIS is studied also in [9], however, also exploiting pre-shared keys used for asymmetric cryptography; thus, it cannot be considered working purely at the physical layer. In [10] PLA based on the CIR in a dynamic wireless communication environment, is studied, and convolutional neural networks are used to perform classification: this overcomes the limitations of the classical statistical approach based on hypothesis testing when the wireless channel is time-varying.
In this paper, we consider that signals received by Bob are reflected through a RIS that he controls, and the legitimate transmitter, Alice, is equipped with a single antenna. In contrast, the adversary, Trudy, possesses multiple antennas and employs precoding techniques to attempt to bypass the verification process. Assuming Trudy has full knowledge of all channel matrices, we first determine her optimal attack strategy. We then examine the conditions under which Bob’s channel estimation is identical regardless of whether Alice or Trudy is transmitting. When Trudy is limited to a single antenna, we derive conditions based on the angle of arrival at the RIS. Our analysis shows that under multipath propagation conditions to the RIS, the indistinguishability requirement cannot be satisfied. However, in the case of a single-path line-of-sight (LOS) scenario, Trudy can successfully impersonate Alice by transmitting from a different location. These findings are supported by numerical simulations. We also evaluate the system’s security in situations where indistinguishability cannot be achieved.
The rest of the paper is organized as follows. Section 2 presents the system model. Section 3 describes the PLA mechanism and, then, in Section 4, a security analysis is performed, focusing on conditions that make the attack indistinguishable from a legitimate signal. Numerical results are discussed in Section 5 and, finally, conclusions are drawn in Section 6.
We consider the uplink scenario shown in Fig. 1, where the BS (Bob) aims to authenticate a UE (Alice) in a simo communication system, with Alice equipped with a single antenna and Bob with a ULA of \(M\) antennas. The signal transmitted by Alice reaches Bob through a RIS, while a blockage obstructs the Alice-Bob direct link. An attacker device, Trudy, attempts to impersonate Alice by transmitting messages that Bob may mistake as originating from Alice. Trudy is equipped with a ULA of \(N_{\rm T}\) antennas. We also assume that no direct communication is possible between Trudy and Bob, and that all of her messages are transmitted through the RIS.
Transmissions occur at mmwave frequencies. ULA antennas are uniformly spaced by a distance \(d = {\lambda}_c/2\), where \({\lambda}_c\) is the carrier wavelength. Moreover, we assume that the field of view of Bob is \(120^{\circ}\).
The RIS, controlled by Bob, has \(N\) reflecting elements spaced by the same distance \(d\). The \(n\)-th element, \(n=0,1,\ldots, N-1\), of the RIS introduces a phase shift \(\omega_n = e^{j\varphi_n}\) on the equivalent baseband signal and has unitary gain. The RIS configuration matrix is defined as \[\boldsymbol{\Omega} = {\rm diag}\{[ e^{j\varphi_0},\ldots , e^{j\varphi_{N-1}}]\}.\]
We denote the baseband equivalent vector for the channel from Alice to the RIS as \(\boldsymbol{f}\in\mathbb{C}^{N\times 1}\), the channel matrix from the RIS to Bob as \(\boldsymbol{G}\in\mathbb{C}^{M \times N}\). Thus, the resulting Alice-RIS-Bob cascaded channel is \[\label{eq:cascadedCh} \boldsymbol{h}_{\mathrm{ARB}}=\boldsymbol{G\Omega f}\,.\tag{1}\] Alice transmits suitable pilot symbols to let Bob estimate the channel, which is used for authentication. The pilot signal is assumed to be known to Trudy.
We denote as \(\boldsymbol{T}\) the matrix of the channel from Trudy to the RIS. To impersonate Alice, Trudy precodes the transmitted signal (including pilots) with vector \(\boldsymbol{q}\) and the resulting Trudy-RIS-Bob channel is then \[\label{eq:HTR} \boldsymbol{h}_{\rm TRB} = \boldsymbol{G \Omega Tq} \in \mathbb{C}^{M \times 1}.\tag{2}\] All channels (\(\boldsymbol{f}\), \(\boldsymbol{G}\), and \(\boldsymbol{T}\)) are time-invariant.
In the presence of objects around the transmitter and the receiver, the transmitted signal reaches the receiver through multiple paths. At the mmWave band, channels typically have only a few relevant paths; thus, we use a geometric model for their description. We define the \(K\)-size array response column vector for AoA \(\theta\) as \[\label{eq:2} \boldsymbol{e}_K(\theta) = \frac{1}{\sqrt{K}} [1 , e^{-j \frac{2\pi}{{\lambda}_c} d \sin\theta}, \ldots, e^{-j (K - 1) \frac{2\pi}{{\lambda}_c} d \sin\theta}]^T.\tag{3}\] For a generic channel with \(L\) paths, we define the \(L\)-paths array response matrix with AoA angles \(\boldsymbol{\theta} = [\theta_1,...,\theta_L]^T\) as \[\boldsymbol{E}_N(\boldsymbol{\theta}) = [\boldsymbol{e}_N(\theta_1) , ..., \boldsymbol{e}_N(\theta_L)].\]
Let \(L_f\) be the number of paths between Alice and the RIS, and \(\phi_{f,l}\), \(\theta_{f,l}\), and \(\gamma_{f,l}\) represent the AoD at Alice, the AoA at the RIS, and the complex path gain for the \(l\)-th path i.e., \(l = 1,...,L_f\), respectively. Let us also define \(\boldsymbol{\phi}_f = [{\phi}_{f,1},...,{\phi}_{f, L_{f}}]^T\) and \(\boldsymbol{\theta}_f = [{\theta}_{f,1},...,{\theta}_{f, L_{f}}]^T\). Moreover, \(\boldsymbol{1}_{L_f}\), \(\boldsymbol{E}_N(\boldsymbol{\theta}_f)\), and \(\boldsymbol{\Gamma}_f = \text{diag}([\gamma_{f,1}, ..., \gamma_{f,L_{f}}]^T)\) denote the \(L\)-size column vector of ones corresponding to Alice’s array response matrix, the RIS array response matrix, and diagonal path gain matrix, respectively. The baseband channel matrix between Alice and the RIS is modeled as [11] \[\begin{align} \label{eq:3} \boldsymbol{f} = \sqrt{\frac{KN}{L_{f}}} \sum_{l=1}^{L_{f}}{\gamma_{f,l} \boldsymbol{e}_N(\theta_{f,l})\boldsymbol{e}_{1}^H(\phi_{f,l})} = \boldsymbol{E}_N(\boldsymbol{\theta}_f)\boldsymbol{\Gamma}_f \boldsymbol{1}_{L_f}\,. \end{align}\tag{4}\]
The RIS-Bob channel matrix is modeled as \[\begin{align} \label{eq:G} \boldsymbol{G} = \boldsymbol{E}_M(\boldsymbol{\theta}_G)\boldsymbol{\Gamma}_G\boldsymbol{E}_N^H(\boldsymbol{\phi}_G) \in \mathbb{C}^{M \times N}\,, \end{align}\tag{5}\] where \(\boldsymbol{\theta}_G\) and \(\boldsymbol{\phi}_G\) are the vectors of AoAs to Bob and AoDs from the RIS, and \(\boldsymbol{\Gamma}_G\) is the diagonal matrix of path gains.
Similarly, the Trudy–RIS channel is modeled as \[\begin{align} \label{eq:6} \boldsymbol{T} = \boldsymbol{E}_N(\boldsymbol{\theta}_t)\boldsymbol{\Gamma}_t\boldsymbol{E}_{N_t}^H(\boldsymbol{\phi}_t) \in \mathbb{C}^{N \times N_{\rm T}}, \end{align}\tag{6}\] where \(\boldsymbol{\theta}_t\) and \(\boldsymbol{\phi}_t\) are the vectors of AoAs to the RIS and AoDs from Trudy, and \(\boldsymbol{\Gamma}_t\) is the diagonal \(L_t \times L_t\) matrix of the \(L_t\) path gains.
Trudy is assumed to perfectly know all the channels, including the Alice-RIS and RIS-Bob channel matrices \(\boldsymbol{f}\) and \(\boldsymbol{G}\). This assumption is very generous to Trudy, because she typically is neither co-located with Alice nor Bob. Moreover, the channels corresponding to \(\boldsymbol{f}\) and \(\boldsymbol{G}\) are only experienced in cascade through the RIS. Note that Alice and Bob can easily estimate the overall cascaded Alice-RIS-Bob channel, while it is harder for them, and even more so for Trudy, to estimate the individual channels represented by \(\boldsymbol{f}\) and \(\boldsymbol{G}\). Consequently, considering the attacker with complete channel knowledge will result in a conservative estimate of the security performance, corresponding to a worst-case condition for the legitimate receiver.
We also assume that Trudy chooses the transmit power without restrictions. Finally, we assume that neither Alice nor Bob knows the instantaneous channels with Trudy nor their statistics. In particular, Alice and Bob do not know where Trudy is located, so they cannot infer anything about the propagation of signals transmitted or received by Trudy.
Since the RIS is used for communication purposes between Alice and Bob, its configuration should be optimized accordingly by Bob. We indicate the communication-optimal RIS configuration maximizing the spectral efficiency as \[\label{commoptconf} \ThisStyle{\ooalign{ \SavedStyle\mkern 3mu\overline{\phantom{\mathrm{\Omega}}}\cr \SavedStyle\boldsymbol{\Omega}}} = {\rm diag} (e^{j\bar{\varphi}_1}, \ldots, e^{j\bar{\varphi}_N}),\tag{7}\] where \(\bar{\varphi}_n\), \(n=0, \ldots, N-1\), represent the communication-optimal phase shifts of the \(N\) RIS elements. Various works in the literature have proposed methods for optimizing the RIS configuration. Here we consider the technique of [12].
We consider a PLA mechanism, where Bob aims at deciding between the two hypotheses \[\begin{align} \mathcal{H}_0 &: \text{the signal comes from Alice,} \nonumber\\ \mathcal{H}_1 &: \text{the signal comes from the attacker Trudy.}\nonumber \end{align}\] To this end, the channel vector estimated by Bob operates as a distinguishing feature between the transmissions done by Alice and Trudy.
The PLA mechanism includes two phases, namely the association and verification phases. Since we assume that Bob does not know the cascade channel when Trudy is transmitting, we will not exploit this information for PLA.
In the association phase, Alice transmits some known pilot signal \(s_0\) to Bob, who exploits its knowledge to obtain a noisy estimate of \(\boldsymbol{h}_{\rm ARB}\) that we denote \(\bar{\boldsymbol{h}}\). We assume that such a phase is authenticated at a higher layer; thus, it provides a reliable estimate of the Alice-Bob channel. The association phase has to be repeated every time the Alice-Bob channel changes. In the subsequent verification phase, upon reception of a signal Bob estimates the channel over which such a signal traveled, assuming that \(s_0\) was transmitted, and obtaining the estimate \(\hat{\boldsymbol{h}}\). Then, Bob performs a test on the obtained estimate to decide whether the transmitter was Alice or not.
Let \(\boldsymbol{r}\) denote the signal received by Bob when Alice is transmitting. Assuming that Bob knows \(s_0\) and the communication-optimal RIS configuration \(\ThisStyle{\ooalign{ \SavedStyle\mkern 3mu\overline{\phantom{\mathrm{\Omega}}}\cr \SavedStyle\boldsymbol{\Omega}}}\), the received signal is \(\boldsymbol{r} = \boldsymbol{h}_{\rm ARB} s_0 + \boldsymbol{n}\), where \(\boldsymbol{n}\) is a circularly-symmetric complex Gaussian vector with zero mean and variance \(\sigma_n^2\) per entry. Bob obtains an estimate of the channel as \[\label{estch} \hat{\boldsymbol{h}} = \frac{\hat{\boldsymbol{r}}}{s_0}= \boldsymbol{h}_{\rm ARB} + \frac{\boldsymbol{n}}{s_0}.\tag{8}\]
Since we do not exploit any information on Trudy’s channel for this test, we resort to the LT on \(\hat{\boldsymbol{h}}\), based on the norm-2 distance between the current channel estimate and that obtained in the association phase [13], i.e., \[\label{eq:mse} \zeta = \|\hat{\boldsymbol{h}} - \bar{\boldsymbol{h}}\|^2.\tag{9}\] The LT providing a decision \(\hat{\mathcal{H}}\) between the two hypotheses is obtained by thresholding \(\zeta\) as follows \[\label{testMSE} \begin{equation} \zeta < \tau: \; \hat{\mathcal{H}} = {\mathcal{H}}_0, \quad \zeta \geq \tau: \; \hat{\mathcal{H}} = {\mathcal{H}}_1, \end{equation}\tag{10}\] where \(\tau\) is a suitably chosen threshold.
Two possible error events might occur in the authentication mechanism: the FA, when Bob discards a message as forged by Trudy while it is coming from Alice, and the MD, when Bob accepts a message coming from Trudy as legitimate.
Specifically, an FA occurs when, under hypothesis \(\mathcal{H}_0\), \(\zeta \geq \tau\), whereas, an MD occurs when, under hypothesis \(\mathcal{H}_1\), \(\zeta < \tau\). As security metrics, we then consider the probabilities of FA and MD, i.e. \[P_{\mathrm{FA}} = \mathbb{P}[\zeta \geq \tau | \mathcal{H}_0] \,, \quad P_{\mathrm{MD}} = \mathbb{P}[\zeta < \tau | \mathcal{H}_1] \,.\label{eq:pmd}\tag{11}\]
We now analyze the security of PLA for the considered scenario. The obtained results will highlight how the structure of the channel, due to the few reflection paths, has an impact on the error probabilities of PLA. First, we compute the optimal precoding vector for Trudy that maximizes the probability of her attack succeeding, i.e., maximizes the MD probability. Then, we discuss the impact of the number of paths on the security.
Let us define the cascade channels when Alice and Trudy are transmitting as \[\label{aT} \boldsymbol{c}_{\rm A} = \boldsymbol{E}_M(\boldsymbol{\theta}_G)\boldsymbol{\Gamma}_G\boldsymbol{E}_N^H(\boldsymbol{\phi}_G) \ThisStyle{\ooalign{ \SavedStyle\mkern 3mu\overline{\phantom{\mathrm{\Omega}}}\cr \SavedStyle\boldsymbol{\Omega}}} \boldsymbol{E}_N(\boldsymbol{\theta}_f)\boldsymbol{\Gamma}_f\boldsymbol{1}_{L_f},\tag{12}\] \[\label{a} \begin{align} \boldsymbol{c}_{\rm T} &= \boldsymbol{E}_M(\boldsymbol{\theta}_G)\boldsymbol{\Gamma}_G\boldsymbol{E}_N^H(\boldsymbol{\phi}_G) \ThisStyle{\ooalign{ \SavedStyle\mkern 3mu\overline{\phantom{\mathrm{\Omega}}}\cr \SavedStyle\boldsymbol{\Omega}}} \boldsymbol{E}_N(\boldsymbol{\theta}_t)\boldsymbol{\Gamma}_t\boldsymbol{E}_{N_t}^H(\boldsymbol{\phi}_t)\boldsymbol{q} \\& = \boldsymbol{c}'_{\rm T}\boldsymbol{q}\,, \end{align}\tag{13}\] where \(\boldsymbol{q}\) is the precoding vector used by Trudy to try to falsify Alice’s channel. Then, the channel estimated by Bob when Alice is transmitting can be written as \(\hat{\boldsymbol{h}}_A = \boldsymbol{c}_{\rm A} + \boldsymbol{n}\), while the estimated channel when Trudy is transmitting with precoding vector \(\boldsymbol{q}\) is \(\boldsymbol{\hat{h}}_T = \boldsymbol{c}'_{\rm T}\boldsymbol{q} + \hat{\boldsymbol{n}}\).
Trudy’s goal is to maximize the probability that Bob accepts her message as legitimate, i.e., to maximize \(P_{\rm MD}\). Considering the likelihood 9 used in the LT, Trudy must choose \(\boldsymbol{q}\) to minimize \(\zeta\), as Trudy knows the Alice-Bob cascade channel \(\boldsymbol{c}_{\rm A}\). However, she does not know the noise of the estimate obtained by Bob in the association phase. Therefore, we obtain the following impersonation optimization problem \[\label{minprob} \boldsymbol{q}^\star = \mathop{\mathrm{arg\,min}}_{\boldsymbol{q}} \| \boldsymbol{c}'_{\rm T}\boldsymbol{q} - \boldsymbol{c}_{\rm A}\|^2 \,.\tag{14}\] Now, we have \[\begin{align} \zeta &= ||\boldsymbol{c}'_{\rm T}\boldsymbol{q}-\boldsymbol{c}_{\rm A}||^{2} \\ &= \boldsymbol{r}^{H}\boldsymbol{c}_{\rm A}-\boldsymbol{c}_{\rm A}^{H}\boldsymbol{c}'_{\rm T}\boldsymbol{q}-\boldsymbol{q}^H\boldsymbol{c}_{\rm T}^{'H}\boldsymbol{r}+\boldsymbol{q}^H\boldsymbol{c}_{\rm T}^{'H}\boldsymbol{c}'_{\rm T}\boldsymbol{q}, \end{align} \label{eq:norm2}\tag{15}\] and by nulling the derivative with respect to \(q\), the solution of the minimization problem 14 is \[\label{solgen} \boldsymbol{q}^\star = \boldsymbol{c}^{'H}_{\rm T}(\boldsymbol{c}'_{\rm T}\boldsymbol{c}^{'H}_{\rm T})^{-1} \boldsymbol{c}_{\rm A}.\tag{16}\]
When \(\zeta=0\), the Alice-Bob channel is indistinguishable from the Trudy-Bob channel, and Bob cannot detect an attack. Let us investigate which are the conditions under which this may occur. Clearly, when Trudy is in the same position as Alice, they have the same channel to Bob. The interesting point here is to understand if there are other positions of Trudy that (together with some optimum precoding vector \(\boldsymbol{q}\)) provide the same indistinguishability condition. Such positions may exist, since Bob estimates only the cascade channel from Alice, and signals transmitted by Trudy pass through the same RIS used by Alice. From 14 we note that indistinguishability is achieved when the system of complex linear equations \[\boldsymbol{c}'_{\rm T} \boldsymbol{q} = \boldsymbol{c}_{\rm A}\] is solvable. However, determining general conditions on the Trudy-RIS channel that ensure the solution is challenging. Therefore, in the following, we focus on the special case in which also Trudy has a single transmit antenna, for which a theoretical analysis is feasible.
Let us focus on the case in which Trudy has a single antenna and both Alice-RIS and Trudy-RIS channels have \(L\) paths. Thus 13 becomes \[\label{a22} \boldsymbol{c}_{\rm T} = \boldsymbol{E}_M(\boldsymbol{\theta}_G)\boldsymbol{\Gamma}_G\boldsymbol{E}_N^H(\boldsymbol{\phi}_G) \ThisStyle{\ooalign{ \SavedStyle\mkern 3mu\overline{\phantom{\mathrm{\Omega}}}\cr \SavedStyle\boldsymbol{\Omega}}} \boldsymbol{E}_N(\boldsymbol{\theta}_t)\boldsymbol{\Gamma}_t\boldsymbol{1}_Lq\,,\tag{17}\] and the precoding vector boils down to the scalar \(q\).
To understand the conditions for indistinguishability in this case, let us define \(\boldsymbol{W} = \boldsymbol{E}_M^H(\boldsymbol{\theta}_G) \boldsymbol{E}_M(\boldsymbol{\theta}_G) \in \mathbb{C}^{L_G \times L_G}\) as the matrix with entry \([\boldsymbol{W}]_{ii}=M\) and \[[\boldsymbol{W}]_{ij} = \sum_{m=1}^{M}{e^{-j(m-1)\kappa(\sin{\theta}_{G,i}-\sin{\theta}_{G,j})}}\,, \quad for i\neq j \label{eq:W}\tag{18}\] \(\boldsymbol{z}_A\) as a \(L_G\)-size vector with entry \(l_1 = 1, \ldots, L_G\) \[\label{eq:zA} [\boldsymbol{z}_A]_{l_1} = \sum_{l_2=1}^{L_f} \gamma_{f,l_2} \sum_{n=1}^{N} e^{-j[\kappa(n-1)\mu_{A,l_1 l_2} + \bar{\varphi}_{n}]},\tag{19}\] for \(\mu_{A,l_1 l_2} = (\sin \phi_{G,l_1} - \sin \theta_{f, l_2})\), and \(\boldsymbol{z}_T\) as a \(L_G\)-size vector with entry \[\label{eq:zT} [\boldsymbol{z}_T]_{l_1} = \sum_{l_2=1}^{L_t} \gamma_{t,l_2}\sum_{n=1}^{N} e^{-j[\kappa(n-1)\mu_{T,l_1 l_2} + \bar{\varphi}_{n}]},\tag{20}\] for \(\mu_{T,l_1 l_2} = \sin \phi_{G,l_1} - \sin \theta_{t, l_2}\). We also have \[\label{eq:t1} \boldsymbol{c}_{\rm A}^{H}\boldsymbol{c}_{\rm A} = \boldsymbol{z}_A^H \boldsymbol{\Gamma}_G^H \boldsymbol{W} \boldsymbol{\Gamma}_G \boldsymbol{z}_A,\tag{21}\] \[\label{eq:t2} \boldsymbol{c}_{\rm T}^{'H}\boldsymbol{c}'_{\rm T} = \boldsymbol{z}_T^H \boldsymbol{\Gamma}_G^H \boldsymbol{W} \boldsymbol{\Gamma}_G\boldsymbol{z}_T,\tag{22}\] \[\label{eq:t3} \boldsymbol{c}_{\rm A}^H \boldsymbol{c}'_{\rm T} = \boldsymbol{z}_A^H \boldsymbol{\Gamma}_G^H \boldsymbol{W} \boldsymbol{\Gamma}_G\boldsymbol{z}_T,\tag{23}\] \[\label{eq:t4} \boldsymbol{c}_{\rm T}^{'H} \boldsymbol{c}_{\rm A} = \boldsymbol{z}_T^H \boldsymbol{\Gamma}_G^H \boldsymbol{W} \boldsymbol{\Gamma}_G\boldsymbol{z}_A = (\boldsymbol{c}_{\rm A}^H \boldsymbol{c}_{\rm T}' )^{H}.\tag{24}\]
Now, substituting 21 , 22 , 23 , and 24 into 15 , and for \(\tilde{\boldsymbol{W}} =\boldsymbol{\Gamma}_G^H \boldsymbol{W} \boldsymbol{\Gamma}_G\), we have \[\label{eq:zeta2} \zeta = \boldsymbol{z}_A^H\tilde{\boldsymbol{W}}\boldsymbol{z}_A - q\boldsymbol{z}_A^H \tilde{\boldsymbol{W}} \boldsymbol{z}_T - q^*\boldsymbol{z}_T^H\tilde{\boldsymbol{W}}\boldsymbol{z}_A + qq^* \boldsymbol{z}_T^H \tilde{\boldsymbol{W}}\boldsymbol{z}_T \,.\tag{25}\]
Defining \(b{=}\boldsymbol{z}_A^H \tilde{\boldsymbol{W}} \boldsymbol{z}_A\), \(c{=}\boldsymbol{z}_A^H \tilde{\boldsymbol{W}} \boldsymbol{z}_T\), and \(d{=}\boldsymbol{z}_T^H \tilde{\boldsymbol{W}} \boldsymbol{z}_T\), 25 becomes \[\label{eq:mse0} \zeta = d|q|^2 - cq - (cq)^* + b\,.\tag{26}\]
We are now ready to investigate the indistinguishability condition. Replacing \(q=\beta e^{j\alpha}\) in 26 , such condition can be written as \[\label{eqSol} d\beta^2 - 2|c|\beta \cos(\alpha + \rho) + b = 0\,,\tag{27}\] with \(c=|c|e^{j\rho}\). We firstly note that (by definition) \(\zeta \geq 0\) and it is minimized for \(\alpha^\star = -\rho\). Substituting \(\alpha^\star\) in 27 , we have \(d\beta^2 - 2|c|\beta + b = 0\), which has solutions only if \(|c|^2 - bd \geq 0\), or, equivalently, if \[\label{eqDiscr} |\boldsymbol{z}_A^H \tilde{\boldsymbol{W}} \boldsymbol{z}_T|^2 \geq (\boldsymbol{z}_A^H \tilde{\boldsymbol{W}} \boldsymbol{z}_A)(\boldsymbol{z}_T^H \tilde{\boldsymbol{W}} \boldsymbol{z}_T).\tag{28}\] However, by the Cauchy-Schwarz inequality \[|\boldsymbol{z}_A^H \tilde{\boldsymbol{W}} \boldsymbol{z}_T|^2 \leq (\boldsymbol{z}_A^H \tilde{\boldsymbol{W}} \boldsymbol{z}_A)(\boldsymbol{z}_T^H \tilde{\boldsymbol{W}} \boldsymbol{z}_T),\] and thus 28 must hold with equality. However, this happens if and only if \(\sqrt{\tilde{\boldsymbol{W}}}\boldsymbol{z}_A\) and \(\sqrt{\tilde{\boldsymbol{W}}}\boldsymbol{z}_T\) are linearly dependent. Note that this does not generally imply \(\boldsymbol{z}_A\) and \(\boldsymbol{z}_T\) to be linearly dependent unless \(\tilde{\boldsymbol{W}}\) is a full rank matrix. By definition, the rank of \(\tilde{\boldsymbol{W}}\) is the same of \(\boldsymbol{W}\) (due to \(\boldsymbol{\Gamma}_G\) being diagonal), which is full rank if and only if the vectors \(\{\boldsymbol{e}_M(\theta_{G,i})\}_{i=1}^{L_G}\) (i.e., the columns of \(\boldsymbol{E}_M(\boldsymbol{\theta}_G)\)) are linearly independent. This condition is satisfied when \(L_G \leq M\) and the angles \(\theta_{G,i}\) related to the different paths are distinct, i.e., \(\sin\theta_{G,i} \neq \sin\theta_{G,j}\), \(\forall i,j = 1, \ldots, L_G\), with \(i \neq j\). Since each entry of \(\boldsymbol{W}\) is given by the inner product of array response vectors 18 , which depend only on \(\sin(\cdot)\) and are periodic over \(\pi\) for ULAs with half-wavelength spacing, we must have \[\theta_{G,i} \neq \theta_{G,j} + u\,\pi,\] for any integer \(u\). Since we assume Bob has a field of view of \(\frac{2}{3}\pi\), we are also ensuring \(\boldsymbol{W}\) to be full rank when \(L_G \leq M\). In this case, it can be stated that 28 holds with equality if and only if \(\boldsymbol{z}_A\) and \(\boldsymbol{z}_T\) are linearly dependent. From the definitions in 19 and 20 , we conclude that the indistinguishability conditions require that Alice and Trudy have the same number of paths (\(L_t=L_f\)), the AoA angles at the RIS corresponding to Alice and Trudy match exactly, yielding \[\label{zAzTlinDep1} \sin \theta_{f,l} = \sin \theta_{t,l}, \quad l=1, \ldots, L_t = L_f\,,\tag{29}\] and their path gains are proportional, i.e., \[\label{zAzTlinDep2} \gamma_{f,l} = \lambda\, \gamma_{t,l}\,, \quad l=1, \ldots, L_t = L_f\,.\tag{30}\] These are then the indistinguishability conditions for \(N_{\rm T}= 1\).
When the RIS–Bob channel is single-path (\(L_G{=}1\)), \(\boldsymbol{z}_A\) and \(\boldsymbol{z}_T\) collapse to complex scalars. This dimensionality reduction significantly simplifies the attacker’s task, as linear dependence now can be trivially achieved in \(\mathbb{C}\), where any two non-zero scalars are always linearly dependent if one is a scaled version of the other.
Hence, it becomes easier for the attacker to find values of \(\alpha\) and \(\beta\) such that 27 is satisfied. Indeed, in this case, even when Trudy does not show the same angles and path gains of Alice (\(z_T \neq z_A\)), indistinguishability can still be achieved by appropriately tuning \(\alpha\) and \(\beta\) so that 27 holds. In formulas, this happens for \[\alpha = -\rho + u\pi, ueven, \alpha \in [-\pi, \pi],and\beta = \frac{|z_A|}{|z_T|}\] or \[\alpha = -\rho + u\pi, uodd, \alpha \in [-\pi, \pi],and\beta = -\frac{|z_A|}{|z_T|}.\]
The case \(L_G{=}1\) inherently poses a higher impersonation risk, as it offers fewer spatial degrees of freedom to differentiate between Alice and Trudy.
This result could also be directly inferred from the structure of the cascaded channels in 12 and 17 . Since the common term \(\boldsymbol{E}_M(\boldsymbol{\theta}_G)\boldsymbol{\Gamma}_G\boldsymbol{E}_N^H(\boldsymbol{\phi}_G)\) of the RIS-Bob channel has rank \(1\), the cascaded channels lie in the same one-dimensional subspace. Therefore, no matter how different Trudy’s and Alice’s angles and path gains are, once they pass through it, the result is always confined to a single spatial direction, limiting Bob’s ability to distinguish between them. In fact, any differences in Alice and Trudy transmissions are effectively collapsed into a single direction by the rank-one projection of \(\boldsymbol{G}\) and, then, Trudy can more easily mimic Alice’s cascaded channel.
In this section, we assess the performance of the considered authentication method investigating both single-path (i.e., \(L_G = 1\)) and multipath (i.e., \(L_G = 3\)) scenarios for the RIS-Bob channel. We consider \(L_f=L_t=3\) and path gains \({\gamma_{f,l}}\), \({\gamma_{G,l}}\), and \({\gamma_{t,l}}\) distributed as \({\mathcal{CN}}(0,1)\). We assume that the angles at the RIS and the AoDs from the transmitters are uniformly distributed in \(\left[ -\frac{\pi}{2}, \frac{\pi}{2} \right]\), while the AoAs at Bob are uniformly distributed in the range \(\left[ -\frac{\pi}{6}, \frac{\pi}{6}\right]\). Angles and gains are generated independently for Alice and Trudy. Bob is equipped with \(M \in \{4, 8, 16, 32\}\) antennas, while Alice and Trudy are single-antenna devices. The number of RIS elements is \(N=64\).
Fig. 2 shows a contour plot of the test function \(\zeta\) under attack conditions for a single-path RIS-Bob channel (i.e., \(L_G=1\)). Note that different angles and path gains for the Trudy-RIS and Alice-RIS channels are considered. The red cross marks the values of \(\alpha\) and \(\beta\) that minimize \(\zeta\): when Trudy chooses the value of \(q^\star\) corresponding to these optimal values of \(\alpha\) and \(\beta\), we have \(\zeta = 0\).
Similarly, Fig. 3 shows a contour plot of the test function \(\zeta\) under attack conditions for \(L_G=3\). Comparing Figs. 3 and 2, we observe that, for \(L_G>1\), even if Trudy uses the optimal \(q^\star\), the resulting minimum of the test function \(\zeta\) is strictly greater than zero. This confirms that, unlike the scenario with \(L_G=1\), perfect impersonation becomes impossible to achieve. Indeed, the presence of \(L_G\) paths increases the rank of the RIS–Bob channel matrix, thereby introducing additional spatial diversity that makes it harder for Trudy to align her cascade channel with that of Alice by setting the proper \(q^\star\).
The result is also confirmed by Fig. 4, which shows the detection error trade-off (DET) curves for different values of \(M\) and \(L_G \in \{1, 3\}\). The crosses mark the points for which \(P_{\rm MD} = P_{\rm FA}\). All the curves show that reducing \(P_{\rm FA}\) results in an increase in \(P_{\rm MD}\), and vice versa. It can also be noticed that for \(L_G=1\), we have \(P_{\rm MD} = 1-P_{\rm FA}\), regardless of the number of Bob’s antennas \(M\). In fact, in this case, Trudy can always find an attack strategy that yields to indistinguishability with Alice; thus the probability that Bob decides for hypothesis \(\mathcal{H}_1\) (i.e., attack condition) is the same irrespective of who is transmitting. For \(L_G>1\), instead, the optimal attack does not usually lead to indistinguishability (since the AoAs from Trudy and Alice are independent). Indeed, the DET curves do not start from the top-left corner as is typically the case. This is due to the statistical nature of the test and imperfections in Trudy’s impersonation of Alice. In fact, when \(L_G>1\), the perfect alignment between Trudy’s and Alice’s cascaded channels is not achievable, even if Trudy uses \(q^\star\). Hence, the minimum achievable \(P_{\rm MD}\) is strictly less than \(1\), emphasizing a significant limit on the success of the impersonation attack. Hence, we can conclude that a higher \(L_G\) enhances authentication robustness by limiting the ability of Trudy to fully mimic Alice’s cascaded channel. Moreover, we observe that, as \(M\) increases, the DET curves move towards smaller \(P_{\rm MD}\) for a target \(P_{\rm FA}\). This shows that having more receive antennas allows for better distinction between Alice and Trudy.
We analyzed the security of a RIS-assisted PLA scheme in scenarios with no direct link between the transmitter and the receiver, and multipath propagation conditions of the channels to and from the RIS. Assuming the worst case scenario of an attacker Trudy having full channel knowledge, we determined her optimal attack strategy. Then, we examined the conditions under which Bob’s channel estimation may have the same statistics regardless of whether Alice or Trudy is transmitting, deriving the conditions based on the AoAs at the RIS for single antenna attacker. Numerical results show that when the RIS–Bob channel is single-path, impersonation is feasible even with mismatched channel parameters. Conversely, increasing the number of RIS–Bob paths significantly enhances authentication robustness by limiting the attacker’s ability to mimic the legitimate user.
M. Baldi is supported by the project SERICS (PE00000014) under the MUR National Recovery and Resilience Plan, funded by the European Union - Next Generation EU. M. Baldi and S. Tomasin are in part supported by European Union (EU) COST Action CA22168—Physical Layer Security for Trustworthy and Resilient 6G Systems (6G-PHYSEC). The work of L. Senigagliesi and S. Tomasin are supported by the European Commission through the Horizon Europe/Smart Networks and Services Joint Undertaking (JU SNS) Project ROBUST-6G under Grant 101139068.↩︎