Improved security in ultra wide band ranging systems
By employing signal processing, encryption, and AI algorithms in the UWB ranging system, and dynamically adjusting system parameters, the problem of inaccurate distance measurement caused by ghost peak attacks was solved, ensuring the security and reliability of the system and preventing unauthorized access.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GM GLOBAL TECHNOLOGY OPERATIONS LLC
- Filing Date
- 2024-12-23
- Publication Date
- 2026-04-28
AI Technical Summary
Ultra-wideband (UWB) ranging systems are vulnerable to ghost peak attacks, which can lead to inaccurate distance measurements, unauthorized access, and device interference, affecting vehicle safety and reliability.
By employing robust signal processing algorithms, encryption technologies, and physical countermeasures, combined with AI algorithms to proactively identify and mitigate ghost peak attacks, and by learning signal shape and environmental interference levels, the system parameters are dynamically adjusted to ensure the accuracy and integrity of distance measurements.
Effectively prevent Ghost Peak attacks, ensure the security and reliability of UWB ranging systems, prevent unauthorized access, improve system resilience and adaptability to the ever-changing threat environment.
Smart Images

Figure CN121940410A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to computer network security, and more specifically to secure ranging techniques. More specifically, aspects of this disclosure relate to systems, methods, and apparatus for proactively identifying and mitigating potential range reduction attacks against ranging protocols using ultra-wideband (UWB). Background Technology
[0002] The increasing complexity and connectivity of modern vehicles have heightened the need to protect them against electronic attacks. The proliferation of features such as infotainment systems, telematics, and autonomous driving capabilities has expanded the attack surface, creating new opportunities for malicious actors. Furthermore, reliance on complex embedded systems and software can introduce vulnerabilities that attackers can exploit. Weak security measures, component sharing, a lack of cybersecurity awareness within the automotive industry, and regulatory challenges further exacerbate the risk of electronic attacks on modern vehicles.
[0003] Ghost peak attacks and other ranging system attacks pose a significant security challenge to ultra-wideband (UWB) ranging systems. These attacks exploit the unique characteristics of UWB signals—their wide bandwidth and short pulse duration—to inject false signals, or "ghost peaks," into communication channels. This manipulation can lead to inaccurate distance measurements, potentially jeopardizing the security and reliability of the system. Ghost peak attacks can have devastating consequences, including unauthorized access to restricted areas or equipment, location spoofing, and interference with other devices that rely on UWB signals. Malicious actors can use inaccurate distance measurements to access secure areas or equipment that are normally restricted to authorized personnel, or to manipulate location information provided by UWB ranging systems. This can lead to a variety of harmful consequences, such as inaccurate navigation, tracking errors, and even personal injury. Furthermore, ghost peak attacks can disrupt the operation of other devices that use UWB signals, such as radar systems, wireless communication networks, and medical devices. This can have serious consequences for insurance, security, and economic activities.
[0004] To mitigate the risks associated with ghost peak attacks, UWB ranging systems typically employ a combination of robust signal processing algorithms, encryption techniques, and physical countermeasures. Advanced signal processing techniques help identify and filter spoofed signals, improving the accuracy and reliability of distance measurements. Encryption methods protect the integrity and confidentiality of UWB communications, making it more difficult for attackers to inject spoofed signals. Physical measures such as shielding, antenna diversity, and frequency hopping can also be used to reduce the vulnerability of UWB systems to ghost peak attacks.
[0005] Accordingly, it is desirable to provide systems, methods, and mechanisms for proactively identifying and mitigating potential range reduction attacks on UWB ranging. More precisely, it is desirable to provide mechanisms for access control, data integrity and source authentication, denial-of-service prevention, and the efficient implementation of these mechanisms using hardware. Furthermore, other desirable features and characteristics of this disclosure will become apparent from the accompanying drawings and the foregoing technical and background information, based on the following detailed description and the appended claims. Summary of the Invention
[0006] This document discloses vehicle control systems and methods for deploying vehicle safety systems, along with related control logic; methods for manufacturing such systems; methods for operating such systems; and vehicles equipped with distributed computing systems. Various embodiments of the system disclosed herein for providing a secure UWB ranging system in a motor vehicle data communication system are presented by way of example and not limitation.
[0007] According to one aspect of an exemplary embodiment, a method for determining a distance between a transmitter and a receiver includes: storing first data in a memory indicating characteristics of an expected peak; receiving a data sequence including a first peak and a second peak by a receiver; authenticating the data sequence by a processor in response to second data received in the second peak; determining the distance between the transmitter and the receiver by the processor in response to a difference between a first reception time of the first peak and a second reception time of the second peak, wherein the determination of the distance is initiated in response to the first peak matching the expected peak; and enabling a vehicle control algorithm by a vehicle controller in response to the distance.
[0008] According to another aspect of the exemplary embodiment, in response to a first peak not matching an expected peak, the search time interval for detecting a subsequent first peak is reduced.
[0009] According to another aspect of the exemplary embodiment, the first peak and the second peak are part of a pseudo-random spread spectrum time jump sequence.
[0010] According to another aspect of the exemplary embodiment, the vehicle control algorithm includes unlocking the vehicle and transitioning the vehicle between a standby state and an on state.
[0011] According to another aspect of the exemplary embodiment, in response to a first peak mismatch with an expected peak, the search time interval for detecting a subsequent first peak is reduced, and the duration of the search time interval is determined in response to vehicle location, vehicle environment, weather conditions, user habits, and potential risk level.
[0012] According to another aspect of the exemplary embodiment, in response to a first peak mismatch with an expected peak, the search time interval for detecting a subsequent first peak is reduced, and the duration of the search time interval is determined in response to a multipath level estimated in response to reflections of signals transmitted and detected by the vehicle communication system.
[0013] According to another aspect of the exemplary embodiment, in response to a first peak mismatch with an expected peak, the search time interval for detecting a subsequent first peak is reduced, and the duration of the search time interval is reduced in response to the length of the pseudo-random spread spectrum time-jump sequence preamble in the time domain.
[0014] According to another aspect of the exemplary embodiment, in response to the first peak not matching the expected peak, the first peak is rejected, and a subsequent peak is detected between the first peak and the second peak, wherein the subsequent peak is then compared with the expected peak.
[0015] According to another aspect of the exemplary embodiment, the power difference between the first peak and the second peak is used to compare the first peak with the expected peak.
[0016] According to another aspect of an exemplary embodiment, an apparatus for determining the distance between a transmitter and a receiver includes: a memory configured to store first data indicating a characteristic of an expected peak; a receiver configured to receive from the transmitter a data sequence including a first peak and a second peak; a processor configured to authenticate the data sequence in response to second data received in the second peak, to determine the distance between the transmitter and the receiver in response to a difference between a first reception time of the first peak and a second reception time of the second peak, wherein the determination of the distance is initiated in response to the first peak matching the expected peak, and to generate a control signal in response to the distance; and a vehicle controller configured to enable a vehicle control algorithm in response to the control signal.
[0017] According to another aspect of the exemplary embodiment, the processor is further configured to: reduce the search time interval for detecting a subsequent first peak in response to a first peak not matching an expected peak.
[0018] According to another aspect of the exemplary embodiment, the processor is further configured to: reduce the search time interval for detecting a subsequent first peak in response to a first peak not matching an expected peak, and wherein the duration of the search time interval is determined in response to vehicle location, vehicle environment, weather conditions, user habits, and potential risk level.
[0019] According to another aspect of the exemplary embodiment, the processor is further configured to: reduce the search time interval for detecting a subsequent first peak in response to a first peak mismatch with an expected peak, and wherein the duration of the search time interval is determined in response to a multipath level estimated in response to reflections of signals transmitted and detected by the vehicle communication system.
[0020] According to another aspect of the exemplary embodiment, the processor is further configured to: reduce the search time interval for detecting a subsequent first peak in response to a first peak mismatch with an expected peak, and wherein the duration of the search time interval is reduced in response to the length of the pseudo-random spread spectrum time-jump sequence preamble in the time domain.
[0021] According to another aspect of the exemplary embodiment, in response to the first peak not matching the expected peak, the first peak is rejected, and a subsequent peak is detected between the first peak and the second peak, wherein the subsequent peak is then compared with the expected peak.
[0022] According to another aspect of the exemplary embodiment, the power difference between the first peak and the second peak is used to compare the first peak with the expected peak.
[0023] According to another aspect of the exemplary embodiment, the first peak and the second peak are part of a pseudo-random spread spectrum time jump sequence.
[0024] According to another aspect of the exemplary embodiment, the vehicle control algorithm includes unlocking the vehicle and transitioning the vehicle between a standby state and an on state.
[0025] According to another aspect of an exemplary embodiment, a vehicle communication system includes: a transmitter having a first memory for storing a shared key and for transmitting a pseudo-random spread spectrum time-jump sequence including a first peak and a second peak, wherein the second peak is generated in response to the shared key; a second memory for storing first data indicating a plurality of characteristics of an expected peak, wherein the plurality of characteristics include a time difference between the first peak and the second peak, a first power difference between the first peak and the second peak, and a second power difference between the leading edge of the first peak and a noise threshold; a receiver for receiving the pseudo-random spread spectrum time-jump sequence including the first peak and the second peak; a processor configured to authenticate the pseudo-random spread spectrum time-jump sequence in response to the second peak and the shared key, and to determine a distance between the transmitter and the vehicle communication system in response to a difference between a first reception time of the first peak and a second reception time of the second peak, wherein the distance determination is initiated in response to the first peak matching the expected peak; and a vehicle controller configured to enable a vehicle control algorithm in response to the distance, and to control a vehicle in response to the vehicle control algorithm.
[0026] According to another aspect of the exemplary embodiment, in response to a first peak mismatch with an expected peak, the search time interval for detecting a subsequent first peak is reduced, and the duration of the search time interval is determined in response to vehicle location, vehicle environment, weather conditions, user habits, potential risk level, length of the pseudo-random spread spectrum time jump sequence preamble in the time domain, and multipath level, which is estimated in response to reflections of signals transmitted and detected by the vehicle communication system. Attached Figure Description
[0027] The present disclosure will be described below with reference to the following figures, wherein the same numerals denote the same elements, and wherein:
[0028] Figure 1 This is a functional block diagram of a vehicle according to an embodiment of the present disclosure, the vehicle including an exemplary system for providing a safe UWB ranging system and a motor vehicle data communication system;
[0029] Figure 2 The figure shows a block diagram illustrating an exemplary implementation of a system for providing a secure UWB ranging system and a motor vehicle data communication system, according to an exemplary embodiment of the present disclosure.
[0030] Figure 3 The figure illustrates an exemplary functional block diagram of a system for providing a secure UWB ranging system and a vehicle data communication system in a motor vehicle according to embodiments of the present disclosure; and
[0031] Figure 4 The diagram illustrates an exemplary implementation of a method for providing a secure UWB ranging system and a motor vehicle data communication system, according to embodiments of the present disclosure. Detailed Implementation
[0032] The following detailed description is merely exemplary in nature and is not intended to limit this disclosure or its application and use. Furthermore, it is not intended to be bound by the foregoing background information or any theories set forth in the following detailed description.
[0033] In motor vehicle applications, where malicious actors attempt to access wireless vehicle communication and security systems, UWB ranging can be used to accurately determine the distance between objects such as vehicles and transmitters. For example, UWB ranging can be used to detect the distance between a vehicle and a key fob used to unlock and start the vehicle. Ghost peak attacks can exploit the unique characteristics of UWB signals; malicious actors can inject spoofed signals or "ghost peaks" into the communication channel, leading to inaccurate distance measurements. This can compromise system security and reliability, potentially resulting in unauthorized access to restricted areas, location spoofing, and interference with other UWB-based devices. To mitigate these risks, UWB ranging systems typically employ a combination of robust signal processing algorithms, encryption techniques, and physical countermeasures to identify and filter spoofed signals, protect communication integrity, and reduce vulnerability to ghost peak attacks.
[0034] Turn now Figure 1 According to various embodiments, an exemplary system 100 for providing a secure UWB ranging system and a motor vehicle data communication system is shown. The exemplary system 100 includes a vehicle 10 having a plurality of sensing devices 40a-40n, a propulsion system 20, a transmission system 22, a steering system 24, a braking system 26, a sensor system 28, an actuator system 30, at least one data storage device 32, at least one controller 34, and a communication system 36.
[0035] like Figure 1 The vehicle 10 depicted typically includes a chassis 12, a body 14, front wheels 16, and rear wheels 18. The body 14 is mounted on the chassis 12 and substantially surrounds the components of the vehicle 10. The body 14 and the chassis 12 may together form a frame. The wheels 16-18 are each rotatably coupled to the chassis 12 near a corresponding corner of the body 14.
[0036] In various embodiments, vehicle 10 is an autonomous vehicle, and control system 100 is incorporated into autonomous vehicle 10 (hereinafter referred to as autonomous vehicle 10). Autonomous vehicle 10 is, for example, a vehicle automatically controlled to transport passengers from one location to another. Vehicle 10 is depicted as a passenger car in the illustrated embodiment, but it should be understood that any other means of transportation may also be used, including motorcycles, trucks, sport utility vehicles (SUVs), recreational vehicles (RVs), boats, aircraft, etc. In exemplary embodiments, autonomous vehicle 10 is a so-called Level 4 or Level 5 automation system. Level 4 system indicates “high automation,” referring to the driving mode-specific performance of the automated driving system for all aspects of a dynamic driving task, even if the human driver does not properly respond to intervention requests. Level 5 system indicates “full automation,” referring to the full-time performance of the automated driving system for all aspects of a dynamic driving task under all roadway and environmental conditions manageable by a human driver. It is understood that in various embodiments, vehicle 10 may be a non-autonomous vehicle and is not limited to this example.
[0037] As shown in the figure, vehicle 10 typically includes a propulsion system 20, a transmission system 22, a steering system 24, a braking system 26, a sensor system 28, an actuator system 30, at least one data storage device 32, at least one controller 34, and a communication system 36. In various embodiments, the propulsion system 20 may include an internal combustion engine, an electric motor such as a traction motor, and / or a fuel cell propulsion system. The transmission system 22 is configured to transmit power from the propulsion system 20 to the wheels 16-18 according to a selectable speed ratio. According to various embodiments, the transmission system 22 may include a step-ratio automatic transmission, a continuously variable transmission (CVT), or other suitable transmissions. The braking system 26 is configured to provide braking torque to the wheels 16-18. In various embodiments, the braking system 26 may include friction brakes, brake-by-wire brakes, regenerative braking systems such as electric motors, and / or other suitable braking systems. The steering system 24 influences the position of the wheels 16-18. Although depicted as including a steering wheel for illustrative purposes, in some embodiments contemplated within the scope of this disclosure, the steering system 24 may not include a steering wheel.
[0038] The sensor system 28 includes one or more sensing devices 40a-40n that sense observable conditions of the external and / or internal environments of the autonomous vehicle 10. The sensing devices 40a-40n may include, but are not limited to, radar, lidar, global positioning system, optical camera, thermal imager, ultrasonic sensor, and / or other sensors.
[0039] In various embodiments, sensing devices 40a-40n are disposed at different locations on vehicle 10. In the exemplary embodiments described herein, one or more of sensing devices 40-40n are implemented as lidar devices. In this regard, each of sensing devices 40a-40n may include or incorporate one or more lasers, scanning components, optical arrangements, photodetectors, and other components suitably configured to scan the environment near vehicle 10 horizontally and rotatably at a specific angular frequency or rotational rate. In the exemplary embodiments described herein, one or more of sensing devices 40a-40n are implemented as optical cameras configured to capture images of the environment near vehicle 10.
[0040] Actuator system 30 includes one or more actuator devices 42a-42n that control one or more vehicle features, such as, but not limited to, propulsion system 20, transmission system 22, steering system 24, and braking system 26. In various embodiments, vehicle features may also include interior and / or exterior vehicle features, such as, but not limited to, doors, trunk, and cabin features, such as air, music, lighting, etc. (not numbered).
[0041] Still referencing Figure 1 In an exemplary embodiment, communication system 36 is configured to wirelessly communicate information to and from other entities 48 (such as, but not limited to, other vehicles (“V2V” communication), infrastructure (“V2I” communication), remote systems, personal devices, and / or calibration stations). In an exemplary embodiment, communication system 36 is a wireless communication system configured to communicate via a wireless local area network (WLAN) using the IEEE 802.11 standard or by using cellular data communication. However, additional or alternative communication methods (such as dedicated short-range communication (DSRC) channels) are also considered within the scope of this disclosure. A DSRC channel refers to a one-way or two-way short-to-medium-range wireless communication channel specifically designed for automotive use and corresponding set of protocols and standards.
[0042] Data storage device 32 stores data for automatically controlling the autonomous vehicle 10. In various embodiments, data storage device 32 stores a defined map of the navigable environment. In various embodiments, the defined map may be predefined by and obtained from a remote system. For example, the defined map may be assembled by a remote system and communicated to the autonomous vehicle 10 (wirelessly and / or via wire) and stored in data storage device 32. In various embodiments, data storage device 32 stores calibration data for aligning the sensing devices 40a-40n. In various embodiments, using the methods and systems described herein, one or more of the calibration data are estimated as extrinsic parameters. It is understood that data storage device 32 may be part of controller 34, separate from controller 34, or part of controller 34 and a separate system.
[0043] The controller 34 includes at least one processor 44 and a computer-readable storage device or medium 46. The processor 44 may be any custom or commercially available processor, central processing unit (CPU), graphics processing unit (GPU), auxiliary processor among several processors associated with the controller 34, semiconductor-based microprocessor (in the form of a microchip or chipset), macroprocessor, any combination thereof, or any device generally used for executing instructions. The computer-readable storage device or medium 46 may include volatile and non-volatile memory such as read-only memory (ROM), random access memory (RAM), and keep-alive memory (KAM). KAM is a persistent or non-volatile memory that can be used to store various operational variables when the processor 44 is powered off. The computer-readable storage device or medium 46 may be implemented using any of several known memory devices such as PROM (programmable read-only memory), EPROM (electrical PROM), EEPROM (electrically erasable PROM), flash memory, or any other electrical, magnetic, optical, or combined memory device capable of storing data (some of which represent executable instructions used by the controller 34 to control the autonomous vehicle 10).
[0044] The instructions may include one or more separate programs, each comprising an ordered list of executable instructions for implementing logical functions. When executed by processor 44, the instructions receive and process signals from sensor system 28, execute logic, calculations, methods, and / or algorithms for automatically controlling components of autonomous vehicle 10, and generate control signals to actuator system 30 based on the logic, calculations, methods, and / or algorithms to automatically control components of autonomous vehicle 10. Although in Figure 1 Only one controller 34 is shown, but embodiments of the autonomous vehicle 10 may include any number of controllers 34 that communicate via any suitable communication medium or combination of communication media and cooperate to process sensor signals, perform logic, calculations, methods and / or algorithms, and generate control signals to automatically control the features of the autonomous vehicle 10. In various embodiments, as described in more detail below, one or more instructions of the controller 34 are embodied in the control system 100 and, when executed by the processor 44, cause the processor 44 to perform methods and systems for dynamically aligning sensor devices by updating calibration data stored in the data storage device 32.
[0045] According to various embodiments, controller 34 implements an autonomous driving system (ADS). The software and / or hardware components of controller 34 (e.g., processor 44 and computer-readable storage device 46) are used to provide an autonomous driving system for use with vehicle 10, for example, to automatically control various actuators 30 on vehicle 10, thereby controlling vehicle acceleration, steering and braking respectively, without human intervention.
[0046] In various embodiments, the instructions of the autonomous driving system 70 may be organized by function or system. For example, the autonomous driving system may include a computer vision system, a positioning system, a guidance system 78, and a vehicle control system 80. It will be understood that in various embodiments, the instructions may be organized into any number of systems (e.g., combined, further divided, etc.), as this disclosure is not limited to this example.
[0047] In various embodiments, the computer vision system 74 synthesizes and processes sensor data and predicts the presence, location, classification, and / or path of objects and features in the environment of the vehicle 10. In various embodiments, the computer vision system 74 may combine information from multiple sensors (including, but not limited to, cameras, lidar, radar, and / or any number of other types of sensors). In various embodiments, the computer vision system 74 receives information from and / or implements the control system 100 described herein.
[0048] The positioning system 76 processes sensor data and other data to determine the position of the vehicle 10 relative to its environment (e.g., local position relative to a map, precise position relative to a road lane, vehicle heading, speed, etc.). The guidance system 78 processes sensor data and other data to determine a path for the vehicle 10 to follow. The vehicle control system 80 generates control signals for controlling the vehicle 10 based on the determined path.
[0049] In various embodiments, the controller 34 implements machine learning techniques to assist the functions of the controller 34, such as feature detection / classification, obstacle mitigation, route traversal, mapping, sensor integration, and ground condition determination.
[0050] According to certain exemplary embodiments, the control system, generally shown as 100, is associated with vehicle 10. Typically, the control system 100 selectively aligns two sensors of vehicle 10 by estimating external parameters. As will be discussed in more detail, this estimation is based on a method that utilizes a mathematical optimization problem given a set of LiDAR-camera control points with highly flexible 3D-2D correspondence requirements. In various embodiments, the two sensors include a LiDAR sensor and a camera sensor. It will be understood that other sensors may be implemented in various embodiments.
[0051] According to certain exemplary embodiments, a plurality of sensing devices 40a-40n, a propulsion system 20, a transmission system 22, a steering system 24, a braking system 26, a sensor system 28, an actuator system 30, at least one data storage device 32, at least one controller 34, and a communication system 36 are communicatively coupled to transmit data between each other.
[0052] Turn now Figure 2 The diagram illustrates an exemplary implementation of a secure UWB ranging system 200 and a vehicle data communication system. The exemplary UWB system 200 may include an antenna 215, a transceiver 210, a UWB demodulator / modulator 220, a processor 230, and a vehicle controller 240. In some exemplary embodiments, the antenna 215 may be an antenna array, etc. In some exemplary embodiments, a UWB anchor is a fixed device that uses multiple antennas to locate other UWB devices (referred to as tags). The exemplary UWB system 200 can be used to proactively identify and mitigate potential HRP UWB distance reduction attacks (such as ghost peak attacks) by learning characteristic signal shapes, power distributions, and interference levels associated with various environmental conditions, including open sky and enclosed space environments, weather patterns, and individual user behavior, to detect anomalies deviating from expected patterns, thereby indicating potential distance reduction attacks. While this description is within the context of automotive applications, secure ranging and distance reduction attacks can be applied to other domains, such as smart homes, where certain functions are activated based on proximity, for example, to unlock front or garage doors, or to turn on air conditioning or lights, or even to locate lost / misplaced electronic devices within a house or building. The mitigations presented in this disclosure relate to UWB-based ranging, regardless of whether the application is automotive or non-automotive. Low-rate pulse repetition frequency (LRP) can also be vulnerable to ghost peak attacks under certain conditions, although LRP generally offers more security protection than HRP. In this regard, the mitigations described herein primarily focus on the less secure HRP in the context of vehicle access applications, but they can also be applied to LRP.
[0053] UWB signals can be transmitted and received via transmitter 205 (such as a key fob or mobile device). Due to its high data rate, low power consumption, and ability to penetrate obstacles, UWB has become a popular choice for vehicle key fob and mobile phone security applications. However, UWB is vulnerable to distance reduction attacks, a security threat specifically targeting UWB communication systems. By intercepting and manipulating transmitted UWB signals, malicious actors can introduce delays, causing receivers to miscalculate the distance between themselves and the transmitter, potentially leading to unauthorized access to restricted areas or devices, and other potential security consequences.
[0054] In the UWB system 200, transmitting devices (such as transmitter 205 or transceiver 210 in vehicle 212) can generate short, wide-spectrum pulses several times per second to conserve battery power and reduce interference with other devices. The pulses travel through the air and reach antenna 215 on vehicle 212. The received signal can then be amplified, filtered, and demodulated to extract the transmitted data. The system can accurately measure the propagation time required for the signal to travel from the key fob to the vehicle. This information is used to calculate the distance between the two devices.
[0055] To determine the propagation time, transmitter 205 first generates a scrambled timestamp sequence (STS) based on a shared key in a specific time slot. This STS is used to verify the transmitter's identity and prevent unauthorized access. The STS is an encrypted sequence that ensures the accuracy and integrity of the ranging measurement timestamp. It is a key feature of the IEEE 802.15.4z standard, enhancing data integrity and providing resilience against UWB ranging attacks. UWB frame transmission can be performed on a set of channels used by the transmitter and receiver according to a pseudo-random hopping sequence. Typically, once authentication is successful, transmitter 205 is authorized to unlock vehicle 212 or perform other functions. The STS sequence includes code used in spread spectrum communication systems, involving pseudo-random hopping of narrowband signals over a wide frequency range to improve resistance to interference and interference. The UWB signal may include a front peak 209 and a middle peak 208. The front peak 209 is used for acquisition and synchronization. The front peak 209 is used to establish a timing reference for the receiver, allowing it to accurately decode the incoming signal, and can also be used for ranging to determine the distance between the transmitter and receiver. Figure 2 The Y-axis in the graph corresponds to the cross-correlation between the received and expected signals. Mid-peak 208 (highest peak) corresponds to the cross-correlation of the signal obtained from multipath reflections. Leading peak 209 corresponds to the cross-correlation of the signal obtained from the direct path. This is also the peak related to ranging, as time of flight is measured via the direct path. The mid-peak carries the transmitted data and is modulated to carry it. Common modulation techniques include peak-amplitude modulation (PAM) and peak-position modulation (PPM).
[0056] In the UWB ranging system 200, once the maximum peak from the multipath signal is detected, the receiver uses a reverse search window to find the smaller leading-edge peak that corresponds to the direct path. Once the smaller leading-edge peak is found, its position on the time axis provides a timestamp that can be used to estimate the time of flight and thus the distance. The preamble is a specific sequence of peaks or symbols preceding the actual data transmission. Its primary purpose is to establish synchronization and estimate transmission channel characteristics, such as attenuation and multipath effects. The leading peak 209 is typically the first peak or symbol within the preamble. It serves as a strong reference signal for the receiver to detect the presence of the signal and to estimate the timing offset between the local clock and the incoming signal. The middle peak 208 is typically the peak or symbol within the preamble following the leading peak 209. The middle peak 208 can be used to provide additional information about channel characteristics (especially for multipath channels) and for fine-tuning timing synchronization. The preamble, leading peak 209, and middle peak 208 work together to ensure accurate ranging in the UWB system. By establishing synchronization, estimating channel characteristics, and acquiring the signal, these components enable the receiver to accurately measure the time of flight and determine the distance to the transmitter.
[0057] For ranging, UWB demodulator 220 operates to demodulate mid-peak 208 to verify the identity of transmitter 205. Subsequently, processor 230 can perform a reverse search of the received signal history within a search window to determine the time interval between mid-peak 208 and preceding peak 209. This time interval is used to determine the distance between transmitter 205 and vehicle 212, where an earlier arrival time indicates a shorter distance between transmitter 205 and vehicle 212.
[0058] In a spectral attack, a malicious actor sends a UWB signal that causes a spectral peak 206 (on the cross-correlation axis) earlier than the legitimate peak 209. If spectral peak 206 is within the search window, the vulnerable system may confuse it with the preceding peak 209. Because this spectral peak 206 is sent earlier than the preceding peak 209, the vulnerable system will use spectral peak 206 to determine the distance from transmitter 205 to vehicle 212, and assume that transmitter 205 is closer to vehicle 212 than the actual transmitter 205. Subsequently, this determined proximity may allow the vulnerable system to allow the vehicle to be unlocked or other security actions to be performed.
[0059] To enhance the resilience of UWB systems against Spectral attacks, Exemplary System 200 can be configured to employ innovative AI algorithms to proactively identify, detect, and mitigate potential HRP UWB distance reduction attacks, including Spectral Peak attacks. By analyzing received signals, the algorithm learns the expected signal shape, power patterns, and interference levels associated with various factors, including location, weather conditions, and individual user behavior. The algorithm then detects deviations from these expected patterns, flagging any discrepancies that may indicate an attack. Key parameters examined include the time and power difference between the peak value and the leading edge, and the power difference between the leading edge and a noise threshold. Any significant deviation from established specifications triggers a security alert, indicating a potential distance reduction attack. This advanced approach ensures robust security and protects against the evolving threats posed by such attacks.
[0060] Security tagging initiates an algorithmic proactive response to potential HRP UWB distance reduction attacks. During detection, the algorithm employs strategic countermeasures, such as skipping initial suspicious frontiers and moving on to the next, or shrinking the search window to half its default size. Following the ranging session, the algorithm validates its detections through user actions or inputs, leveraging this feedback to refine its model. The acquired knowledge is then shared with a centralized AI server, which uses the aggregated training data to update the model, enhancing its overall effectiveness in mitigating HRP UWB distance reduction attacks.
[0061] This AI algorithm employs a dynamic and proactive approach to mitigate HRP UWB distance reduction attacks. By continuously monitoring environmental factors such as location, weather, user behavior, and potential risk levels, the algorithm can adjust parameters like search window width and noise threshold in real time. This adaptive strategy helps prevent attackers from exploiting vulnerabilities and ensures the integrity of distance measurements. To assess multipath interference, the algorithm actively transmits signals and analyzes reflections, allowing it to refine its mitigation techniques accordingly.
[0062] The advanced AI system employs novel algorithms to proactively detect and mitigate potential HRP UWB distance-reduction attacks, such as Ghost Peak attacks. By analyzing signal patterns, identifying anomalies, and utilizing user-specific data, threats can be identified, and system parameters can be dynamically adjusted to prevent unauthorized access. Post-incident assessment further enhances threat detection capabilities, ensuring continuous improvement and adaptation to evolving security challenges. Collaborative learning methods and shared data across multiple vehicles enhance the system's overall resilience and adaptability. This enables the AI algorithm to more efficiently identify emerging threats and develop countermeasures. Furthermore, the system's ability to dynamically adjust the search window and noise threshold ensures optimal performance under various environmental conditions, further strengthening the security posture.
[0063] Turn now Figure 3 This diagram illustrates a functional block diagram of an exemplary implementation of a secure UWB ranging system 300 and a motor vehicle data communication system according to embodiments of the present disclosure. The diagram illustrates a reinforcement learning-based AI algorithm designed to enhance the security of the UWB ranging system against Specter attacks. This agent-based approach enables the vehicle to dynamically adapt its response strategy to evolving threat scenarios.
[0064] UWB distance spectre attacks pose a significant threat to the security of UWB systems, exploiting vulnerabilities in the HRP layer to manipulate distance measurements. These attacks, involving the introduction of false signals or manipulation of legitimate signals, can lead to unauthorized access or compromised security. To address these threats, a reinforcement learning algorithm is provided, employing advanced techniques to analyze signal characteristics, detect anomalies, and dynamically adjust system parameters. By proactively identifying and mitigating potential attacks, the integrity and security of UWB-based applications are ensured.
[0065] Vehicle 305 continuously observes the phase, distance, and / or amplitude of signal 315, identifying deviations from the expected baseline as potential threats. Based on the observed data, policy 310 determines the optimal mitigation strategy. This policy 310 is learned through reinforcement learning algorithm 320. Observations 315 are also fed to reinforcement learning algorithm 320. The reinforcement learning algorithm iteratively refines the policy based on the results of actions, thereby ensuring continuous improvement. Based on the updated policy learning algorithm 320, learned updates are fed to policy 310.
[0066] In response to rule 310, the vehicle control system then responds to the detected threat by initiating appropriate device-to-vehicle ranging threat mitigation measures. Environment 330 represents external factors affecting the effectiveness of the signal and mitigation measures, including noise, interference, and potential ghost attacks. In response to environment 330 and action 350, a reward function evaluates the effectiveness of the vehicle's response based on response time and peak phase. Timely threat mitigation and accurate phase alignment are prioritized. Through this iterative process, the algorithm learns optimal rules by interacting with the environment, receiving rewards for successful actions, and penalties for unsuccessful actions. By adopting this AI-driven approach, the vehicle can effectively learn from its experience, adapt to changing threat landscapes, and proactively mitigate ghost attacks, thereby ensuring the integrity and security of the UWB ranging system.
[0067] Turn now Figure 4The diagram illustrates a flowchart of an exemplary implementation of method 400 for a secure UWB ranging system and a motor vehicle data communication system. Method 400 first operates to store 405 data representing characteristics of STS peaks from an certified transmitter. These characteristics may include the time and power difference between the highest peak and the leading edge, the power difference between the leading edge and a noise threshold, the shape of the leading edge, its maximum amplitude, and its power distribution.
[0068] Method 400 then proceeds to receive a 410 STS sequence from a remote transmitter. Method 400 decodes the STS peaks 415 and determines whether the transmitter is an authenticated transmitter. In some exemplary embodiments, the transmitter may be authenticated in response to a public key, etc. If the transmitter is not authenticated 420, method 400 rejects the 460 STS sequence and returns to receiving subsequent STS sequences 410.
[0069] If the STS sequence is successfully authenticated 420, then method 400 compares the leading peak of the received STS sequence with a stored leading peak 430. In some exemplary embodiments, the receiver can perform the comparison by cross-correlation of the received signal with the expected signal. If the cross-correlation value is high, such as above a certain threshold, it indicates the maximum peak corresponding to the multipath signal. If the cross-correlation does not reach the threshold, it means that the received STS is erroneous or contains too many errors. Once the maximum peak is found, the receiver can use a reverse search window to find the leading peak corresponding to the direct path. Method 400 can compare peak shape, signal strength difference between the leading peak and the middle peak, power distribution, and / or power difference between the leading peak and a noise threshold. If the first peak matches a stored first peak 440, then method 400 determines the distance 445 between the transmitter and the vehicle in response to the timing of the leading peak. For example, the method can store the received sequence, authenticate the STS sequence in response to data transmitted in the middle peak, and then calculate the time difference between the arrival of the first peak and the middle peak in the sequence. This time difference is directly proportional to the distance between the transmitter and the receiver. In response to the detected time and transmitter authentication, method 400 then authorizes an action 445 based on distance, such as unlocking the vehicle, remote start, or switching from standby mode to driving mode. Subsequently, method 400 may update the front-peak characteristics 425 of the front-peak stored in memory in response to a newly received front-peak. The updated front-peak is then stored 405 in memory for further ranging system security.
[0070] If the preceding peak and the stored preceding peak do not match 440, the method can take countermeasures to detect the preceding peak from the certified transmitter. In some exemplary embodiments, method 400 can reduce the backward search time window 450 used to detect the preceding peak. Therefore, method 400 detects the preceding peak only by backtracking the time of the certified preceding peak by a reduced amount of time. This window can be repeatedly reduced until a matching preceding peak is detected. If a new matching preceding peak is detected 455, method 400 determines the distance between the transmitter and the vehicle and authorizes an action based on that distance. If no new matching peak is detected 455, method 400 can then reject the STS sequence 460 and return to receiving the next STS sequence 410.
[0071] In some exemplary embodiments, when the initial leading peak is determined to be a mismatch 440, method 400 may employ pattern recognition and self-learning (such as based on signal shape, integrity, and characteristics associated with unique location / event / user features) to detect a match between the leading peak and a stored leading peak. Method 400 may use location and location characteristics such as open sky, dense urban areas, enclosed spaces, weather conditions, user habits, and potential risks to the predicted multipath signal, as well as possible threat conditions. In some exemplary embodiments, the reverse search window depends on the maximum delay between the multipath signal and the direct path signal. This delay, in turn, depends on the space where the measurement is performed, such as open sky, dense urban areas, weather conditions, temperature, humidity, etc. The optimal width of the search window for each of these cases may be learned by an AI model and set to the correct / optimal value by the vehicle and key fob / phone or more generally by the transmitter and receiver in the ranging session. Method 400 may employ: threat detection, such as detecting threats using a training set and inconsistencies with patterns developed specifically for the user / location / time of day / weather conditions; threat mitigation by dynamically adjusting system parameters to defend against attacks; and threat assessment by using post-incident actions to determine the credibility of a threat. Additionally, Method 400 may employ shared learning or crowdsourcing to upload threat data to a centralized database accessible to all vehicles. Method 400 may proactively and dynamically adjust the width of the reverse search window, adjust the noise threshold, and sense the environment and environmental conditions to determine optimal / safer system parameters. Method 400 may proactively and dynamically adjust the noise threshold based on factors such as fading and multipath interference. In some exemplary embodiments, Method 400 may estimate the level of multipath interference by sensing its environment, transmitting signals, and measuring the characteristics of reflected signals.
[0072] While at least one exemplary embodiment has been presented in the foregoing detailed description, it should be understood that numerous variations exist. It should also be understood that the exemplary embodiments or multiple exemplary embodiments are merely examples and are not intended to limit the scope, applicability, or configuration of this disclosure in any way. Rather, the foregoing detailed description will provide those skilled in the art with a convenient roadmap for implementing the exemplary embodiments or multiple exemplary embodiments. It should be understood that various changes can be made to the function and arrangement of the elements without departing from the scope of this disclosure as set forth in the appended claims and their legal equivalents.
Claims
1. A method for determining the distance between a transmitter and a receiver, comprising: Store in memory the first data indicating the characteristics of the expected peak; The receiver receives a data sequence including a first peak and a second peak. The processor authenticates the data sequence in response to the second data received in the second peak; The distance between the transmitter and the receiver is determined by the processor in response to the difference between a first reception time of the first peak and a second reception time of the second peak, wherein the determination of the distance is initiated in response to the first peak matching the expected peak; and The vehicle controller activates the vehicle control algorithm in response to the distance.
2. The method for determining the distance between a transmitter and a receiver according to claim 1, wherein the search time interval for detecting a subsequent first peak is reduced in response to the first peak not matching the expected peak.
3. The method for determining the distance between a transmitter and a receiver according to claim 1, wherein the first peak and the second peak are part of a pseudo-random spread spectrum time-jump sequence.
4. The method for determining the distance between a transmitter and a receiver according to claim 1, wherein the vehicle control algorithm includes unlocking the vehicle and switching the vehicle between a standby state and an on state.
5. The method for determining the distance between a transmitter and a receiver according to claim 1, wherein in response to the first peak not matching the expected peak, the search time interval for detecting a subsequent first peak is reduced, and wherein the duration of the search time interval is determined in response to vehicle location, vehicle environment, weather conditions, user habits, and potential risk level.
6. The method for determining the distance between a transmitter and a receiver according to claim 1, wherein in response to the first peak not matching the expected peak, the search time interval for detecting a subsequent first peak is reduced, and wherein the duration of the search time interval is determined in response to a multipath level estimated in response to the vehicle communication system transmitting a signal and detecting reflections of the signal.
7. The method for determining the distance between a transmitter and a receiver according to claim 1, wherein in response to the first peak not matching the expected peak, the search time interval for detecting a subsequent first peak is reduced, and wherein the duration of the search time interval is reduced in response to the length of the pseudo-random spreading time-jump sequence preamble in the time domain.
8. The method for determining the distance between a transmitter and a receiver according to claim 1, wherein the first peak is rejected in response to the first peak not matching the expected peak, and a subsequent peak is detected between the first peak and the second peak, wherein the subsequent peak is then compared with the expected peak.
9. The method for determining the distance between a transmitter and a receiver according to claim 1, wherein the power difference between the first peak and the second peak is used to compare the first peak with the expected peak.
10. An apparatus for determining the distance between a transmitter and a receiver, comprising: The memory is configured to store initial data indicating characteristics that are expected to peak. The receiver is configured to receive a data sequence including a first peak and a second peak from the transmitter; The processor is configured to authenticate the data sequence in response to second data received in the second peak, to determine the distance between the transmitter and the receiver in response to the difference between a first reception time of the first peak and a second reception time of the second peak, wherein the distance determination is initiated in response to the first peak matching the expected peak, and to generate a control signal in response to the distance. as well as A vehicle controller for enabling a vehicle control algorithm in response to the control signal.