Papers1 provider · 2 records
May 15, 2026· Zenodo (CERN European Organization for Nuclear Research)
article
Open access

AUTHENTICATING IOT DEVICES WITHOUT REVEALING THEIR RF FINGERPRINTS: A ZERO-KNOWLEDGE FRAMEWORK ON BLOCKCHAIN

Authors:YASSINE LKHALIDI , MOHAMED LKHALIDI , HATIM KHARRAZ AROUSSI , ACHRAF TIFERNINE *

Abstract

IoT device authentication must resist impersonation and credential theft while respecting the computational constraints of edge devices. Existing frameworks rely on static cryptographic keys that, once extracted, enable full impersonation, whereas RF fingerprinting schemes that bind identity to hardware imperfections transmit and store device templates in plaintext, exposing them to template theft and linkability attacks. ZK-RFAuth is a three-phase authentication framework that integrates Siamese neural network-based RF fingerprinting, Groth16 zero-knowledge proof (ZKP) verification, and proof-of-authority blockchain logging. During registration, a Siamese convolutional network extracts a compact embedding from raw I/Q samples and commits a Poseidon hash of the quantized mean template on-chain. During verification, the prover generates a Groth16 proof demonstrating that the L1 distance between a fresh embedding and the registered template falls below a per-device threshold without revealing either vector. The proof and authentication outcome are recorded on-chain for tamper-evident auditing. Evaluated on the WiSig dataset (28 WiFi transmitters, 224,000 frames), ZK-RFAuth achieves 91.4% closed-set accuracy and 2.25% equal error rate at embedding dimension d = 64, with 88.4% genuine acceptance rate and 70.8% open-set rogue rejection using per-device P95 thresholds. The ZKP circuit requires only 972 rank-1 constraint system (R1CS) constraints over 100× fewer than an equivalent SHA-256 circuit producing 144-byte proofs verifiable in approximately 3 ms.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.