Search papers, labs, and topics across Lattice.
LightGuard is a dual-link system that uses LiFi for initial key exchange and WiFi for subsequent data transmission, preventing cryptographic key exposure over RF channels. The system bootstraps WiFi security by establishing session keys over a physically confined LiFi channel, ensuring keys never traverse the open RF medium. A prototype using commodity WiFi NICs and a custom LiFi transceiver demonstrates the feasibility of this approach.
Stop leaking your WiFi keys: LightGuard uses light to establish a secure channel before switching to WiFi, physically isolating the key exchange from eavesdroppers.
WiFi is inherently vulnerable to eavesdropping because RF signals may penetrate many physical boundaries, such as walls and floors. LiFi, by contrast, is an optical method confined to line-of-sight and blocked by opaque surfaces. We present LightGuard, a dual-link architecture built on this insight: cryptographic key establishment can be offloaded from WiFi to a physically confined LiFi channel to mitigate the risk of key exposure over RF. LightGuard derives session keys over a LiFi link and installs them on the WiFi interface, ensuring cryptographic material never traverses the open RF medium. A prototype with off-the-shelf WiFi NICs and our LiFi transceiver frontend validates the design.