Source-linked AI summary

Principles of Physical Layer Security in Multiuser Wireless Networks: A Survey

Amitav Mukherjee, S. A. A. Fakoorian, Jing Huang, A. Lee Swindlehurst

arXiv:1011.3754v3cs.IT

TL;DR

Physical-layer security asks how wireless systems can protect confidential messages from eavesdroppers without depending solely on higher-layer encryption. This survey synthesizes information-theoretic foundations and secure-transmission, key-generation, coding, and interdisciplinary approaches across increasingly complex wireless networks. It concludes that the field exploits channel and noise independence or secure coding, while noting that application to commercially deployed systems remains largely unexplored.

  • Problem

    Wireless confidentiality traditionally relies on cryptography, but dynamic networks face key-distribution and computational-complexity issues, motivating physical-layer alternatives.

  • Method

    The paper surveys physical-layer security from Shannon, Wyner, and Maurer’s foundations through antenna, multiuser, relay, secret-key, coding, game-theoretic, stochastic-geometric, and authentication approaches.

  • Results

    The survey identifies two broad mechanisms: exploiting independent channel and noise conditions across nodes, or designing transmission and coding strategies that limit eavesdropper information.

  • Takeaways & Limitations

    The reviewed techniques span point-to-point and multiuser networks, including artificial-noise jamming, CSI-based precoding, secret-key establishment, and practical secrecy-preserving code design.

  • Takeaways & Limitations

    Application of physical-layer security techniques to commercially deployed wireless systems is largely unexplored.

Abstract

from arXiv · show

This paper provides a comprehensive review of the domain of physical layer security in multiuser wireless networks. The essential premise of physical-layer security is to enable the exchange of confidential messages over a wireless medium in the presence of unauthorized eavesdroppers without relying on higher-layer encryption. This can be achieved primarily in two ways: without the need for a secret key by intelligently designing transmit coding strategies, or by exploiting the wireless communication medium to develop secret keys over public channels. The survey begins with an overview of the foundations dating back to the pioneering work of Shannon and Wyner on information-theoretic security. We then describe the evolution of secure transmission strategies from point-to-point channels to multiple-antenna systems, followed by generalizations to multiuser broadcast, multiple-access, interference, and relay networks. Secret-key generation and establishment protocols based on physical layer mechanisms are subsequently covered. Approaches for secrecy based on channel coding design are then examined, along with a description of inter-disciplinary approaches based on game theory and stochastic geometry. The associated problem of physical-layer message authentication is also introduced briefly. The survey concludes with observations on potential research directions in this area.

I. INTRODUCTION

Physical-layer security addresses confidential wireless communication without relying solely on higher-layer encryption by exploiting channel and noise randomness or designing secure transmissions. The survey traces foundations from Shannon and Wyner through wiretap, antenna, and multiuser systems, while reviewing key generation, coding, and related security approaches.

  • Motivation: Cryptographic protection in dynamic wireless networks faces key-distribution and computational-complexity issues, while its security premise remains computational rather than mathematically proven.Previously trusted ciphers have also been defeated as computational power increased.
  • Motivation: Physical-layer security exploits wireless-channel and noise randomness to limit information extracted by unauthorized receivers.The approach is presented as a way to address secrecy at the bit level without relying exclusively on cryptographic assumptions.
  • Survey scope: The survey reviews historical foundations and recent research across information-theoretic and signal-processing treatments of physical-layer security.It emphasizes single- and multi-antenna wiretap channels to support understanding of advanced multiuser networks.
  • System model: The basic secrecy setting contains a transmitter, legitimate receiver, and unauthorized receiver, with eavesdropper channel-state information ranging from none to complete.Most reviewed work models the eavesdropper as passive, while statistical knowledge of eavesdropper locations can also inform transmission.
  • Wiretap foundations: Wyner’s wiretap channel models the eavesdropper’s observation as a degraded channel after the legitimate receiver’s discrete memoryless main channel.The transmitter seeks reliable delivery to the legitimate receiver while limiting information leakage to the wiretapper.
  • Wiretap foundations: Wyner showed that secure communication can be achieved without a secret key, defining secrecy capacity as the maximum rate under asymptotic perfect secrecy.This criterion is weaker than Shannon’s strong secrecy, which requires zero mutual information regardless of block length.
  • Performance metrics: Secrecy outage probability measures the likelihood that instantaneous secrecy rate R_s falls below a predefined threshold ε under a fading distribution.Signal-processing designs may instead constrain eavesdropper BER or SINR, but those constraints do not satisfy weak or strong secrecy.

B. Single-Antenna Wiretap Channels Since Wyner

Single-antenna wiretap research extends secrecy-capacity analysis from degraded to non-degraded and fading channels, revealing achievable secrecy under broader channel conditions and transmitter-information assumptions.

  • For degraded Gaussian wiretap channels, secrecy capacity equals the main-channel capacity minus the wiretap-channel capacity.The main and wiretap capacities are denoted CM and CW, respectively.
  • Csiszár and Körner characterized private-message, equivocation, and common-message rates for non-degraded two-receiver broadcast channels.
  • Non-causal encoder side information can enhance the achievable secrecy-rate region through dirty-paper coding.
  • Type-II wiretap codes characterize optimal tradeoffs between code rate k/N and the number of observed coded bits μ while guaranteeing secrecy.
  • With fading, information-theoretic security is achievable even when the eavesdropper has a better average SNR than the legitimate receiver.
  • Under unknown eavesdropper realizations, Gaussian random codes, artificial noise injection, and power bursting can achieve positive secrecy rates even when the main channel is arbitrarily worse on average.

III. MULTI-ANTENNA CHANNELS

The survey extends physical-layer secrecy from single-antenna wiretap channels to MIMO systems, where spatial dimensions and channel-state information shape secure transmission. It reviews beamforming, artificial-noise, covariance-optimization, and practical MIMO secrecy strategies, while noting unresolved capacity calculations under average-power constraints.

  • MIMO wiretap channels: MIMO wiretap channels use multiple antennas at the transmitter, legitimate receiver, and passive eavesdropper to exploit spatial dimensions for secrecy.The general model uses channel matrices H_b and H_e, with transmit covariance Q_x subject to an average-power constraint.
  • MIMO wiretap channels: Space-time coding and CSI-informed transmission strategies target low eavesdropper interception or detection probabilities under different eavesdropper-CSI assumptions.The reviewed strategies include constant-spatial-inner-product constellations when the eavesdropper lacks receive CSI.
  • Transmission strategies: When only eavesdropper-channel statistics are known, artificial noise is designed to be orthogonal to the intended receiver, degrading primarily the eavesdropper.If N_T > N_R, the artificial-noise precoder can use the nullspace of H_b; partial eavesdropper CSIT can support covariance optimization or relaxed orthogonality.
  • Transmission strategies: GSVD beamforming requires instantaneous eavesdropper-channel knowledge, whereas artificial noise requires its statistics; main-channel waterfilling performs relatively poorly without eavesdropper information.The comparison assumes N_T = N_E = 3 and N_R = 2 with transmit power measured in dB and 0 dB noise power.
  • Capacity and optimization: Under a matrix input covariance constraint, Gaussian input without prefix coding can achieve MIMO secrecy capacity, and closed-form optimal covariance expressions are available through MSE-mutual-information relations.The survey also reviews upper and lower bounds and equations characterizing general MIMO solutions.
  • Capacity and optimization: If no generalized eigenvalues exceed 1, the intended receiver is degraded relative to the eavesdropper and the secrecy capacity is zero.The relevant generalized eigenvalues are those of the stated positive-definite matrix pencil.
  • Capacity and optimization: For the general MIMO case under an average-power constraint, no computable secrecy-capacity expression is available, although special cases admit closed-form solutions.For a fixed semidefinite S, C_sec(S) is computable; closed forms are available in certain full-rank and high-SNR cases.

A. Broadcast and Multiple-Access Channels

The survey generalizes physical-layer secrecy to broadcast and multiple-access networks, distinguishing confidentiality among intended receivers from protection against external eavesdroppers. It reviews capacity results, coding strategies, and remaining gaps, including the lack of general computable expressions for MIMO broadcast channels and limited multi-antenna MAC work.

  • Broadcast channels: Broadcast secrecy divides into confidential-message channels, where receivers eavesdrop on one another, and wiretap broadcast channels protected only from external eavesdroppers.The survey focuses primarily on the more challenging confidential-message category.
  • Broadcast channels: For two confidential messages, dirty-paper coding can simultaneously achieve both receivers’ maximum secrecy rates under a matrix input covariance constraint.The cited result combines artificial noise and random binning to achieve the MIMO Gaussian wiretap secrecy capacity.
  • Broadcast channels: Secret dirty-paper coding and channel splitting characterize MIMO Gaussian broadcast channels with confidential and common messages.Secure broadcasting with more than two receivers has also been studied under related models.
  • Broadcast channels: A computable secrecy-capacity expression remains unavailable for the general MIMO broadcast channel under an average transmit-power constraint.Linear precoding solutions exist under matrix covariance constraints and yield closed-form suboptimal algorithms under average power.
  • Multiple-access channels: In Gaussian multiple-access wiretap channels, secrecy sum capacity can be achieved with Gaussian inputs and stochastic encoders under degraded-wiretapper models.The reviewed work also derives achievable rate regions for different secrecy constraints.
  • Multiple-access channels: For fading cognitive MACs with confidential messages, closed-form power allocation achieves every boundary point of the secrecy-capacity region.The model has two users sending common information while user 1 protects confidential information from user 2.
  • Multiple-access channels: Existing MAC work largely assumes single-antenna nodes, leaving relatively little research on multiple-antenna confidential-message scenarios.This scope boundary follows the survey’s discussion of current MAC results.

B. Interference Channel

Interference-channel secrecy research studies secure degrees of freedom and achievable secrecy regions under simultaneous cross-link interference. Results emphasize interference alignment, with cooperative and non-cooperative strategies differing substantially in achievable secrecy performance.

  • Interference channels contain multiple simultaneous links sharing the same time-frequency slot, so unintended transmissions can interfere with each receiver.
  • Secure degrees of freedom capture how the sum secrecy rate scales as transmit SNR ρ tends to infinity.
  • Interference alignment generally underlies achievability of secure degrees of freedom across the surveyed multiuser networks.
  • For K-user Gaussian interference channels with K ≥3, positive secure degrees of freedom are achievable under very strong interference using interference alignment and channel extension.
  • In two-user MIMO interference channels, cooperative and non-cooperative schemes yield secrecy regions and operating points based on GSVD, bargaining, and artificial-noise alignment.
  • Ordinary jamming is near optimal for the standard wiretap channel but far from optimal for the interference channel.

V. RELAYS AND COOPERATIVE METHODS

Relay-network security extends physical-layer secrecy to cooperative settings with either untrusted or trusted relays. The central distinction is whether relay nodes themselves must be prevented from learning transmitted messages.

  • Relay and cooperative-network security studies secrecy capacity and achievable secrecy-rate bounds using modified conventional relay strategies.
  • Untrusted relays must forward messages while remaining unable to learn them.
  • Trusted relays may forward messages without requiring those messages to remain secret from the relays.

A. Untrusted Relays

Untrusted-relay models require cooperation from a relay that is simultaneously a helper and a potential eavesdropper. Surveyed solutions include secrecy-rate optimization, relay selection, outage analysis, and destination-assisted jamming.

  • An untrusted relay is modeled as co-located with the eavesdropper, so it helps forward the message while also attempting to decode it.
  • Relay-wiretap coding studies derive deterministic and stochastic rate regions when transmitted messages must remain confidential to the relay.
  • Untrusted-relay cooperation can be beneficial in models with an orthogonal link in the second hop.
  • A half-duplex amplify-and-forward system can have the destination jam the relay during source transmission and later subtract that intentional interference.
  • Related MIMO studies optimize source and relay beamformers, relay selection, and secrecy outage probability for one-way and two-way untrusted relays.

B. Trusted Relays and Helpers

Trusted-relay and helper schemes counter external eavesdroppers through relaying, cooperative jamming, noise forwarding, and artificial-noise processing. These methods exploit authorized nodes or normally inactive network nodes to degrade eavesdropper observations.

  • Trusted-relay scenarios separate relays from external eavesdroppers, allowing relays to relay, jam cooperatively, or serve as stand-alone helpers.
  • Noise forwarding uses relay-generated dummy codewords independent of the secret message to confuse the eavesdropper.
  • Two-hop multiple-relay schemes derive relay weights to maximize achievable secrecy rate when the source-relay link is unprotected from eavesdropping.
  • Helpers transmit random codewords decodable by the intended receiver but not by the eavesdropper, or transmit jamming signals that interfere with interception.
  • Cooperative jamming can use normally inactive source, destination, or surrounding nodes as temporary helpers without external helpers.
  • Fig. 8 examines secrecy rate versus transmit power in a two-hop channel with cooperative jamming, unknown ECSIT, and four antennas at all nodes.
  • In two-way wiretap channels, transmitting nodes jam the eavesdropper during both phases using spatial degrees of freedom or external helpers.

VI. WIRELESS SECRET KEY AGREEMENT

Wireless secret-key agreement exploits shared randomness between legitimate terminals while limiting the eavesdropper’s information through public discussion, reconciliation, and privacy amplification. The survey reviews foundational bounds and wireless techniques for generating stronger common randomness.

  • Foundations: Maurer’s protocol uses public discussion to reconcile Alice’s and Bob’s observations, then applies privacy amplification to extract a shared secret key.The protocol assumes repeated observations of correlated random variables X, Y, and Z, followed by interactive public communication.
  • Foundations: The secret-key rate is bounded above by min[I(X;Y), I(X;Y|Z)] and below by max[I(X;Y)−I(X;Z), I(Y;X)−I(Y;Z)].These bounds quantify how correlation between legitimate terminals and the eavesdropper’s observations constrain achievable key rates.
  • Wireless mechanisms: Wireless key generation exploits reciprocal channel randomness, including fading phases, multipath coefficients, channel estimates, feedback, and level-crossing behavior.Multiple-antenna channels can further increase common randomness available to legitimate users.
  • Wireless mechanisms: Transmit-array optimization can induce faster channel fluctuations, while unknown deterministic multipath parameters provide alternative sources for key extraction.These approaches broaden key-generation mechanisms beyond the standard common-randomness framework.
  • Enhancements: MIMO secret-key research includes randomized beamforming and practical protocols designed for temporally and spatially correlated channels.Randomized beamforming can make blind channel estimation by the eavesdropper more difficult.
  • Enhancements: Keyless-security techniques such as cooperative jamming and artificial noise can be reused to enhance secret-key rates in two-way wiretap and relay networks.The survey also discusses the optimality of Gaussian jamming against secret-key establishment in two-way wireless channels.

VII. CODE DESIGN FOR SECRECY

Code design for secrecy develops channel codes that simultaneously support reliable decoding and confidentiality against eavesdroppers. The survey covers stochastic constructions, graph-based and lattice codes, and polar codes with secrecy-capacity results.

  • Cryptographic connections: The survey also connects practical secrecy-preserving channel coding with classical cryptography through the McEliece cryptosystem.McEliece uses a public-key encoding based on disguised error-correcting codes and randomized error perturbations.
  • Wiretap coding: Wyner’s stochastic encoding partitions a mother codebook into secret subcodes and randomly selects codewords within the message-associated subcode.The mother code supplies decoding redundancy, while subcode randomness limits information leakage.
  • Constructive codes: LDPC and multilevel codes were applied to wiretap channels to satisfy reliability and Wyner’s weak secrecy criterion simultaneously.The cited construction targets binary erasure wiretap channels with a noiseless main channel.
  • Constructive codes: Structured integer and nested lattice codes achieve arbitrarily large secrecy rates for Gaussian wiretap channels with an external helper.The result illustrates secrecy gains from structured coding with cooperative assistance.
  • Constructive codes: Polar codes achieve secrecy capacity for binary symmetric and deterministic wiretap channels and are also secrecy-capacity-achieving for secret-key generation over a binary symmetric channel.The same coding family is therefore extended from wiretap secrecy to secret-key generation.

B. Distributed Storage Coding

Distributed-storage coding extends secrecy design to systems that must reconstruct data despite node failures and constrained repair bandwidth. The survey considers adversaries observing stored or repaired data and codes that preserve secrecy during recovery.

  • Distributed Storage Coding: Regenerating codes distribute file chunks across storage nodes so data can be reconstructed from k nodes while reducing storage and repair-bandwidth costs.Security is added because eavesdroppers may observe stored or repair data.
  • Distributed Storage Coding: A Type-I adversary observes data stored on up to ℓ nodes, whereas a Type-II adversary can additionally observe their repair data.The distributed-storage threat model is illustrated by an eavesdropper accessing compromised nodes.
  • Distributed Storage Coding: Secrecy capacity Cs(α, γ) is the maximum reliably reconstructable data that remains perfectly secret from Eve for all data collectors and eavesdroppers.Here α denotes per-node storage and γ denotes the total repair data downloaded by a replacement node.
  • Distributed Storage Coding: For a Type-I adversary, the secrecy-capacity bound reflects that only the k−ℓ uncompromised nodes can provide secure and reliable information to the data collector.The bound captures the loss of secure information caused by compromised storage nodes.
  • Distributed Storage Coding: Secure exact-repair codes based on the product-matrix framework make downloaded replacement data independent of helper-node identities.This property supports secure repair while preserving the intended storage-system operation.
  • Network coding: Secure network coding injects random keys at the source so multicast messages remain secret when a wiretapper observes an unknown set of network links.For equal-capacity multicast links, the secrecy capacity equals the cut-set bound.

VIII. RELATED TOPICS

Related research applies physical-layer security to strategic multiagent interactions, cognitive radio, sensor networks, and large-scale spatial networks. These settings use game theory, spectrum-aware transmission, estimation strategies, and stochastic-geometry-inspired connectivity analysis.

  • Game theory: Game-theoretic models represent transmitters, receivers, helpers, and attackers as rational agents maximizing individual payoffs under cooperative or non-cooperative interaction.Stable outcomes in these models are Nash equilibria, while cooperative games can support coalitions and mutual benefit.
  • Game theory: Secrecy rate, SINR differences, and jamming behavior serve as payoffs in zero-sum, cooperative, and Stackelberg formulations of secure wireless networks.These models analyze adversarial jammers, collaborative beamforming, helper payments, and hierarchical interactions.
  • Cognitive radio: Cognitive-radio security research addresses spectrum-sensing attacks, denial-of-service vulnerabilities, and primary-user emulation threats with corresponding mitigation strategies.Primary-user emulation detection uses transmitter location and signal characteristics.
  • Cognitive radio: In cognitive-radio secrecy, secondary-user data can act as cooperative jamming while simultaneously improving network spectral efficiency.Stackelberg power control selects primary and secondary transmission powers so secondary access is allowed only when the primary secrecy rate improves.
  • Sensor networks: Sensor-network secrecy includes deliberate channel fluctuations, secret quantization mappings, and censoring strategies for energy-constrained systems with eavesdroppers.Some designs jointly optimize legitimate-receiver decision rules and mapping probabilities under eavesdropper-error constraints.
  • Large-scale networks: Large-scale security analysis uses secrecy graphs and spatial models to study secure connectivity, including in-degree, out-degree, and percolation properties.These methods characterize how randomly distributed legitimate nodes and eavesdroppers affect network connectivity.

D. Physical Layer Authentication

Physical-layer authentication complements confidentiality by helping receivers detect forged or modified messages. The survey introduces information-theoretic, key-based, and wireless-fingerprinting approaches, including channel-based hypothesis testing.

  • Message authentication enables receivers to detect whether messages were forged or illegitimately modified by someone other than the claimed source.
  • Information-theoretic authentication has been studied under shared-secret-key and noiseless-transmission assumptions, later incorporating message distortions, joint typicality decoding, noise, and channel errors.
  • Wireless fingerprinting extracts device-specific non-ideal transmission parameters from received signals without requiring a key embedded in the modulation scheme.
  • A multi-antenna authentication test first estimates the legitimate channel and then compares a newly observed channel estimate against it using hypothesis testing.
Loading 1011.3754v3…