Protocol Integration of Physical Layer Deception into EAP-TEAP Wi-Fi Authentication
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "Protocol Integration of Physical Layer Deception into EAP-TEAP Wi-Fi Authentication".
Elias: Credential-based Extensible Authentication Protocol (EAP) authentication cannot distinguish a legitimate credential holder from an adversary using compromised credentials.
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: So, we're diving into this paper, "Protocol Integration of Physical Layer Deception into EAP-TEAP Wi-Fi Authentication," and it looks like they’re tackling a major weakness in credential authentication. They are arguing that standard credential-based protocols just don't have the tools to tell the difference between someone who actually has the right credentials and someone who is just using a stolen set of credentials.
Elias: I agree, Nadia; the core idea seems to be introducing Physical Layer Deception, or PLD, as a way to add that layer of physical verification. They propose pairing a primary object sent over one transport with a recovery object sent over another channel with different levels of reliability to create an authentication requirement specific design for integrating PLD into EAP-TEAP Wi-Fi authentication.
Priya: From my perspective, the focus on differentiating the reliability of these objects is interesting because it directly relates to how much noise or deception an attacker needs to overcome to fool the system. I wonder what kind of data this mechanism actually yields for measurement purposes once it's implemented across all those layers.
Nadia: Exactly, Priya; they are proposing a batched PLD-based re-verification step for the TEAP/RADIUS/IEEE eight hundred two point one one authentication chain, which means instead of just one check, you get a series of rounds where the system verifies exactly how many rounds were active and what those outcomes were.
Elias: That batching construction is key; they enforce a structure where there's a "batch of L rounds and exactly A active positions" with one A L, and all L responses need to verify correctly for the server to accept the whole thing.
Priya: It sounds like this adds a lot of complexity on the network side, but from a privacy standpoint, if it works as described, it might provide more robust checks than just looking at one single authentication exchange.
Nadia: The paper details how they handle each round: on an active round, the server exposes something like m i = p i k i for a fresh key and pairs that with a genuine key-bearing recovery object. On an inactive round, they expose just m i = p i paired with a non-key-bearing litter object so the presence of that litter never tells you anything about whether the round was active or not.
Title and authors: Elias: That distinction between m i = p i k i for active rounds and m i = p i for inactive ones is what sets up the decoder cases: (a) Active, recovered, (b) Active, missed, and (c) Inactive. The receiver uses the valid key to reconstruct the true value p if recovered; otherwise, it falls back to p = m i, which is correct when inactive but fails on an active round where recovery didn't happen.
Priya: That fallback mechanism is where I see a potential point of failure or, conversely, a point of strength depending on the adversary’s strategy; if they can force a failure in the recovery path during an active round, does that mean we’ve successfully gated access?
Nadia: Precisely; the paper analyzes this under different attacker models. They look at how an informed random-guess attacker versus a perception attacker behaves, and they give us unconditional false-accept probabilities based on those models.
Elias: The analysis also addresses repeated observations, showing that because the PLD mechanism is public, an adversary can exploit lower-layer retransmissions to gain independent observations of the same recovery object; this leads to an effective per-round recovery probability r E,J = one - (one - r E) J, which tends toward one as J grows.
Priya: That suggests that if an attacker can observe enough traffic, their ability to recover the true value gets much better, which is a serious concern for any physical layer scheme. How does this observation translate into real-world impact on deployment?
Nadia: The authors propose a specific retry policy to limit this risk, suggesting N N max independent sessions followed by backoff and a suspicious-retry alarm to try and manage the false-accept probability.
Elias: The prototype they built end to end across the server, access point, and device in the open-source hostap two point one two codebase is quite impressive; it was evaluated under mac80211 hwsim for about one thousand five hundred ninety-three attempts across four campaigns, measuring mean latency around twenty-five milliseconds added to ordinary TEAP.
Title and authors: Priya: So, when we look at the results showing acceptance falling as the recovery probability decreases under degraded conditions as A increases, does that tell us anything about how resilient this design is in real-world network environments with varying signal quality?
Nadia: It demonstrates a clear trade-off where accepting more active rounds means you're relying on more complex physical interactions, and if the recovery probability drops, the legitimate receiver's probability of success also drops.
Elias: The protocol overhead calculations show that this adds roughly seventy-three bytes or one hundred twenty-one bytes for TEAP Batch Request/Response TLVs, plus one hundred fifty bytes for RADIUS recovery VSAs, and one hundred forty-seven bytes for Category-one hundred twenty-seven Actionframe bodies across the three transport hops.
Priya: Considering all these factors—the complexity, the overhead, and the statistical analysis of observation exploitation—what do you see as the most significant implication this paper has for how we approach securing Wi-Fi authentication in general?
Nadia: I think it pushes us toward designing authentication systems that are inherently aware of physical layer signals, moving beyond just relying on what a credential says to verify *how* that credential is being presented physically.
Elias: It forces a re-evaluation of the assumptions made in existing schemes regarding the separation between primary and recovery objects, showing that this physical differentiation creates a new authentication-specific requirement for integration.
Priya: I think the impact will be felt most strongly in environments where physical layer manipulation is possible; if an attacker can manipulate those secondary channels, they might actually be able to gain more information than just stealing a password.
Nadia: It’s definitely an interesting piece of work, and it highlights how layered security can be enforced by tying application-layer logic directly into the physical constraints of the wireless transport.
Elias: I think we should keep an eye on how this mechanism interacts with other protocols, especially as we look at more complex agentic systems that rely on these kinds of authentication chains.
Priya: And I’m curious to see if future work can address the latency overhead while maintaining this level of physical verification.
Nadia: That’s what we'll be looking at next time, when we discuss how to make this kind of robust check practical for everyday deployment.
The paper's summary: Elias: It’s how they construct those objects over different transports that really catches my eye; specifically how they generate m i = p i k i for active rounds, tying the message to a fresh key k i, which then gets paired with a genuine recovery object. That structure implies a tight dependency between the physical presence and the cryptographic key material, and I'm keen to see if that dependency introduces any exploitable side channels for an adversary.
Priya: From my perspective, what’s most important is that they are not just checking a single success or failure; they are verifying an entire batch of rounds simultaneously, which gives us a richer dataset on the physical interaction itself. I want to know if this batched approach actually provides more meaningful data for privacy measurement than a standard handshake.
Nadia: Exactly, Priya; that batching construction enforces that every round in the set must verify correctly for the server to accept anything, which means we get a comprehensive view of the negotiation's validity. I’m thinking about how this batched structure changes the attack surface compared to a simple single-round check.
Elias: That complexity is where I want to focus; if an adversary can observe enough rounds, they can potentially gather more information about the key material k i because of that batching requirement, and we need to see if that observation translates into a break in the underlying cryptographic assumptions.
Priya: I’m curious about the attacker models they used; how does their analysis of an informed random-guess attacker versus a perception attacker translate into tangible security gains or losses for the end user? Does it really change how resilient this system is under different types of adversaries?
Nadia: That’s my main question, Priya; I want to know if we can actually exploit this cheaply. If an adversary has to perform enough physical interactions to get those independent observations they mention, does that cost them too much in terms of time or resources compared to just trying a stolen credential directly?
Elias: The paper touches on the effective recovery probability r E,J as the number of independent observations J grows, and it tends toward one; that suggests that persistence is an attacker's biggest hurdle here. I’m wondering if there are any specific parameters in their model where we could potentially find a weakness or a way to break that convergence rate.
Priya: And what about the practical implications for deployment? If we have these overhead calculations, how much extra latency are we really talking about when implementing this across the server, AP, and device? That’s something I need to quantify against real-world performance expectations.
Nadia: The latency is around twenty-five milliseconds added to ordinary TEAP traffic, which is manageable for many applications, but that overhead needs to be weighed against the enhanced security posture it provides against credential theft. Elias, what are your thoughts on the overall assumptions underpinning this entire physical layer deception model?
Elias: The core assumption seems to be that a secondary channel can reliably carry a recovery object with differentiated reliability, and I’m waiting to see how robust they prove that separation holds up against real-world interference or manipulation.
Priya: I’m looking forward to the experimental results showing the trade-off curve between false acceptance probability and legitimate receiver success rate under degraded recovery conditions; that data is what will truly tell us what this mechanism can handle in messy environments.
The paper's improvements: Tom: So, we're looking at how they suggest improving this PLD integration for future work; what specific enhancements are they proposing to make this system even more robust? I want to hear about any refinements that address the limitations we discussed earlier regarding observation exploitation.
Elias: They are suggesting a focus on optimizing the retry policy and alarm mechanism, aiming to actively manage the false acceptance probability by limiting how many independent sessions an attacker can observe before triggering countermeasures. This shifts the defense from pure mathematical proof toward a more dynamic, real-time response strategy.
Priya: From a measurement standpoint, I'm interested in how they plan to quantify the effectiveness of these retry limits; we need data showing if this adaptive approach actually translates into measurable improvements in system resilience versus just adding computational complexity. What kind of metrics are they prioritizing?
Nadia: I’m looking for concrete examples of how this adaptive policy would look in action on the network; does it mean different actions depending on whether we see a high rate of observation or a low rate, and how cheap is that to implement across different hardware platforms?
Elias: The proposal implies developing more sophisticated monitoring agents that can assess the statistical independence of observations J in real-time, allowing the system to adjust its security parameters dynamically based on observed environmental noise. That moves us toward a truly adaptive authentication layer.
Priya: It sounds like they're looking at how this physical verification requirement could be integrated into other agentic security frameworks; if we can model the recovery object as a verifiable physical signal, it could apply beyond just Wi-Fi authentication.
Nadia: Exactly, Priya; I think the real impact here is that we are moving toward an authentication gate based not just on credentials but on observable physical interactions, which is a much stronger barrier against credential theft.
Elias: The paper suggests exploring how these mechanisms might interface with post-quantum cryptographic primitives to ensure that the key material itself remains secure even if the physical object is being observed. That’s a big theoretical leap for this work.
Priya: I'm curious about their roadmap; what are the next steps in testing this beyond the simulated environments they used, and what kind of real-world scenarios they think will expose its true limits?
Nadia: We’ll have to see if they can move past the simulation bottleneck and prove that this system maintains its integrity when deployed in a chaotic, high-interference wireless environment. That’s the ultimate test for any physical layer scheme.
Elias: The paper flags that their current implementation is tied closely to the hostap two point one two codebase; future work will likely involve making these components more modular so that this PLD logic can be applied across a wider range of authentication protocols, not just Wi-Fi TEAP.
Conclusion: Nadia: To wrap up, we’ve seen how integrating Physical Layer Deception into EAP-TEAP Wi-Fi Authentication introduces a batched re-verification step that fundamentally changes how we verify credentials against sophisticated attackers by linking physical presence to cryptographic key material. It’s a significant step toward making authentication resistant to compromised credentials.
Elias: I agree, Nadia; the core mechanism of using differentiated reliability between primary and recovery objects creates a new authentication requirement, and it forces us to think about how those parameters break down when an attacker gains repeated observations. The assumptions about object separation are definitely what we need to scrutinize next.
Priya: From a measurement viewpoint, the data clearly shows that this system has a direct trade-off: increasing the number of active rounds improves security but also degrades legitimate receiver performance under low recovery conditions, which is important context for any deployment.
Nadia: That trade-off is definitely something we need to talk about more on how to make it practical; if we can manage that latency and the overhead effectively, this could be a real addition to securing enterprise wireless networks against credential misuse.
Elias: The paper’s findings suggest that the primary risk isn't just stolen credentials anymore, but rather exploiting subtle physical layer behaviors through repeated observation of those recovery objects. That shifts the focus from pure cryptography to physical-layer security verification.
Priya: I think it opens a lot of avenues for research into how different signal characteristics can be used to build verifiable trust, which is a broader concept than just one authentication protocol improvement.
Nadia: Absolutely, Priya; the fact that this was implemented end-to-end in an open-source codebase gives us a solid starting point for anyone looking to build on this foundation for more complex agent security features.
Elias: And I’m eager to see if future work can tackle the complexity of integrating these physical checks into existing, legacy authentication protocols without introducing unacceptable levels of computational overhead.
Priya: I'm just curious about the long-term privacy implications; if we can verify physical presence, does it inadvertently create new ways for systems to track users that we need to be careful about?
Nadia: That’s a valid concern, Priya; the design needs to be carefully managed so that this enhanced verification doesn't become a tool for unwarranted surveillance.
Elias: We’ll keep an eye on how this mechanism interacts with other layers, especially as we look at how these physical proofs might be used in conjunction with the verifiable inference techniques we’re seeing in LLM security research.
Moustafa Ibrahim, Bin Han, Hans D. Schotten
RPTU Kaiserslautern-Landau · German Research Center for Artificial Intelligence (DFKI)
cs.CR, cs.NI
Submitted: 2026-10-01
Updated: 2026-10-01
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Importance score: 80/100
The gist: Credential-based Extensible Authentication Protocol (EAP) authentication cannot distinguish a legitimate credential holder from an adversary using compromised credentials.
Key concepts
- Credential-based EAP
- This is the standard way Wi-Fi authenticates users using passwords or certificates. The paper notes this method fails against adversaries who already possess valid credentials, as it cannot tell if the holder is legitimate or an attacker using stolen data.
- Physical Layer Deception (PLD)
- PLD complements standard authentication by sending a primary object over one transport and a recovery object over another. This allows the system to check for authenticity even when the primary credential might be compromised, using differentiated reliability across different physical channels.
- Batched Re-verification
- Instead of checking credentials one by one, this design bundles multiple authentication rounds into a batch. The server accepts the entire batch only if specific conditions related to active and inactive rounds are met, significantly strengthening the security check against attackers.
Terminology
Summary
Credential-based Extensible Authentication Protocol (EAP) authentication cannot distinguish a legitimate credential holder from an adversary using compromised credentials. Physical Layer Deception (PLD) complements credential-based authentication by exposing a deceptive primary object over a primary transport while a separate recovery object travels with differentiated reliability over a secondary channel, creating an authentication-specific design requirement for integrating PLD into EAP-TEAP Wi-Fi authentication.
The gist: A batched PLD re-verification step for Enterprise Wi-Fi’s TEAP/RADIUS/IEEE 802.11 authentication chain is presented, implemented end to end across the server, access point, and device in the open-source hostap 2.12 codebase.
PLD Mechanism and Batched Re-verification Design
The proposed scheme pairs a primary object carried over a primary transport with a recovery object carried over a separate transport with differentiated reliability. The mechanism involves three decoder cases for each round: (a) Active, recovered (VALID KEY); (b) Active, missed; and (c) Inactive. On an active round, the server exposes the primary object as mi = pi ⊕ ki
for a fresh nonzero key ki, while pairing it with a genuine key-bearing recovery object. On an inactive round, it exposes mi = pi
paired with a litter object that never reveals inactivity through its presence alone. The receiver reconstructs the true value pˆi using the VALID KEY if recovered, otherwise falling back to pˆi = mi, which is correct on an inactive round but wrong on an active one whose recovery failed.
Batched Construction and Protocol Mapping
The design enforces a batch of L rounds and exactly A active positions
where 1 ≤ A ≤ L (A ≥ 1 in normal operation), with all L responses verifying. Each round i is either active or inactive, chosen by the server, where mi = (pi ⊕ ki) for an active round and mi = pi for an inactive round. Every round carries a 32-byte recovery-path object qi, which for an active round is the codeword qi = ki ti, where ti is a hash incorporating the TxnID/Round and ki. This public check establishes codeword validity only. The server accepts the batch only if all L rounds occur exactly once and every Ri of Eq. (4) matches, where Ri is computed based on pˆi.
Threat Model and Attacker Analysis
The scheme targets a claimant who already holds compromised client credential material by adding a PLD-oriented post-credential re-verification step gating final EAP-Success. The adversary is Kerckhoffs-style, knowing the full construction but not its per-attempt realization. The analysis distinguishes between the legitimate receiver (Bob) and the credentialbearing claimant (Eve), considering per-round recovery probabilities rB and rE. For an informed random-guess attacker, the unconditional false-accept probability is given by Eq. (6), while for the Perception attacker, it reduces to PFA = rA E, where A is the number of active rounds.
Repeated Observations and Retry Policy
The PLD mechanism is public, meaning Eve can exploit lower-layer retransmissions to gain independent observations of the same recovery object. Let J denote the number of statistically independent effective observations. Under J i.i.d. observations, the effective per-round recovery probability becomes rE,J = 1 − (1 − rE)J, which tends toward 1 as J grows even for small rE. The retry-aware false-accept probability is PFA = 1 − (1 − rE)J/A, and the legitimate receiver's probability is PFR = 1 − rA B,J. To limit this, the paper proposes N ≤ Nmax independent sessions followed by backoff/ratelimiting and a suspicious-retry alarm.
Prototype and Evaluation
The prototype is implemented as additions to hostap 2.12 across the server, access point, and device, evaluated under mac80211 hwsim. The evaluation covers four campaigns totaling 1593 attempts, including batched recovery behavior, a naive-attacker baseline (which is rejected in all 30 attempts), successful-path latency measurement (mean latency around 25 ms added to ordinary TEAP), and the security-reliability trade-off under two modeled recovery regimes. The results show that acceptance falls as the recovery probability decreases under degraded recovery conditions, illustrating the trade-off between PFA and PFR as A increases.
Protocol Overhead
The overhead is calculated based on implemented message formats across three transport hops: TEAP Batch Request/Response TLVs (73 B/121 B), L RADIUS recovery VSAs (150 B), and L Category-127 Actionframe bodies (147 B).
Improvements for AI systems
Here are the specific improvements and capabilities an AI system could gain by integrating the concepts from this scientific paper:
- Automatic, Authentication-Aware Deception Detection in Wireless Environments:
The AI system can be trained to distinguish between legitimate primary objects and deceptive primary objects being broadcast over a wireless medium. It achieves this by modeling the Recovery Object
as a secondary, differentiated channel signal.
- Enhanced Credential Integrity Verification:
The system moves beyond simple credential checking (which is vulnerable to stolen credentials) by requiring a successful physical-layer re-verification step (the batched PLD re-verification). This ensures that the device presenting the credential is physically present and authorized, not just spoofing the credentials.
- Adaptive Adversary Modeling and Countermeasures:
The AI can dynamically adjust its security posture based on sophisticated attacker models described in Section III.B and III.C:
-
It can estimate an adversary's recovery probability for a given round based on observed behavior (e.g.,
If the attacker is persistent, the recovery object is likely being exploited
). -
It can implement adaptive retry policies that balance legitimate user experience (avoiding excessive retries) against maximizing rejection rates against sophisticated, informed attackers (exploiting repeated observations).
- Cross-Layer Protocol Integration for Security:
The AI system can be designed to manage security decisions across the entire stack—from the application layer (EAP/RADIUS) down to the physical layer (802.11 MAC frames). It ensures that primary authentication data remains opaque to intermediate network components (like Access Points) while simultaneously monitoring and reacting to secondary, recovery-path signals.
- Resource-Aware Authentication Gating:
The system can implement an authentication gate
requirement where a minimum number of active rounds must be successfully verified before granting full access. This ensures that authentication is not bypassed by simply presenting compromised credentials without the necessary physical/recovery interaction, effectively increasing the cost for credential-bearing attackers.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs