Method for triggering a first device as a step of accessing an accessible device
By receiving pilot signals and extracting channel state information, and confirming the matching of messages and channel characteristics, the vulnerability of keyless systems to relay station attacks is solved, thus improving system security.
Patent Information
- Application Number
- CN202180054479.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-09-03
- Filing Date
- 2021-04-06
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2041-04-06
AI Technical Summary
Existing keyless systems are vulnerable to relay station attacks, leading to unauthorized access to vehicles and insufficient security.
By receiving pilot signals, channel state information is extracted and channel characteristics are derived to confirm whether the message and channel characteristics match, thus preventing relay attacks.
It improves the security of the keyless system, prevents relay station attacks, and enhances the security of access devices.
Smart Images

Figure CN116057589B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a method for triggering a first device, wherein the triggering of the first device is a step required for accessing an accessible device. The present invention further relates to a method for accessing an accessible device, the method comprising the method for triggering the first device, the present invention further relates to a first device, a system having the first device and a second device, a computer program product and a computer readable medium. BACKGROUND
[0002] Different applications are known in which an accessible device is to be accessed without a physical key and merely by means of an access device, which has wireless communication capabilities in order to communicate with the accessible device.
[0003] A particular relevant application is an access system for a vehicle. Such an access system is also referred to as a keyless system. A physical key is replaced by some kind of electronic access device, for example a chip with wireless communication capabilities implemented in a key fob, and the vehicle can be accessed by means of this electronic access device. Typically, this requires the vehicle owner to actively participate in accessing the vehicle, for example by pressing a physical button on the electronic access device.
[0004] However, nowadays, new vehicles are typically equipped with passive keyless systems. The vehicle can be accessed, for example the doors and / or the trunk are opened or the ignition is started, merely by short-range wireless communication of the vehicle with the electronic access device.
[0005] Figure 1 The keyless system 1 is schematically shown, which has a passive keyless implementation, which means that the vehicle 10 can be accessed without any vehicle owner 26 interacting with the access device 20 but merely by being in close proximity to the vehicle, for example 1 meter.
[0006] In the example of Figure 1 the access device 20 is provided as a key fob 20. The key fob 20 establishes a communication link with the vehicle 10. More precisely, an antenna of the key fob 20 (not shown in Figure 1 communicates via the communication link with a compatible antenna of the vehicle 10 (not shown in Figure 1 ).
[0007] Figure 2 The keyless system 1 of Figure 1 is schematically shown how the prior art method 100 works in order to grant access to the vehicle 10 only to a rightful vehicle owner 26 or a person having the original physical electronic access device 20.
[0008] In step 101 of the prior art method 100, an antenna of the vehicle 10 sends out a so-called wake-up or challenge signal. In order to send out the wake-up or challenge signal, it can be necessary to touch a handle of the vehicle 10 or to perform some other interaction with the vehicle 10.
[0009] The wake-up or challenge signal has a rather limited range, for example 10 meters. The limited range of the wake-up or challenge signal or in other words the limited range of the communication link that can be established between the vehicle 10 and the remote key 20 is pre-selected such that the vehicle 10 is accessed, for example unlocked, when the vehicle owner 26 is in close proximity to the vehicle 10 such that it can be safely predicted that he will want to access the vehicle 10.
[0010] If the remote key 20 is not within the pre-selected range of the wake-up or challenge signal, the remote key 20 cannot respond to the wake-up or challenge signal sent out by the vehicle 10 and the method aborts in step 102. However, the vehicle 10 can periodically repeat step 101, i.e. send out the wake-up or challenge signal, for example every few milliseconds, without the need for interaction with the vehicle 10.
[0011] Once the remote key 20 is within the proximity of the vehicle 10 that matches the selected range of the wake-up or challenge signal, the remote key 20 receives the wake-up or challenge signal in step 103. The wake-up or challenge signal contains a unique message or key that is only known to or identifiable by the remote key 20. In step 104, the remote key 20 determines whether the message contained in the received wake-up or challenge signal matches a saved or expected message. There are different methods known in the prior art with respect to the content of the message, its identification and specific security features, like encryption, that can be applied to the content of the wake-up or challenge signal.
[0012] If this is not the case, the method 100 aborts in step 105. For example, a wake-up or challenge signal from a different vehicle that is not the vehicle of the owner 26 can have been received and this wake-up or challenge signal has a different message.
[0013] On the other hand, if the message contained in the received wake-up or challenge signal matches the expected message, in step 106 a wake-up or challenge signal from the remote key 20 is sent back to the vehicle 10. This wake-up or challenge signal contains a unique message or key that is only known to or identifiable by the vehicle 10.
[0014] The vehicle 10 receives in a step 107 the wake-up or challenge signal transmitted from the remote key 20 and determines in a step 108 whether the message contained therein matches the expected message expected by the vehicle 10. If this is not the case, for example, a wake-up or challenge signal of a remote key has been received from a remote key which is not the owner 26, the vehicle 10 does not grant access and the method 100 aborts in a step 109. Otherwise, if the message contained in the received wake-up or challenge signal and the expected message match, the vehicle 10 is triggered in a step 110 and thus the vehicle 10 is accessed in a step 111, for example, the vehicle 10 is unlocked.
[0015] While accessing the vehicle 10 by means of the keyless system 1 as described above provides the owner 26 with the advantageous, comfortable function, it also has the problem of being vulnerable to hacking. In particular, so-called relay attacks or relay station attacks, also known as RSA, are used to gain access to the vehicle 10.
[0016] Figure 3 An exemplary setup of such a relay attack is shown. An attacker 52 positions a relay station 50 between the vehicle 10 and the remote key 20. The attacker 52 receives the wake-up or challenge signal on his relay station 50 at a distance in the preselected range of the wake-up or challenge signal via a first relay communication link 40. If necessary, the attacker 52 can trigger the vehicle 10 to send out the wake-up or challenge signal, for example, by touching the handle of the door on the driver's side of the vehicle 10.
[0017] The relay station 50 then forwards (or relays) the wake-up or challenge signal with the original message contained therein to the remote key 20 via a second relay communication link 41. As described above, the remote key 20 matches this message with the expected message and sends back a response signal. The response signal is then received by the relay station 50 via the second relay communication link 41 and is forwarded (or relayed) to the vehicle 10 via the first relay communication link 40 together with its original message. Thus, the response signal from the remote key 20 is received directly by the vehicle. Thus, the maximum attack range can be limited.
[0018] Figure 4 Another exemplary setup of such a relay attack with two relay stations 50, 51 is shown. A first attacker 52 with a first relay station 50 is located in the vicinity of the vehicle 10 and a second attacker 53 with a second relay station 51 is located in close proximity to the remote key owner 26. In Figure 4 In this case, the first attacker 52 receives the wake-up or challenge signal on his relay station 50 via the first relay communication link 40. The relay station 50 then forwards (or relays) the wake-up or challenge signal with the original message contained therein to the second relay station 51 via the second relay communication link 41. The second relay station 51 then forwards (or relays) the wake-up or challenge signal with the original message contained therein to the remote key 20 via the third relay communication link 42. As described above, the remote key 20 matches this message with the expected message and sends back a response signal. The response signal is then received by the second relay station 51 via the third relay communication link 42 and is forwarded (or relayed) to the first relay station 50 via the second relay communication link 41 together with its original message. The first relay station 50 then forwards (or relays) the response signal to the vehicle 10 via the first relay communication link 40. Thus, the response signal from the remote key 20 is received directly by the vehicle. Thus, the maximum attack range can be limited. Figure 3 The proportions of the elements in Figure 3 are not to scale but are schematic. The distance of the remote key owner 26 from the vehicle 10 is much greater than the distance in
[0019] Similar toFigure 3 In the exemplary setup of Fig. 1, the wake-up or challenge signal is forwarded (relayed) between the vehicle 10 and the access device 20, in this case in the form of a smart device 20, such as a smartphone 20, by means of a plurality of relay communication links 42, 43, 44 between the vehicle 10 and the access device 20 and the relay stations 50, 51. Therein, the relay communication link 43 is designed to bridge the larger distance between the relay stations 50, 51.
[0020] Such an attack setup is designed to electronically reduce the large physical distance between the owner 26 and the vehicle 10 using the relay station technology, which can be a multiple of the preselected range of the wake-up or challenge signal. Thus, the keyless system 1 can be fooled to believe that the vehicle 10 and the access device 20 are in close proximity to each other, although they are not. The attacker can gain access to the vehicle 10 regardless of the limited range of the antennas of the vehicle 10 and the access device 20 and the encrypted content of the wake-up or challenge signal. SUMMARY
[0021] It is an object of the present invention to provide a method which makes such a keyless system more secure, in particular against attacks like relay station attacks or at least makes attacks like relay station attacks more difficult.
[0022] This object is solved by the technical solution defined by the present invention. Thus, the object is solved by the method for triggering a first device according to the present invention, the method for accessing an accessible device according to the present invention, the first device according to the present invention, the system according to the present invention, the computer program product according to the present invention and the computer readable medium according to the present invention. Further details of the present invention evolve from the present invention and the description and the drawings. Thus, features and details described in connection with the method for triggering a first device according to the present invention apply to the method for accessing an accessible device according to the present invention, the first device according to the present invention, the system according to the present invention, the computer program product according to the present invention and the computer readable medium according to the present invention and vice versa, so the disclosure with respect to the individual aspects of the present invention refer to each other or can refer to each other.
[0023] According to a first aspect of the present invention, the above object is solved by a method for triggering a first device, in particular a computer implemented method. The first device has at least one antenna for wireless communication with a second device having at least one antenna. The first device is an accessible device, in particular a vehicle, or an access device, in particular a remote key or a smart device. The second device is the other one of the accessible device and the access device. The triggering of the first device is a step required for accessing the accessible device. The method comprises the steps of:
[0024] (a) receiving at least one pilot signal at the first device via the at least one antenna;
[0025] (b) determining whether at least one message contained in the received at least one pilot signal corresponds to at least one expected message expected by the first device;
[0026] (c) extracting channel state information from the received at least one pilot signal;
[0027] (d) deriving at least one channel characteristic from the extracted channel state information;
[0028] (e) determining whether at least one derived channel characteristic corresponds to at least one expected channel characteristic expected by the first device; and
[0029] (f) triggering the first device if the received at least one message corresponds to the expected at least one message and at least one derived channel characteristic corresponds to at least one expected channel characteristic, otherwise not triggering the first device.
[0030] The opposite case applies when the received message does not correspond to the expected message or at least one derived channel characteristic does not correspond to at least one expected channel characteristic.
[0031] The above method steps are referred to by the letters (a) to (f) in alphabetical order for the sake of simplicity and are not intended to limit the steps to the exact order. For example, step (b) can alternatively be performed after or in parallel to steps (c) and (d). However, it is preferred that the steps of the method are performed in the given alphabetical order.
[0032] Current approaches to solve the problem of relay station attacks focus on proximity, in particular ranging or positioning. For example, it can be identified how far away the access device is from the accessible device or the exact position of the access device relative to the vehicle. This information can help to solve the problem.
[0033] However, the present application does not focus on the proximity, although such a technique can additionally be implemented, but aims at identifying in the received at least one pilot signal or in other words in its wireless communication channel (through which the received at least one pilot signal is transmitted) traces or evidence of an attack, in particular of a relay attack. To this end, channel state information of the received at least one pilot signal is extracted and at least one channel feature is derived from the channel state information. The at least one channel feature can be derived, for example, by calculating or simply extracting the at least one channel feature from the channel state information. Then, it is determined whether the at least one derived channel feature is actually the expected channel feature or in other words whether there are traces or evidence of an attack in the at least one derived channel feature which have actually changed the at least one channel feature with respect to the expected at least one channel feature such that it can be determined that the at least one channel feature does not originate from a communication between the access device and the accessible device which has not been interfered by a relay station.
[0034] Furthermore, it is further ascertained whether at least one message contained in the at least one received pilot signal is expected by the first device. In other words, in addition to the signal tracking by means of the extracted channel state information, it is determined whether the at least one message is from the accessible device (e.g. a vehicle) or the access device (e.g. a remote key or a smart device). The at least one message can be encrypted or secured by any method known in the art. In particular, the accessible device and the access device can be configured with such encryption or security features and / or methods as known in the art.
[0035] If the determination results in that the received at least one message corresponds to the expected at least one message and the at least one derived channel feature corresponds to the at least one expected channel feature, the first device is triggered. In other words, if it is identified by means of the at least one message and the at least one derived channel feature that the at least one message originates from the second device, the first device is triggered. Thereby, the security of the method for triggering the first device in the method for accessing the accessible device is significantly increased compared to having an encrypted message in the pilot signal only and / or a proximity detection technique.
[0036] Otherwise, i.e. if the received at least one message does not correspond to the expected at least one message or the at least one derived channel feature does not correspond to the at least one expected channel feature, the first device is not triggered. This corresponds to the case that the at least one pilot signal is not transmitted directly from the second device.
[0037] In the method for triggering the first device, the first device can be the access device or the accessible device, while the second device is the other device. When the first device is the accessible device, all method steps (a) to (f) of the method according to the first aspect of the application can be performed on the accessible device. In this case, the triggering of the first device can directly lead to the accessing of the accessible device, or in other words, to the granting of access to the accessible device. For example, a lock of a vehicle as the accessible device can be unlocked after the vehicle has been triggered.
[0038] Generally, in the above case where the first device is the accessible device, a previous at least one pilot signal can have been transmitted from the accessible device to the second device as the access device. Only after the access device has recognized at least one message contained in the pilot signal as the at least one expected message, the access device will actually transmit back at least one pilot signal, which is then received by the accessible device as the first device. In turn, the accessible device as the first device performs the method steps (a) to (f) of the method of the first aspect of the application as explained above.
[0039] However, alternatively, the first device can be the access device. Then, all method steps (a) to (f) of the method of the first aspect of the application can be performed on the access device. In this case, the triggering of the first device can not directly lead to the accessing of the accessible device, or in other words, to the granting of access to the accessible device. Instead, the triggering of the first device can lead to the transmission of at least one pilot signal back to the accessible device as the second device. If the access device as the first device is not triggered, no pilot signal is transmitted back to the accessible device as the second device, and the accessible device can not be accessed. Thus, the triggering of the access device as the first device is only an intermediate step required for accessing the accessible device, but not the final step as it can be present when the accessible device is the first device.
[0040] Additionally, the method for triggering the first device can be performed continuously. First, the first device can be the access device, and then, the first device can be the accessible device. Thus, the security of the method for accessing the accessible device can be further improved. However, this also requires that both the access device and the accessible device are provided with the capability for extracting the channel state information, deriving at least one channel feature from the channel state information, and determining whether the at least one channel feature is the expected channel feature.
[0041] As will become apparent from the foregoing, the present application is not limited to the first device being a specific one of the access device and the accessible device, but the wording first device and second device is provided for distinguishing between the device on which the method steps (a) to (f) for triggering the method of the first device can be executed, i.e. the first device, and the second device which shall transmit the at least one pilot signal received by the at least one antenna of the first device. However, in case of a relay attack, the real at least one pilot signal can have been transmitted or forwarded by a relay station as explained previously.
[0042] The channel state information comprises channel characteristics, or in other words channel properties of the communication link, or in other words the communication channel of the communication link. The channel properties or characteristics are properties of the communication channel via which the pilot signal is transmitted or sent. The extraction, in particular the estimation, of such channel state information can be performed based on signals received over the communication channel. The channel state information describes how a signal propagates from a transmitter to a receiver. It can represent, for example, the combined effects of scattering, fading, and power decay with distance. The channel state information can be extracted or estimated at the receiver as the first device in the method according to the first aspect, while the second device acts as the transmitter in the method according to the first aspect. The extraction of the channel state information can be done in the frequency domain or in the time domain.
[0043] The at least one derived channel characteristic and / or the at least one expected channel characteristic can be modified by means of an analytical and / or statistical process. Additionally or alternatively, this can mean that the modification is performed in real time on the first device. Thus, the security can be further improved by a method which improves itself over time.
[0044] Machine learning, in particular deep learning, can be applied in the analytical and / or statistical process. For example, the machine learning can use the at least one derived channel characteristic and / or the at least one expected channel characteristic as input features and improve the process based on their specific values or their selection among several different channel characteristics. The output of such machine learning can be a correction of the specific value of the at least one expected channel characteristic or a different channel characteristic among several different channel characteristics which can be derived from the extracted channel state information can be used.
[0045] The first device can have two or more antennas. Additionally or alternatively, the second device can have two or more antennas. In the case where the first device has two antennas and the second device has one antenna, such a setup is commonly referred to as single-input multiple-output (SIMO) compared to a single-input single-output (SISO) setup, both of which can be implemented in the present invention. In the case where the second device has two antennas and the first device has one antenna, such a setup is commonly referred to as multiple-input single-output (MISO). MISO setups can also be implemented in the present invention. Thus, the method can be performed based on two or more received pilot signals. For example, when the first device has two antennas, these antennas act as receivers and receive two pilot signals from the second device acting as a transmitter. Channel state information extracted from two pilot signals is larger and allows more channel characteristics to be derived and compared. This can effectively improve security.
[0046] In particular, the first device can have two or more antennas and the second device can have two or more antennas, such that the method is performed based on at least four received pilot signals. In the case where the first device has two antennas and the second device has two antennas, such a setup is commonly referred to as multiple-input multiple-output (MIMO), which is a particularly preferred embodiment in the present invention. It enables channel state information to be extracted even better.
[0047] The channel state information can be extracted from the at least four received pilot signals as a channel matrix. Such a channel matrix can contain values describing all of the channel characteristics of each of the pilot signals.
[0048] The derived channel characteristic can be a determinant calculated from the extracted channel matrix. It has been found that the determinant of the channel matrix is a particular suitable channel characteristic to derive and compare to an expected determinant as an expected channel characteristic.
[0049] The expected channel characteristic can be any value of the determinant but substantially zero. Substantially zero includes zero and values close to zero due to additional noise. This means that the first device is not triggered when the determinant of the calculated determinant is substantially zero. Otherwise, the first device is triggered when the calculated determinant is any number other than substantially zero and the received at least one message is at least one expected message. Reference is made below to Figures 5 to 10 A specific example based on a MIMO setup is explained.
[0050] Alternatively, the at least one derived channel characteristic can be from an adjacent channel noise, a fading characteristic and / or any channel characteristic specific to a plurality of pilot signals (e.g. two, four or more pilot signals). In this case, not a combined value describing the overall channel characteristic is employed as in the case of the channel matrix, but rather one or more such channel characteristics, in particular their values, are derived and successively compared to the expected channel characteristic, in particular to the expected value of such an expected channel characteristic.
[0051] According to a second aspect of the present application, the initially stated object is solved by a method (in particular a computer-implemented method) for accessing an accessible device (in particular a vehicle). The method comprises the method (in particular the method steps) according to the first aspect of the present application. The method according to the second aspect of the present application further comprises the following steps:
[0052] - if the accessible device is the first device, accessing the accessible device after triggering the first device; or
[0053] - if the accessing device is the first device, sending at least one further pilot signal to the second device via at least one antenna of the first device after triggering the first device.
[0054] The method according to the second aspect of the present application is a method for accessing the accessible device, the method comprising the method for triggering the first device according to the first aspect of the present application. As previously explained, when the first device is the accessible device, the accessible device can be directly accessed after it is triggered. However, if the first device is the accessing device, a further pilot signal is sent to the accessible device as second device after triggering the accessing device.
[0055] The accessible device as second device can successively again become the first device in the sense of the method according to the first aspect of the present application, or in other words, the method according to the first aspect of the present application can successively (i.e. after performing the method according to the first aspect of the present application on the accessing device as first device) be performed on the accessible device as first device.
[0056] Thus, in case at least one further pilot signal is sent to the accessible device as second device, the method according to the second aspect of the present application can further comprise the following steps:
[0057] - receiving at least one further pilot signal on the second device via at least one antenna;
[0058] - determining whether at least one message contained in the received at least one further pilot signal corresponds to at least one expected message expected by the second device;
[0059] - extracting channel state information from the received at least one further pilot signal;
[0060] - deriving at least one channel feature from the extracted channel state information;
[0061] - determining whether the at least one derived channel feature corresponds to at least one channel feature expected by the second device; and
[0062] - accessing the accessible device if the received at least one message corresponds to the expected at least one message and the at least one derived channel feature corresponds to the at least one expected channel feature, and not accessing the accessible device otherwise.
[0063] Wherein also the features explained previously with respect to the method according to the first aspect of the application, in particular with respect to the channel state information and the channel feature, can be implemented.
[0064] The accessible device can be a vehicle, in particular a car. The access can be an unlocking of the vehicle, in particular a passive unlocking of the vehicle. Alternatively or additionally, the access can be a starting of an ignition of the vehicle.
[0065] According to a third aspect of the application, the initially stated object is achieved by a first device having at least one antenna for wireless communication with a second device having at least one antenna. The first device is an access device, in particular a remote key or a smart device, or an accessible device, in particular a vehicle. The first device comprises means configured to perform the method according to the first aspect of the application or the second aspect of the application.
[0066] In addition to the at least one antenna, the means of the first device can be a controller unit, in particular a controller unit of the at least one antenna, a memory unit, a computing unit, and an accessible unit.
[0067] According to a fourth aspect of the application, the initially stated object is achieved by a system having a second device and a first device according to the third aspect of the application.
[0068] Similar to the first device, the second device can comprise means configured to perform the method according to the first aspect of the application or the second aspect of the application. In addition to the at least one antenna, such means can be a controller unit, in particular a controller unit of the at least one antenna, a memory unit, and a computing unit.
[0069] According to a fifth aspect of the present application, the initially stated object is solved by a computer program product comprising instructions for causing the first device of the third aspect of the present application or the system of the fourth aspect of the present application to perform the method according to the first aspect of the present application or the second aspect of the present application.
[0070] According to a sixth aspect of the present application, the initially stated object is solved by a computer readable medium having stored thereon the computer program product according to the fifth aspect of the present application.
[0071] The computer readable medium can be a memory unit of the first device or the second device or any other unit capable of storing the computer program product such that the computer program product can be read by a computer.
[0072] Further advantages, features and details of the present application emerge from the following description, in which the present application is described according to one possible example with reference to the drawings in the following figures. Thus, features from the claims as well as features mentioned in the description (alone or in any combination) can be essential to the present application. BRIEF DESCRIPTION OF DRAWINGS
[0073] The present application is discussed in more detail below with reference to the drawings, in which:
[0074] Figure 1 is a schematic diagram of a keyless system according to the present application;
[0075] Figure 2 is a schematic diagram of a prior art method for a keyless system of Figure 1 ;
[0076] Figure 3 is a schematic diagram of a relay attack with one relay station in a keyless system of Figure 1 ;
[0077] Figure 4 is a schematic diagram of a relay attack with two relay stations in a keyless system of Figure 1 ;
[0078] Figure 5 is a schematic diagram of an exemplary method of the present application for a keyless system of Figure 1 ;
[0079] Figure 6 is a schematic diagram of an example of an accessible device in a keyless system of Figure 1 ;
[0080] Figure 7 is a schematic diagram of an example of an accessible device in a keyless system of Figure 1A schematic diagram illustrating an example of an access device in a keyless system;
[0081] Figure 8 for Figure 1 In keyless systems Figure 6 Accessible devices and Figure 7 A schematic diagram of the communication link between access devices;
[0082] Figure 9 for Figure 1 A keyless system with multiple transmitters and receivers Figure 6 Accessible devices and Figure 7 A schematic diagram of the communication link between access devices;
[0083] Figure 10 for Figure 6 Accessible devices and Figure 7 A schematic diagram of the communication link between access devices, wherein the communication link is as follows: Figure 3 The relay attack disruption shown has one relay station; and
[0084] Figure 11 for Figure 6 Accessible devices and Figure 7 Access between devices such as Figure 4 The diagram shows a communication link.
[0085] Through Figures 1 to 11 The same reference numerals are used for the same parts. Detailed Implementation
[0086] The introduction of this patent application discusses in detail... Figures 1 to 4 .
[0087] Figure 5 schematically shown Figure 1 The method 200 of the keyless system 1 according to the present invention operates to grant access to the accessible device 10 only to the legitimate owner 26 or the person with the original physical electronic access device 20. The method 200 of the present invention is similar to the prior art method in the first steps 201 to 208.
[0088] In the further examples discussed in this invention, the accessible device 10 is a vehicle 10, particularly a car 10. However, the accessible device 10 is not limited to a vehicle 10, but can be any other type, such as a car garage, a building door, or the like. For example, the access device 20 can be a remote key 20 or a smart device 20, such as a smartphone 20. However, the access device 20 is not limited to these examples, but can instead be any other type, such as a key card, smart card, smartwatch, or the like.
[0089] In a step 201 of the method 200, at least one antenna of the device 10 can emit a pilot signal. In order to emit at least one pilot signal, it can be necessary to touch a handle of the vehicle 10 or to perform another interaction with the vehicle 10.
[0090] The pilot signal can have a rather short range, for example 5 to 100 meters, in particular 10 to 50 meters. The short range of the at least one pilot signal or in other words of the communication link established between the vehicle 10 and the remote key 20 is preselected so that the vehicle 10 is accessed, for example unlocked, only when the vehicle owner 26 is in close proximity to the vehicle 10 so that it can be safely predicted that he will want to access the vehicle 10.
[0091] If the remote key 20 is not within the preselected range of the pilot signal, the remote key 20 cannot respond to the pilot signal emitted by the vehicle 10 and the method 200 is aborted in a step 202. However, it can be provided that the vehicle 10 repeats the step 201 periodically, i.e. emits a pilot signal every few milliseconds, without the need for an interaction with the vehicle 10.
[0092] As soon as the remote key 20 is within the proximity of the vehicle 10 matching the selected range of the pilot signal, the remote key 20 receives the pilot signal in a step 203. The pilot signal contains a unique message or key known only to the remote key 20 or identifiable by the remote key 20. In a step 204, the remote key 20 determines whether the message contained in the received pilot signal matches a saved or expected message. There are different methods known in the art that can be applied with respect to the content of the message, its identification and specific security features applicable to the content of the pilot signal, like encryption.
[0093] If this is not the case, the method 200 is aborted in a step 205. For example, a pilot signal from a different vehicle than the vehicle of the owner 26 can have been received and the pilot signal has a different message.
[0094] On the other hand, if the message contained in the at least one received pilot signal matches the expected message, a pilot signal from the remote key 20 is sent back to the vehicle 10 in a step 206. The pilot signal contains a unique message or key known only to the vehicle 10 or identifiable by the vehicle 10.
[0095] The vehicle 10 receives in step 207 the pilot signal transmitted from the remote key 20 and determines in step 208 whether the message contained in the pilot signal matches the expected message expected by the vehicle 10. If this is not the case, for example, a pilot signal of a remote key has been received from a remote key which is not the owner 26, the vehicle 10 does not grant access and the method 200 aborts in step 209. Otherwise, if the message contained in the received pilot signal and the expected message match, the vehicle 10 is not triggered in step 210 to grant access to the vehicle, but the vehicle 10, in particular a specific component or unit in the vehicle, such as a computing unit, extracts channel state information from the received at least one pilot signal.
[0096] In the following step 211, at least one channel feature is derived from the extracted channel state information. In step 212, the at least one derived channel feature is compared to at least one channel feature expected by the vehicle 10. If the at least one derived channel feature, e.g. its value, corresponds to the at least one expected channel feature, e.g. is within its expected value range, the method 200 proceeds to step 214. Otherwise, the method 200 aborts in step 213.
[0097] In step 214, the vehicle 10 is triggered to grant access to the vehicle 10 in step 215, which is performed after the vehicle 10 is triggered. For example, in step 215, a lock of the vehicle 10 can be unlocked or the ignition of the vehicle 10 can be started.
[0098] In addition or as an alternative to steps 210 to 212 in the accessible device 10, the method 200 can use the security features of steps 210 to 212 in the access device 20 before the at least one pilot signal is transmitted in step 206.
[0099] In the method 200 according to this example of the application, the digital processing of the at least one pilot signal by means of extracting channel state information, deriving at least one channel feature and comparing the at least one channel feature to at least one expected channel feature is a security feature designed to solve a relay attack. Reference is made to Figure 8 、 Figure 9 and Figure 10 Examples of such channel features and specific channel features which can be used are given.
[0100] In this example, the accessible device 10 and the access device 20 can have a structure or components as explained with reference to Figure 6 and Figure 7 .
[0101] Figure 6An example of a possible structure of the accessible device 10 is shown with two antennas 11, 12 and a controller unit 13 connected to the two antennas 11, 12. The controller unit 13 controls the pilot signals to be transmitted from and to be received by the antennas 11, 12. The controller unit 13 is connected to a memory unit 14 and a computing unit 15. The computing unit 15 is connected to an accessible unit 16, e.g. the ignition unit or the locking unit of the accessible device 10, when the accessible device 10 is designed as a vehicle.
[0102] Figure 7 An example of a possible structure of the accessible device 20 is shown, which is similar to the accessible device 10 of Figure 6 but without the accessible unit 16. The accessible device 20 has two antennas 21, 22 and a controller unit 23 with the same functions as in the accessible device 10. The controller unit 23 is connected to a memory unit 24 and a computing unit 25. The memory unit 24 and the computing unit 25 are connected to each other.
[0103] In both cases, the accessible device 10, the accessible device 20, the computing unit 15, 25 can be designed to perform the determination whether the at least one message contained in the received at least one pilot signal corresponds to the at least one expected message and / or whether the at least one derived channel characteristic corresponds to the at least one expected channel characteristic as explained before. To this end, the computing unit 15, 25 can execute a computer program product comprising instructions stored in the memory unit 14, 24. The memory unit 14, 24 can also store the at least one expected message and / or the at least one expected channel characteristic.
[0104] Turning to Figure 8 , a specific example of the steps 210 to 212 of the method 200 is explained. In this case, the antennas 21, 22 of the accessible device 20 act as transmitters. They transmit via the communication channels h11, h21, h12, h22 of the communication link 30 the pilot signals t1, t2 which are received by the antennas 11, 12 of the accessible device 10 as pilot signals r1, r2. As explained before, the case can additionally or alternatively be the opposite, such that the antennas 11, 12 of the accessible device 10 can transmit via the communication channels h11, h21, h12, h22 the pilot signals t1, t2 which are received by the antennas 21, 22 of the accessible device 20 as received pilot signals r1, r2.
[0105] In reference to Figure 5In step 210 of the method 200 of explanation, channel state information is extracted from the received pilot signals r1, r2 received via the communication channels h11, h21, h12, h22 of the communication link 30. The channel state information can be described in the form r1 = h11 x t1 + h12 x t2 and r2 = h21 x t1 + h22 x t2. Then, a channel matrix H is established, in which the reception vector r can be represented in the frequency domain as the product of the channel matrix H and the transmission vector t:
[0106]
[0107] or
[0108]
[0109] After that, in step 211, as a channel feature to be derived, the determinant of the channel matrix H is formed. The determinant of the channel matrix H for a MIMO setup (but other setups can be applied) is the determinant = det(H) = h11 x h22 - h12 x h21. .
[0110] It has been found that the determinant of such an antenna system, in particular of at least a 2x2 MIMO antenna system, has a determinant that has an arbitrary value. This means that when the access device 10 and the visited device 20 communicate with each other in a relay attack procedure without any interference by a relay station, the determinant has an arbitrary value.
[0111] Figure 9 Basically in an alternative embodiment of the keyless system of Figure 1 is shown Figure 8 In Figure 9 , the devices 10, 20 can be provided with several transmitters and receivers as indicated by t1... tm and r1... rn, and thus the devices 10, 20 can each have more than two antennas 11, 12, 21, 22.
[0112] Figure 10 and Figure 11 show the case of a communication link between the respective antennas 11, 12, 21, 22 of the devices 10, 20 with one relay station 50 or two relay stations 50, 51 that forward the pilot signals t1, t2 sent via the communication channels g1, g3 from the antennas 21, 22 of the visited device 20 in the course of the RSA. This corresponds to Figure 3 and Figure 4 schematic diagram.
[0113] In Figure 10In the case of one relay station 50, the pilot signals t1, t2 are transmitted via the communication channels g1, g3 of the first communication link 40 to the relay station 50, which performs the RSA and forwards (or relays) the pilot signals t1, t2 to the accessible device 10 via the communication channels g2, g4 of the second communication link 41 established between the relay station 50 and the accessible device 10.
[0114] In the case of one relay station 50, the pilot signals t1, t2 are transmitted via the communication channels g1, g3 of the first communication link 40 to the relay station 50, which performs the RSA and forwards (or relays) the pilot signals t1, t2 to the accessible device 10 via the communication channels g2, g4 of the second communication link 41 established between the relay station 50 and the accessible device 10. Figure 11 In the case of one relay station 50, the pilot signals t1, t2 are transmitted via the communication channels g1, g3 of the first communication link 40 to the relay station 50, which performs the RSA and forwards (or relays) the pilot signals t1, t2 to the accessible device 10 via the communication channels g2, g4 of the second communication link 41 established between the relay station 50 and the accessible device 10.
[0115] When performing the RSA, a gain is applied to the pilot signals. In other words, the pilot signals t1, t2 are amplified. In the case of two relay stations 50, 51, this happens twice (gains Ga and Gb).
[0116] When applying the method 200 of Figure 4 to a communication between the devices 10, 20 experiencing the RSA with one relay station 50 according to Figure 10 , in step 210 the channel matrix G is established, wherein the receive vector r in the frequency domain is:
[0117]
[0118] For a communication between the devices 10, 20 experiencing the RSA with two relay stations 50, 51 according to Figure 11 , in step 210 the channel matrix G is established, wherein the receive vector r in the frequency domain is:
[0119]
[0120] For both cases of the RSA, the channel matrix G is the same.
[0121] The determinant of the channel matrix G calculated in step 211 is the determinant . Thus, the value of the determinant is zero or substantially zero due to noise but not an arbitrary value.
[0122] Therefore, step 212 in the method 200 is performed based on the expected channel characteristics with an arbitrary value or in other words not zero of the determinant.
[0123] Thus, when RSA occurs, the method 200 will abort in step 213 and only continue to access the accessible device 10 if the value of the determinant is substantially non-zero.
[0124] If the devices 10 and 20 are within a predetermined range of each other based on the communication link 30 without RSA, a communication link 30 without RSA with the communication channels h11, h21, h12, h22 can be established in addition to the communication links 40, 41, 42, 43, 44 with RSA or established due to RSA. If the pilot signals t1, t2 are strong enough, the pilot signals t1, t2 can then be received by the accessible device 10. The pilot signals t1, t2 received on the accessible device 10 via the communication link 30 can then be superimposed with the pilot signals t1, t2 received on the accessible device 10 via the communication links 41, 44 with RSA. If the distance is large or the pilot signals t1, t2 received on the accessible device 10 via the communication link 30 are blocked by elements in between (e.g. concrete of a parking garage), the pilot signals t1, t2 received on the accessible device 10 via the communication link 30 can be negligible. In any case, the pilot signals t1, t2 relayed via the communication links 40, 41, 42, 43, 44 with RSA can be determined due to their channel state information not matching the expected channel state information as described above and thus the method 200 is performed independently whether or not a communication link 30 without RSA is established.
[0125] As previously explained, the antenna system is not limited to the explained 2x2 system or the example of the determinant of the channel matrix as a channel characteristic. The system can be any nxn or n x m system, where n and m are equal to or larger than 1.
[0126] Furthermore, in general, the proposed technology can be applied at different frequencies within the same frequency band and / or different frequency bands. Furthermore, different wireless technologies like wireless LAN, Bluetooth, Ultra Wide Band or other technologies can be used for the communication between the devices 10, 20.
[0127] Reference signs
[0128] 1 System 10 Accessible device, vehicle 11、12、21、22 Antenna 13、23 Controller unit 14、24 Memory unit 15、25 Computing unit 16 Accessible unit 20 Access device, remote key, smart device 26 Owner 30 Communication link without RSA 40、41、42、43、44、45 Communication link with RSA 50、51 Relay station 52、53 Attacker 100 Prior art method 101……111 Steps of prior art method 200 Method according to example of the invention 201……215 Steps of method according to example of the invention h Communication channel g Communication channel t Transmitted pilot signal r Received pilot signal
Claims
1. A method for triggering a first device, - The first device has at least one antenna (11, 12, 21, 22) for wireless communication with a second device having at least one antenna (11, 12, 21, 22). - The first device is an accessible device (10), or the first device is an access device (20); - The second device is another of the accessible device (10) and the access device (20), and - The first device is triggered as a step required to access the accessible device (10), wherein the method includes the following steps: (a) Receive at least one pilot signal (t, r) on the first device via the at least one antenna (11, 12, 21, 22). (b) Determine whether at least one message contained in at least one received pilot signal (t, r) corresponds to at least one expected message anticipated by the first device; (c) Extract channel state information from at least one received pilot signal (t, r); (d) Derive at least one channel feature from the extracted channel state information; (e) Determine whether at least one derived channel feature corresponds to at least one channel feature expected by the first device; as well as (f) If the received at least one message corresponds to the expected at least one message and the at least one derived channel feature corresponds to at least one expected channel feature, then the first device is triggered; otherwise, the first device is not triggered. The first device has two or more antennas (11, 12, 21, 22), and the second device has two or more antennas (11, 12, 21, 22) to enable the method to be performed based on at least four received pilot signals (t, r). Specifically, the channel state information is extracted from the at least four received pilot signals (t, r) to form a channel matrix. The derived channel features are the determinants calculated from the extracted channel matrix.
2. The method according to claim 1, wherein, The at least one derived channel feature and / or the at least one expected channel feature are modified by means of analysis and / or statistical processes.
3. The method according to claim 2, wherein, Machine learning is applied in the analytical and / or statistical processes.
4. The method according to any one of claims 1 to 3, wherein, The accessible device is a vehicle, and / or the access device is a remote key or a smart device.
5. The method according to claim 3, wherein, Deep learning is applied in the analysis and / or statistical processes.
6. The method according to any one of claims 1 to 3, wherein, The expected channel characteristics are any value of the determinant, but approximately zero.
7. The method according to any one of claims 1 to 3, wherein, At least one additional channel feature is derived from the extracted channel state information, and the derived additional channel feature is derived from adjacent channel noise, fading characteristics and / or any channel feature specific to multiple pilot signals.
8. A method for accessing an accessible device (10), wherein, The method comprises the method according to any one of claims 1 to 7, plus the following additional steps: -If the accessible device (10) is the first device, then access the accessible device (10) after triggering the first device, or - If the access device (20) is the first device, then after the first device is triggered, at least one additional pilot signal (t, r) is sent to the second device via the at least one antenna (11, 12, 21, 22) of the first device.
9. The method according to claim 8, wherein, The accessible device (10) is a vehicle, and the access is the unlocking of the vehicle and / or the starting of the vehicle's ignition.
10. The method according to claim 9, wherein, The access refers to the passive unlocking of the vehicle.
11. A first device having at least one antenna (11, 12, 21, 22) for wirelessly communicating with a second device having at least one antenna (11, 12, 21, 22), the first device being an access device (20) or an accessible device (10), wherein the first device includes means configured to perform the method according to any one of claims 1 to 10.
12. A system (1) having a second device and a first device according to claim 11.
13. A computer program product comprising instructions for causing the first device according to claim 11 or the system according to claim 12 to perform the method according to any one of claims 1 to 10.
14. A computer-readable medium having a computer program product according to claim 13 stored thereon.
Citation Information
Patent Citations
Radio field-based authentication of nodes within a radio link
DE102017011879A1
Radio communication device, radio communication system, and radio communication method
WO2009144868A1
A key fob, a remote keyless entry system and a method of using a remote keyless entry system
WO2019092051A1