Skip to Content
PhotonicsPhotonics
  • Article
  • Open Access

29 July 2023

Securing Non-Terrestrial FSO Link with Public Key Encryption against Flying Object Attacks

,
,
,
,
,
and
1
The Faculty of Engineering, Environment and Computing, Coventry University, Coventry CV1 5FB, UK
2
School of Electronic Engineering and Computer Science, Queen Mary University of London, London E1 4NS, UK
3
The Centre for Future Transport and Cities, Coventry University, Coventry CV1 2TE, UK
4
Department of Computer Science, Nottingham Trent University, Clifton Campus, Nottingham NG11 8NS, UK

Abstract

Free Space Optical (FSO) communication has potential terrestrial and non-terrestrial applications. It allows large bandwidth for higher data transfer capacity. Due to its high directivity, it has a potential security advantage over traditional radio frequency (RF) communications. However, eavesdropping attacks are still possible in long non-terrestrial transmission FSO links, where the geometry of the link allows foreign flying objects such as Unmanned Aerial vehicles (UAVs) and drones to interrupt the links. This exposes non-terrestrial FSO links to adversary security attacks. Hence, data security techniques implementation is required to achieve immune FSO communication links. Unlike the commonly proposed physical layer security techniques, this paper presents a lab-based demonstration of a secured FSO communication link based on data cryptography using the GNU Radio platform and software-defined radio (SDR) hardware. The utilized encryption algorithm (Xsalsa20) in this paper requires high-time complexity to be broken by power-limited flying objects that interrupt the FSO beam. The results show that implementing cryptographic encryption techniques into FSO systems provided resilience against eavesdropping attacks and preserved data security. The experiment results show that, at a distance of 250 mm and laser output power of 10 mW, the system achieves a packet delivery rate of 92 % and transmission rate of 10 Mbit/s. This is because the SDR used in this experiment requires a minimum received electrical amplitude of 27.5 mV to process the received signal. Long distance and higher data rates can be achieved using less sensitive SDR hardware.

1. Introduction

Free space optical (FSO) communication is one of the emerging breakthroughs to support the 6G networks. FSO links promise high data rates, a licence-free spectrum, and massive connectivity. This technology supports fixed terrestrial point-to-point communication for military applications, mobile communications, and internet service providers [1]. This system has also been proposed to provide non-terrestrial communication using satellite and unmanned aerial vehicles (UAVs) networks [2,3,4].
With any mode of FSO communication, terrestrial or non-terrestrial, it is crucial that sensitive information is kept secure. Due to the directional nature of optical beams, FSO is believed to offer superior security to radio frequency (RF) that makes it difficult to intercept [5,6]. For this reason, the literature related to physical layer security in wireless optical communications is scarce [5]. Although it is true that FSO offers more robust physical layer security than traditional RF transmissions, it is not a strong enough argument to disregard data security [5]. The study in [6] delves into physical layer security in FSO for the “difficulty of breach by a third party” compared to cryptographic techniques. Whilst this is true, it is also the case that physical layer encryption techniques often require additional hardware devices which drive the costs compared to mathematical cryptographic techniques at the presentation layer. To the best of our knowledge, none of the previous studies investigated this type of cryptographic encryption in FSO but instead focused on the physical layer.
Considering security is paramount to communication systems, the literature on the presentation layer security is plentiful. Bernstein et al. [7] highlights some of the underlying problems with cryptographic libraries such as OpenSSL and addressed them with a new library called Networking and Cryptography library (NaCl) (also known as salt). This library has some core features such as “No data flow from secrets to load addresses” and “centralizing randomness” to achieve higher performance and security. In [8], salt password hashing was used to secure data storage and transmission over a cloud computing network. The “salt” represents a random string which is hashed and combined with a hashed private key. The combination is once again hashed to guarantee the data cannot be decrypted under any condition. Similarly, the work in [9] used salt cryptography to secure data transmissions by embedding the transmitted information into a video with promising results for how robust it is to attacks.
Likewise, more advanced data security techniques, such as elliptic curve cryptography, exist. In [10] the performance advantages of elliptic curve cryptography (ECC) were compared to other public key systems such as Rivest–Shamir–Adleman (RSA) or Diffie–Helman. The study concluded that the reason for ECC’s success was due to industrial adaptation, which is as important as the performance advantages of a data security proposal. Recently, a non-terrestrial satellite or UAV-based FSO system whilst employing quantum key distribution (QKD) to secure the transmission was proposed in [11,12]. However, quantum-based security is cost ineffective because the technology is still in its infancy.
A balance of security and performance is important for adopting technologies such as FSO. It has been shown that strong upper-layer encryption techniques already exist and have been used to ensure secure data transmissions; however, they are not usually applied to a communication system using an FSO channel.

Motivation and Original Contributions

The most discussed advantage of FSO communication is that it allows huge bandwidths and data capacity, as demand is always growing in both the industrial and commercial sectors. However, eavesdropping attacks are possible when the transmission distance is large. For this reason, securing FSO links is essential to preserve the security of data and help with the adoption of new FSO technologies. Therefore, the main original contributions of this study are
  • Implement a secure FSO link using the NaCl library to generate encryption keys in software using GNU Radio Companion (GRC) 3.7.13.5 and investigate its performance in simulation. In particular, encryption algorithm (Xsalsa20) is used due to its high time complexity. Hence, it provides sufficient data security against adversary UAV that has limited computing power.
  • Demonstrate a laboratory-based experiment of the secure FSO link using optics and software-defined radio (SDR) transceiver and compare results to the simulation.
The rest of the paper is organized as follows. The proposed system model is described in Section 3. Secure FSO link performance in GNU Radio simulation is discussed in Section 4. The experimental demonstration of the link is given in Section 5. Finally, conclusions are provided in Section 6.

2. System Model

FSO is known for its narrow optical beam which offers immunity against security attacks. However, the beam spreads out with propagation distance, z, as follows [13,14]:
ω ( z ) = ω 1 + λ z π ω 2 2
where ω and λ are the beam waist and wavelength, respectively, of the laser at the transmitter.
Figure 1 shows (a) schematic and (b) geometry of a security attack scenario on a non-terrestrial FSO link between a satellite and ground station as the transmitter (Alice) and receiver (Bob), respectively. The attacker (Eve) is a UAV that interrupted the optical beam. The work in [15] showed that an FSO beam has a spread diameter d D θ + R of 50 cm for a divergence angle of θ = 0.1 mrad and link length of D = 5 km, where R is the beam diameter at the transmitter. In satellite FSO communications, when the link length ranges from 500 km for low earth orbit satellites, to 500 million km for deep space optical links, the beam radius expands between 6.63 m to 2.19 × 10 5 m ([16], p. 164). This beam diameter expansion is 1000 times less than RF-based satellite communications beam [17,18] and it can be controlled using optics [19,20]. However, very narrow beam divergence is not desirable because it causes mis-alignment errors due to satellite vibration or platform jitter [17]. With the advances in UAV technologies, a flying attacker of 10 cm receiver aperture can interrupt the broad optical beam and align to the transmitter which exposes the FSO link to security threats [21], as illustrated in Figure 1b. In the terrestrial FSO case, Eve was assumed to be a sufficiently sensitive device that can collect a fraction of leak power < 10 2 , otherwise, it causes a power reduction that notifies the legitimate peers Alice and Bob [5]. The study in [5] also showed that relying on the physical layer security of the FSO is not sufficient when a fraction of leak power > 10 2 . Hence, an upper-layer data encryption technique is required.
Figure 1. Security attack on satellite to ground-station FSO link by a UAV that interrupts the optical beam: (a) schematic (not to scale) and (b) geometry of the link.
In this study, we propose using a presentation layer data encryption technology to secure the transmission of non-terrestrial FSO communication links. Figure 2 illustrates a block diagram of the secure FSO system under investigation. The system is made in a simulation using the GNU Radio platform and as a prototype using an SDR transceiver and optical hardware. GNU Radio provides the user interface and handles the data processing for the transmitter and receiver in the background. The transmitter end allows a user to enter data to be encoded, encrypted, modulated, and shape burst. At the receiver end, the incoming data will be filtered, demodulated, decrypted, and decoded.
Figure 2. System block diagram.
The GNU-Radio module, responsible for implementing the encryption techniques, is an out-of-tree module called gr-nacl, developed by Wunsch et al. [22]. This module uses a well-known library called NaCl that provides functions for high-speed network communication, encryption, and signatures [7,22]. This encryption technique has continuously proven to be secure despite advancements in modern computational power. The most efficient attack on the encryption algorithm (Xsalsa20), which is used in NaCl to generate encryption keys, showed that this technique only breaks 8 of 20 rounds of encryption with time complexity of 2 250 [23]. This provides sufficient data security against power-limited eavesdroppers [24]. The NaCl library was implemented into this GNU Radio module using another library called libsodium [25]. It aims to wrap all the complex NaCl functions into simple high-speed calling functions. Finally, gr-nacl puts these functions into GNU Radio blocks that can be integrated with the rest of the workspace.
The NaCl cryptography library contains an abundance of algorithms and functions. However, only a handful of these have been implemented into gr-nacl: key generation, public encryption, private encryption, and stream encryption. We implemented public encryption techniques using the public encrypt/decrypt blocks and keypair generation blocks for both the sender and recipient.
Public encryption is used to avoid the need to exchange encryption keys across a secure channel. Moreover, this technique allows two parties to establish a secure channel by exchanging encryption keys across an insecure channel which is the case in non-terrestrial FSO.

5. Discussion

This study considered a security attack scenario on a non-terrestrial FSO link between a satellite (Alice) and a ground station (Bob). Due to the long link length (e.g., 500 km to 500 million km), the beam radius expands in the range of meters to kilometers [16]. This beam radius expansion allows for the UAV-born passive eavesdropper (Eve) to interrupt the broad optical beam without notifying the legitimate peers Alice and Bob under the hypothesis that Eve is a sufficiently sensitive device that can collect a fraction of leak power < 10 2 [5]. Hence, an upper-layer data encryption technique that uses the algorithm (Xsalsa20) within NaCl library was implemented to secure FSO systems. GNU radio simulation platform with SDR hardware was used to prove the effectiveness of the proposed data encryption technique to prevent eavesdropping.
Simulation results of a realistic non-terrestrial FSO link showed that when Eve receives a fraction of leak power of 10 2 (i.e., 0.1 W of 10 W) and boosts the received signal using an amplifier with a gain of 20 dB, it can decipher the received packets with PDR of 96%. This is consistent with the literature [5] which reported a failure of the physical layer security to prevent eavesdropping at this level of leak power. The results also showed that Eve failed to decrypt any encrypted messages.
The immunity of the cryptographic encryption techniques to eavesdropping attacks was demonstrated experimentally using GNU Radio simulation platform with Red Pitaya SDR and optical hardware. The results also showed that combining encryption with FSO preserved data security.
The results of this study showed that more work is required to secure non-terrestrial optical communication systems. The proposed Xsalsa20 provides sufficient data security against flying eavesdropper that has limited computing power to break the key. However, advanced encryption techniques are required to prevent more powerful malicious security attacks with higher computing capability.

6. Conclusions

This study proposed implementing a secured FSO link for non-terrestrial communications against security attacks from flying objects. The system was tested in simulation and experimentally using the GNU Radio platform and software-defined radio hardware. The results proved that implementing cryptographic encryption techniques using the algorithm (Xsalsa20) within NaCl library into FSO systems is effective at stopping eavesdropping attacks and preserving data security. The results also showed that at a distance of 250 mm, the secure system achieved a packet delivery rate of 92 % and a transmission rate of 10 Mbit/s. This distance achieves a minimum received electrical amplitude of 27.5 mV required at the receiver SDR to process the data. Combining encryption with FSO helps the adoption of secure non-terrestrial optical communication systems. Xsalsa20 provides sufficient data security against flying eavesdropper that has limited computing power to break the key. More work needs to be done to implement advanced encryption techniques that will increase the versatility of this communication system.

Author Contributions

Conceptualization, D.H. and F.M.A.; methodology, D.H. and F.M.A.; software, D.H.; formal analysis, D.H.; investigation, D.H.; resources, D.H. and F.M.A.; data curation, D.H.; writing original draft preparation, D.H. and F.M.A.; writing review and editing, F.B., Z.A., T.S., O.S., O.K.; visualization, D.H.; supervision, F.M.A. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

The study was approved by the Ethics Review and Approval Procedure of Coventry University (Project ID P144609, approved on 30 November 2022).

Data Availability Statement

The data presented in this study are available on request from the corresponding author (ad9051@coventry.ac.uk). The data are not publicly available due to intellectual property rights.

Conflicts of Interest

The authors declare no conflict of interest.

References

  1. Khalighi, M.A.; Uysal, M. Survey on Free Space Optical Communication: A Communication Theory Perspective. IEEE Commun. Surv. Tutorials 2014, 16, 2231–2258. [Google Scholar] [CrossRef] [Scilit]
  2. Dong, Y.; Hassan, M.Z.; Cheng, J.; Hossain, M.J.; Leung, V.C.M. An Edge Computing Empowered Radio Access Network with UAV-Mounted FSO Fronthaul and Backhaul: Key Challenges and Approaches. IEEE Wirel. Commun. 2018, 25, 154–160. [Google Scholar] [CrossRef] [Scilit]
  3. Lee, J.H.; Park, J.; Bennis, M.; Ko, Y.C. Integrating LEO Satellites and Multi-UAV Reinforcement Learning for Hybrid FSO/RF Non-Terrestrial Networks. IEEE Trans. Veh. Technol. 2023, 72, 3647–3662. [Google Scholar] [CrossRef] [Scilit]
  4. Chaudhary, S.; Amphawan, A. The Role and Challenges of Free-space Optical Systems. J. Opt. Commun. 2014, 35, 327–334. [Google Scholar] [CrossRef] [Scilit]
  5. Lopez-Martinez, F.J.; Gomez, G.; Garrido-Balsells, J.M. Physical-Layer Security in Free-Space Optical Communications. IEEE Photonics J. 2015, 7, 7901014. [Google Scholar] [CrossRef] [Scilit]
  6. Sato, Y.; Ikeda, K.; Koyama, O.; Yamada, M. Improving the quality of decrypted signal in an encryption system for secure free-space optical communication. In Proceedings of the 2019 24th Microoptics Conference (MOC), Toyama, Japan, 17–20 November 2019; pp. 202–203. [Google Scholar] [CrossRef] [Scilit]
  7. Bernstein, D.J.; Lange, T.; Schwabe, P. The security impact of a new cryptographic library. In Proceedings of the Progress in Cryptology–LATINCRYPT 2012: 2nd International Conference on Cryptology and Information Security in Latin America, Santiago, Chile, 7–10 October 2012; pp. 159–176. [Google Scholar]
  8. Sajjan, R.S.; Ghorpade, V.R. Secure online encryption with partial data identity outsourcing: An exemplar for cloud computing. In Proceedings of the 2017 Fourteenth International Conference on Wireless and Optical Communications Networks (WOCN), Mumbai, India, 24–26 February 2017; pp. 1–8. [Google Scholar] [CrossRef] [Scilit]
  9. Sharma, N.; Rathi, R.; Jain, V.; Saifi, M.W. A novel technique for secure information transmission in videos using salt cryptography. In Proceedings of the 2012 Nirma University International Conference on Engineering (NUiCONE), Ahmedabad, India, 6–8 December 2012; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
  10. Lauter, K. The advantages of elliptic curve cryptography for wireless security. IEEE Wirel. Commun. 2004, 11, 62–67. [Google Scholar] [CrossRef] [Scilit]
  11. Alshaer, N.; Ismail, T. Performance Evaluation and Security Analysis of UAV-Based FSO/CV-QKD System Employing DP-QPSK/CD. IEEE Photonics J. 2022, 14, 7324911. [Google Scholar] [CrossRef] [Scilit]
  12. Vu, M.Q.; Le, H.D.; Pham, T.V.; Pham, A.T. Toward Practical Entanglement-Based Satellite FSO/QKD Systems Using Dual-Threshold/Direct Detection. IEEE Access 2022, 10, 113260–113274. [Google Scholar] [CrossRef] [Scilit]
  13. Kaymak, Y.; Rojas-Cessa, R.; Feng, J.; Ansari, N.; Zhou, M. On Divergence-Angle Efficiency of a Laser Beam in Free-Space Optical Communications for High-Speed Trains. IEEE Trans. Veh. Technol. 2017, 66, 7677–7687. [Google Scholar] [CrossRef] [Scilit]
  14. Wang, J.; Wang, G.; Bai, R.; Li, B.; Zhou, Y. Ground simulation method for arbitrary distance optical transmission of a free- space laser communication system based on an optical fiber nanoprobe. J. Opt. Commun. Netw. 2017, 9, 1136–1144. [Google Scholar] [CrossRef] [Scilit]
  15. Eghbal, M.; Abouei, J. Security enhancement in free-space optics using acousto-optic deflectors. J. Opt. Commun. Netw. 2014, 6, 684–694. [Google Scholar] [CrossRef] [Scilit]
  16. Barnwell, N. Free-Space Optical Links for Small Spacecraft Navigation, Timing, and Communication. Ph.D. Thesis, University of Florida, Gainesville, FL, USA, 2018. [Google Scholar]
  17. Kaushal, H.; Kaddoum, G. Optical Communication in Space: Challenges and Mitigation Techniques. IEEE Commun. Surv. Tutorials 2017, 19, 57–96. [Google Scholar] [CrossRef] [Scilit]
  18. Franz, J.; Jain, V.K. Optical Communications, Components and Systems, Analysis Design Optimization Application; CRC Press: Boca Raton, FL, USA, 2000. [Google Scholar]
  19. Najafi, M.; Schmauss, B.; Schober, R. Intelligent Reflecting Surfaces for Free Space Optical Communication Systems. IEEE Trans. Commun. 2021, 69, 6134–6151. [Google Scholar] [CrossRef] [Scilit]
  20. Safi, H.; Dargahi, A.; Cheng, J.; Safari, M. Analytical Channel Model and Link Design Optimization for Ground-to-HAP Free-Space Optical Communications. J. Light. Technol. 2020, 38, 5036–5047. [Google Scholar] [CrossRef] [Scilit]
  21. Ortiz, G.G.; Lee, S.; Monacos, S.; Wright, M.; Biswas, A. Design and development of a robust ATP subsystem for the Altair UAV-to-Ground lasercomm 2.5 Gbps demonstration 2003. Proc. SPIE 4975 Free-Space Laser Commun. Technol. XV 2003, 38, 103–114. [Google Scholar] [CrossRef] [Scilit]
  22. Wunsch, S.; Müller, S.; Nieboer, G. gr-nacl: GNU Radio Data Encryption Module. 2017. Available online: https://github.com/stwunsch/gr-nacl (accessed on 20 July 2023).
  23. Aumasson, J.P.; Fischer, S.; Khazaei, S.; Meier, W.; Rechberger, C. New Features of Latin Dances: Analysis of Salsa, ChaCha, and Rumba. In Proceedings of the Fast Software Encryption; Nyberg, K., Ed.; Springer: Berlin/Heidelberg, Germany, 2008; pp. 470–488. [Google Scholar]
  24. Das, S.K.; Kant, K.; Zhang, N. Handbook on Securing Cyber-Physical Critical Infrastructure, 1st ed.; Morgan Kaufmann Publishers Inc.: San Francisco, CA, USA, 2012. [Google Scholar]
  25. Denis, F. libsodium, 2017. Available online: https://github.com/jedisct1/libsodium (accessed on 20 July 2023).
  26. Duggan, B. gr-nacl: GNU Radio Data Encryption Module. April 2022. Available online: https://github.com/duggabe/gr-control (accessed on 20 July 2023).
  27. Htay, Z.; Ghassemlooy, Z.; Zvanovec, S.; Abadi, M.M.; Burton, A. An Experimental Testbed for Implementation and Validation of Software defined FSO under Atmospheric Conditions using USRPs. In Proceedings of the 2022 13th International Symposium on Communication Systems, Networks and Digital Signal Processing (CSNDSP), Porto, Portugal, 20–22 July 2022; pp. 59–64. [Google Scholar] [CrossRef] [Scilit]
  28. Abadi, M.M. FSO-Comm-GnuRadio-Module, October 2019. Available online: https://github.com/MansourM61/FSO-Comm-GnuRadio-Module (accessed on 20 July 2023).
  29. Pang, W.; Wang, P.; Han, M.; Li, S.; Yang, P.; Li, G.; Guo, L. Optical Intelligent Reflecting Surface for Mixed Dual-Hop FSO and Beamforming-Based RF System in C-RAN. IEEE Trans. Wirel. Commun. 2022, 21, 8489–8506. [Google Scholar] [CrossRef] [Scilit]
  30. Htay, Z.; Ghassemlooy, Z.; Abadi, M.M.; Burton, A.; Mohan, N.; Zvanovec, S. Performance Analysis and Software-Defined Implementation of Real-Time MIMO FSO With Adaptive Switching in GNU Radio Platform. IEEE Access 2021, 9, 92168–92177. [Google Scholar] [CrossRef] [Scilit]
  31. Demin, P. Red Pitaya Notes, March 2022. Available online: https://github.com/pavel-demin/red-pitaya-notes (accessed on 20 July 2023).
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Article Metrics

Citations

Article Access Statistics

Multiple requests from the same IP address are counted as one view.