Methods for secure arrival time measurement
Patent Information
- Application Number
- JP2025512903
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-31
- Filing Date
- 2023-08-07
- Publication Date
- 2025-11-07
AI Technical Summary
Existing UWB time-of-arrival measurements are vulnerable to attacks and face a trade-off between robustness/time accuracy and security due to limited TX budget, leading to compromised distance measurements.
Using a secret distance pulse sequence for both time-of-arrival measurements and authenticity verification, decoding the bit sequence at the path corresponding to the determined arrival time, and optimizing TX budget allocation for longer pulse sequences.
Enhances security against attacks and improves robustness and accuracy of time-of-arrival measurements by verifying the integrity of the measurements and reducing false paths.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to the field of ultra-wideband (UWB) secure time-of-arrival measurements and UWB secure ranging. [Background technology]
[0002] UWB distance measurement is well known. As shown in Figure 1, a verifier V transmits a challenge message C1 with a distance pulse sequence N to a prover P within a UWB channel. The prover P then transmits a response message R1 with a distance pulse sequence N back to the verifier V within the UWB channel. This distance pulse sequence N is used to detect the exact arrival times of the challenge message C1 and the response message R1. Due to the verifier time difference DTv between the transmission of the challenge message C1 and the arrival time of the response message R1, the time of flight of the two messages C1 and R1 can be determined, and thus the distance between the verifier V and the prover P. Thanks to the use of a UWB channel, the pulses of the distance pulse sequence N can be transmitted with a very short duration, on the order of 1-2 ns. As a result, the arrival time of the distance pulse sequence N, and therefore the arrival times of the messages C1 and R1, can be determined with a small error. The distance between the prover and the verifier can be determined based on the verifier time difference DTv and the response time of the prover P. The response time of the prover P can be transmitted from the prover P to the verifier V (two-sided two-way ranging) or can be fixed (one-sided two-way ranging). Therefore, the quality of the distance measurement depends on the quality of the arrival time measurement of message R1 at the verifier V, which in the case of two-sided two-way ranging depends on the quality of the arrival time measurement of message C1 at the prover P.
[0003] The arrival time of a range pulse sequence N at a receiver is typically determined by cross-correlation between the theoretical / expected signal of the (transmitted) range pulse sequence N and the received UWB signal at the receiver. The correct arrival time is indicated by a cross-correlation peak when the expected range pulse sequence N corresponds to the received range pulse sequence N at the receiver. However, for a random range pulse sequence N, the cross-correlation function produces a high peak at the correct arrival time, along with multiple smaller peaks (false peaks) corresponding to some of the cross-correlation positions shifted by multiples of the inter-pulse distance of the non-averaged range pulse sequence. The false peaks have magnitudes far above the noise level and can create false early paths (as will be explained in more detail later in connection with Figure 11). This is why range pulse sequences N with special properties that theoretically eliminate false peaks are always used for distance measurements. Range pulse sequences N typically use Ipatov or Gold codes that exhibit these properties. For such special range pulse sequences N, the cross-correlation does not exhibit any false peaks, and as a result, each peak in the cross-correlation corresponds to a different true path of the message or range pulse sequence N. The same problem arises when determining the CIR based on the preamble in the message header. This is why the preamble (in UWB, also called the SYNC pattern) also uses such special characteristics, e.g., Ipatov codes. Therefore, the preamble of a UWB message is usually used to measure the message's arrival time. This is why the range pulse sequence used for time-of-arrival measurements is often also called the preamble or preamble fragment.
[0004] To prevent someone from spoofing the distance by transmitting a known distance pulse sequence N from an unauthorized device, messages C1 and R1 typically include security pulse sequences SECv and SECp, which are transmitted at a fixed time relationship to the distance pulse sequence N. The security pulse sequence SEC, sometimes called a ranging integrity fragment, is typically a sequence of pulses with random modulation (i.e., carrying random bits). To authenticate transmitter V or P, receiver P or V again cross-correlates the received UWB signal with the expected security pulse sequence SECv or SECp. The authenticity of transmitter P or V or the integrity of messages C1 and R1 are verified in two ways in the state of the art. The arrival times determined by the cross-correlation of the security pulse sequences are compared with the arrival times determined in preamble N. If they correspond, transmitter V or P is authenticated. Alternatively, the arrival times can be determined solely by the security pulse sequences SECv or SECp. Distance measurements with such security pulse sequences SECv or SECp are generally considered secure because an attacker does not know the security pulse sequences SECv or SECp.
[0005] However, Singh et al.'s paper, "Security Analysis of IEEE 802.15.4z / HRP UWB Time-of-Flight," presented at ACM WiSec 2021, presents an attack that can actually compromise secure distance measurements and create false short distances. Because the secure pulse sequence SECv or SECp is based on the cross-correlation of complete secure pulse sequences SECv or SECp, one attack compensates for the power of a wrong guess of the secure pulse sequence with twice the power of the next guess until it hits the correct guess.
[0006] Even if the security pulse sequence SECp or SECv is decoded, standard data decoding techniques are used that decode the data using the strongest path or the full channel impulse response (CIR), but usually not the fastest path, and this can compromise the security of the distance measurement.
[0007] Another problem with separately transmitting the distance pulse sequence N for time-of-arrival measurement and the security pulse sequences SECp or SECv for verification is that while the UWB messages that need to be transmitted are longer, the energy that can be transmitted within the UWB messages, or the TX budget, is limited due to regulatory reasons. This means that the transmitted energy of a UWB channel is limited at any given time. The energy corresponds to the average power of the UWB channel multiplied or integrated over time. More precisely, the energy of each UWB channel for each 1 ms cannot exceed a maximum energy (also known as the TX budget or transmission budget). Within this 1 ms period, the energy can be freely distributed as long as it does not exceed the maximum energy. Shorter UWB messages requiring fewer UWB pulses can use pulses transmitted with higher energy, but longer UWB messages with a larger number of pulses can often only be transmitted with lower individual pulse energy. This makes it more difficult to receive such longer UWB messages because the pulses are hidden in noise. Therefore, a UWB message using the same TX budget with more pulses transmitted at lower power typically makes reception of the UWB message more difficult over longer distances and in noisy environments. Part of the TX budget is already captured by the UWB message header (which often includes the range pulse sequence N or preamble used for time-of-arrival measurements). The remaining TX budget can be used for the security pulse sequence SEC. The longer the range pulse sequence N selected, the more accurate and robustly the time-of-arrival of the UWB message can be determined. The longer the security range pulse sequence SEC selected, the higher the security of the distance measurement. Therefore, the lengths of the two pulse sequences in a UWB message are always a trade-off between robustness / time accuracy and security.
[0008] U.S. Patent Application Publication No. 2018 / 138993 A1 discloses secure time-of-arrival measurements in which the time of arrival is measured using correlation with a synchronization pattern and verified by correlation with a secret verification pattern. In one embodiment, the time of arrival is measured directly using correlation with the secret verification pattern without the need for a synchronization pattern. In one embodiment, the bit sequence transmitted within the secret verification pattern is demodulated to authenticate the transmitting device.
[0009] US Patent Application Publication No. 2018 / 254925 A1 also discloses secure time-of-arrival measurements.
[0010] The IEEE Computer Society's LAN / MAN Standards Committee has published the P802.15.4z(TM) / D07 draft standard for Low-Rate Wireless Networks Amendment: Enhanced Ultra Wideband (UWB) Physical Layers (PHYs) and Associated Ranging Techniques, which contains information on the error resilience of decoded bit sequences for transmitter authentication. Summary of the Invention [Problem to be solved by the invention]
[0011] The object of the present invention is to provide a protocol for secure UWB time-of-arrival measurements that avoids the problems of the state of the art and is in particular safe against attacks. [Means for solving the problem]
[0012] According to the present invention, this object is solved by the independent claims.
[0013] This object is solved by a method for UWB secure time-of-arrival measurement of a secure distance message, transmitting in a UWB channel from a transmitting device to a receiving device a distance pulse sequence corresponding to a secret distance bit sequence, the method comprising the steps of: providing in the receiving device a secret distance bit sequence; determining in the receiving device an expected secret distance pulse sequence corresponding to the secret distance bit sequence expected to be received in the UWB channel when receiving the secure distance message; receiving in the receiving device the secure distance message from the transmitting device, the received secure distance message comprising a UWB signal including a secret distance pulse sequence corresponding to the secret distance bit sequence; The method includes, at the receiving device, determining a time of arrival of the secure distance message path based on the range pulse sequence received and a UWB signal including the secret range pulse sequence of the received secure distance message; determining a time point of an expected secret range pulse sequence pulse of the path in the UWB signal based on the determined time of arrival of the secure distance message path; decoding respective bit values from the UWB signal at the determined time points of each UWB pulse value to determine a bit sequence received by the secure distance message path; and comparing the received bit sequence decoded from the UWB signal with the provided secret range bit sequence to verify the authenticity of the transmitting device and the integrity of the time of arrival measurement.
[0014] This object is solved by a method for transmitting a secure distance message, comprising the step of transmitting a secure distance message to a receiving device, wherein the secure distance message comprises a secret distance pulse sequence used for distance measurement and authenticity verification, and wherein at least the secret distance pulse sequence of the secure distance message is transmitted within a UWB channel.
[0015] This object is solved by a computer program comprising instructions configured to perform one of the methods described above when executed on a processor.
[0016] This object is solved by a receiving device for receiving a secure distance message from a transmitting device, the secure distance message including a distance pulse sequence corresponding to a secret distance bit sequence, the receiving device comprising receiving means and processing means, the receiving means being configured to receive the secure distance message from the transmitting device, the received secure distance message including a UWB signal including a secret distance pulse sequence corresponding to the secret distance bit sequence, the processing means being configured to provide the secret distance bit sequence, and to determine an expected secret distance pulse sequence corresponding to the secret distance bit sequence expected to be received in the UWB channel upon receiving the secure distance message, the expected distance pulse sequence, and The receiving means is configured to: determine, based on a UWB signal including the provided secret distance pulse sequence of the secure distance message, a time of arrival of the secure distance message path; determine an expected secret distance pulse sequence pulse time of the path in the UWB signal based on the determined time of arrival of the secure distance message path; decode respective bit values from the UWB signal at the determined time of each UWB pulse value to determine a bit sequence received along the secure distance message path; and compare the received bit sequence decoded from the UWB signal with the provided secret distance bit sequence to verify the authenticity of the transmitting device and the integrity of the time of arrival measurement.
[0017] This object is solved by a transmitting device for transmitting a secure distance message to a receiving device, the secure distance message including a secret distance pulse sequence used for distance measurement and authenticity verification, and wherein at least the secret distance pulse sequence of the secure distance message is transmitted within a UWB channel.
[0018] This object is further solved by a method for distance measurement between a verifier and a prover, comprising the steps of: sending a challenge message having a challenge pulse sequence from the verifier to the prover; sending a response message having a response pulse sequence from the prover to the verifier; securely determining the arrival time of the response message at the verifier based on a method for secure arrival time measurement; and determining the distance between the verifier and the prover based on the verifier time difference between sending the challenge message from the verifier and the determined arrival time of the response message.
[0019] This object is further solved by a system for distance measurement comprising a verifier and a prover, wherein the verifier is configured to send a challenge message having a challenge pulse sequence to the prover, the prover is configured to send a response message having a response pulse sequence to the verifier, and the verifier is configured to securely determine the arrival time of the response message at the verifier based on a method for secure arrival time measurement, or the verifier is a receiving device as described above that determines a secure arrival time of the response message and determines the distance between the verifier and the prover based on the verifier time difference between sending the challenge message from the verifier and the determined arrival time of the response message.
[0020] The concept of the present invention is to use the same secret distance pulse sequence for time-of-arrival measurements and for verifying the authenticity of the transmitting device, decoding the bit sequence at the time corresponding to the path determined as the arrival time of the secure distance message, thereby verifying the integrity of the time-of-arrival measurements. This allows for high security against any known attacks. Instead of simply considering the cross-correlation of the secret distance pulse sequence to verify the authenticity of the transmitting device, the actual transmitted bit sequence is decoded from the UWB signal. However, the decoding of the UWB signal is only performed at the time defined by the path corresponding to the determined arrival time. This ensures a high level of security against any method that attempts to guess the secret distance pulse sequence and manipulate the power of individual pulses (based on previous guesses). Therefore, the integrity of the time-of-arrival measurements is also verified in this way, and any manipulation of the time-of-arrival measurements is detected when decoding the bit sequence at each time point of the path. Because the same secret distance pulse sequence is used for time-of-arrival measurements and authenticity verification, the pulse sequence can be selected to be longer, which can reduce the impact of false paths. Additionally, the robustness of bit decoding is improved when the bit decoding associated with one path is based on the same pulse sequence that is also used to determine the arrival time, i.e., the path selected for decoding. This decoding technique also differs from most known conventional UWB decoding techniques, which typically use the strongest path or the full CIR for decoding and therefore do not associate the determined arrival time with the path. This opens up the possibility of security attacks against secure time-of-arrival measurements.
[0021] The dependent claims refer to advantageous embodiments of the invention.
[0022] In one embodiment, the step of comparing the received bit sequence decoded from the UWB signal with the provided secret distance bit sequence includes determining a number of errors in the received bit sequence relative to the secret distance bit sequence and considering the transmitter verified if the determined number of errors is below a threshold. Decoding the bit sequence at a point in the path associated with the determined arrival time may increase the error rate of the decoded bit sequence. Secure arrival time measurements can also be performed in noisy environments by accepting a certain error rate in the decoded bit sequence to verify the authenticity of the transmitting device and the integrity of the arrival time.
[0023] In one embodiment, for each determined UWB signal time point, the bits for this time point are decoded from a time window of the UWB signal around that time point, the time window being 16 nanoseconds or less.
[0024] In one embodiment, the same pulse of the secret ranging pulse sequence is used at the receiver once to detect the time of arrival and once to decode the bit value of the pulse.
[0025] In one embodiment, the covert ranging pulse sequence is transmitted within the UWB channel using a time hopping method with two or more different inter-pulse distances, preferably three or more different inter-pulse distances.
[0026] The different inter-pulse distances reduce amplitude false paths when determining the time of arrival based on a combination (e.g., cross-correlation) of a UWB signal including an expected range pulse sequence and a secret range pulse sequence of a received secure range message, and increase the quality of the time of arrival measurement to find the correct true earliest path of the secure range message.
[0027] In one embodiment, the time of arrival of the secure range message at the receiving device is determined based on a cross-correlation between an expected covert range pulse sequence and the received UWB signal.
[0028] In one embodiment, an early path time window before the cross-correlation maximum is determined, and weaker early paths are detected within the early path time window.
[0029] In one embodiment, a mismatched range pulse sequence is calculated that varies some pulse values of the secret pulse sequence to minimize false peaks in the cross-correlation within the early path time window, and a weak early path is determined based on the cross-correlation within the early path time window between the mismatched range pulse sequence and the received UWB signal. This embodiment enables reducing amplitude false paths when determining the time of arrival based on a combination (e.g., cross-correlation) of the expected range pulse sequence and the UWB signal including the secret range pulse sequence of the received secure range message, improving the quality of the time of arrival measurement to find the correct true earliest path of the secure range message.
[0030] In one embodiment, the secret range pulse sequence includes a combination of a known portion and a secret portion, where the known portion corresponds to a special code that reduces or eliminates false peaks, and the influence of the known special code pulse reduces false paths created by the secret portion.
[0031] In one embodiment, each pulse in the secret distance pulse sequence has a first pulse value or a second pulse value, and the secret distance pulse sequence includes known pulses and secret pulses, where the known pulses are pulses whose pulse values are known and the secret pulses are pulses whose pulse values are secret. The known pulses follow a special code that reduces or eliminates false peaks, and the special code includes a first code value corresponding to the first pulse value, a second code value corresponding to the second pulse value, and a third code value corresponding to no pulse being transmitted, and the secret pulses are transmitted at at least some of the third code values within the special code. Preferably, the special code is an IPATOV code. The effect of the known special code pulses reduces false paths created by the interleaved secret pulses.
[0032] Subsequent embodiments allow for an increased TX budget available for covert range pulse sequences. Increasing the TX budget allows for longer covert range pulse sequences to be transmitted with more pulses, allowing for a reduction in amplitude as false paths are averaged over a higher number.
[0033] In one embodiment, the secure distance message includes a first information portion followed by a second information portion, the second information portion including a secure distance bit sequence, and the first information portion is used to detect the secure distance message in a received signal and / or to determine a clock offset between a system clock of the receiving device and a system clock of the transmitting device.
[0034] In one embodiment, the secure distance message includes a message frame in the physical layer, a first information portion is transmitted in a narrowband channel, a second information portion is transmitted after the second information portion in a UWB channel, and a time relationship between the first information portion and the second information portion is defined by the message frame in the physical layer.
[0035] In one embodiment, the secure distance message includes a message frame in a physical layer, a first information portion transmitted within a first UWB frequency-time portion and a second information portion transmitted within at least one second UWB frequency-time portion, each UWB frequency-time portion defined as a portion of a UWB frequency-time region limited by a TX budget of the UWB channel, and the first UWB frequency-time portion is different from the second UWB frequency-time portion.
[0036] In one embodiment, the second information portion is transmitted the minimum time after the start of the first information portion required to again have a full UWB TX budget in the UWB channel.
[0037] In one embodiment, the expected arrival time of the expected range pulse sequence in the UWB channel relative to the arrival time of the first information portion is determined based on a message protocol of the secure range message and based on the determined clock offset, and the arrival time of the secure range message at the receiving device is determined based on the expected range pulse sequence and the UWB signal received at the expected arrival time.
[0038] In one embodiment, the second information portion is transmitted in the UWB channel without the message portion that includes the preamble, start of frame delimiter, and packet header.
[0039] In one embodiment, the second information portion includes multiple second information sub-portions transmitted within different UWB frequency-time portions, each different UWB frequency-time portion being defined as part of a UWB frequency-time domain limited by the TX budget of the UWB channel, and the secret ranging pulse sequence includes multiple different secret ranging pulse sub-sequences transmitted within the different second information sub-portions.
[0040] In one embodiment, the covert ranging pulse sequence comprises a plurality of different covert ranging pulse subsequences transmitted in different UWB frequency-time portions of the UWB channel. Other embodiments in accordance with the invention are set forth in the appended claims and the following description. [Brief explanation of the drawings]
[0041] [Figure 1] FIG. 1 is a schematic diagram illustrating one prior art embodiment of secure distance measurement. [Figure 2] 1 is a diagram of a frame in the physical layer for a UWB message or an NB message according to the prior art; [Figure 3] FIG. 1 illustrates an exemplary time order of a pulse sequence having equidistant pulses. [Figure 4] FIG. 1 illustrates an exemplary time sequence of a pulse sequence having a burst. [Figure 5A] FIG. 2 is a diagram of a first example of a message frame in the physical layer for secure distance messaging according to the present invention. [Figure 5B] FIG. 2 is a diagram of a second example of a message frame in the physical layer for secure distance messaging in accordance with the present invention. [Figure 6] 1 is a diagram of an exemplary message frame transmission and its communication channel between a transmitter and a receiver. [Figure 7] FIG. 10 is a diagram of a third example of a message frame in the physical layer for secure distance messaging in accordance with the present invention. [Figure 8] FIG. 10 is a diagram of a fourth example of a message frame in the physical layer for secure distance messaging in accordance with the present invention. [Figure 9] FIG. 5 is a diagram of a fifth example of a message frame in the physical layer for secure distance messages according to the present invention. [Figure 10] FIG. 1 describes an example of a method for measuring the secure arrival time of a message. [Figure 11] FIG. 1 illustrates one embodiment of a system, method, verifier, and prover for secure distance measurement according to the present invention. [Figure 12] FIG. 1 illustrates the problem of determining the cross-correlation of short random pulse sequences in a multipath environment. [Figure 13] FIG. 1 illustrates an improved embodiment for reducing the problem of false routes. DETAILED DESCRIPTION OF THE INVENTION
[0042] Other characteristics and advantages of the invention can be derived from the following non-limiting description, with reference to the drawings, in which:
[0043] Below, some terms used herein are defined.
[0044] A message is a data unit within the physical layer of the OSI model. In other words, a message is a data unit transmitted over a communication channel, in this case a wireless communication channel, and the data units have a common organization. This organization of messages is called a message frame or message protocol. A message typically initially contains some information that allows for message detection, clock offset determination, and / or frequency offset determination. A message typically contains additional information about the transmitting device (source) and receiving device (destination), so that the receiver RX knows whether the message is actually addressed to it. If not, the receiver RX can ignore the message. Depending on the message protocol, the management information is simpler or more complex. This management information is valid for the complete data transmitted within the message. A new message again contains management information and is therefore completely independent of the previous message. The two messages are independent of each other in terms of the transmitted data and the timing of their transmission. A new message requires new synchronization for the new message. Conventionally, messages are transmitted within the same communication channel. In this invention, there are several embodiments in which messages are transmitted within two subsequent, different communication channels, as will be explained in more detail below.
[0045] A message frame is a definition of the arrangement of data transmitted within a message (also called a message protocol). The message protocol, or frame, is known. This means that the message protocol is either fixed (always the same) or defined by the parameters transmitted within the message itself. Figure 2 shows an example definition of a message frame for a message within the physical layer. A message frame within the physical layer includes a synchronization header SHR, a packet header PHR, and a physical payload P. The synchronization header includes a synchronization pattern, often called PREAMBLE in NB and SYNC in UWB. The terms PREAMBLE and SYNC are used interchangeably herein. After the synchronization pattern, the synchronization header SHR often includes a start-of-frame delimiter SFD. The PHR typically includes the length of the message so that the receiver RX knows when the message / frame ends. The physical payload contains the data being transmitted. The SHR and PHR are for the physical layer, i.e., for the receiving chip to identify the message within the received signal of the communication channel. The physical payload typically includes another frame, often called a MAC frame, from the next higher OSI model layer, the data link layer. The MAC frame contains a MAC header MHR with communication management information about the transmitter, receiver RX, network connection, etc. The MAC payload contains the data to be transmitted. Although this is the preferred organization of the transmission frame, other organizations are possible.
[0046] Messages and / or frames are physically transmitted via a communication channel (short channel), or in this context, via a wireless communication channel. The wireless communication channel includes a radio signal transmitting the message. The wireless communication channel or radio signal has a bandwidth. The bandwidth in this context can be either ultra-wideband (UWB) or narrowband (NB). UWB preferably has a bandwidth of 50 MHz or more, even more preferably 100 MHz or more, even more preferably 200 MHz or more, even more preferably 300 MHz or more, even more preferably 400 MHz or more, and most preferably 500 MHz or more. The NB has a bandwidth that does not significantly exceed, i.e., is smaller than, the coherence bandwidth of the channel. The NB preferably has a bandwidth less than 50 MHz, preferably less than 20 MHz, preferably less than 10 MHz, preferably less than 5 MHz, preferably less than 1 MHz, and preferably less than 500 Hz. The bandwidth of the NB as defined herein refers to the bandwidth used within a single NB communication channel. Data or bits of a message frame are transmitted by symbols. One symbol typically carries one or more bits depending on the modulation scheme. It is also possible for a symbol containing multiple pulses to transmit one bit. NB symbols (symbols of the NB channel) can be transmitted for an unlimited time but are preferably long enough for high symbol energy, while UWB symbols are transmitted for a short time with high instantaneous power. UWB symbols can be, for example, hundreds of nanoseconds long, or even a few microseconds long, but each of the at least one UWB pulse forming a UWB symbol is in the nanosecond or shorter range. A radio signal has a carrier frequency on which a message is transmitted. Conventionally, the NB carrier frequency used for oob messages is in the ultra-high frequency (UHF) band (below 3 GHz), while the UWB carrier frequency is in the very high frequency (SHF) band (above 3 GHz). Preferably, in the present invention, the carrier frequency of the NB channel, if used, is greater than 2.4 GHz, preferably greater than 2.5 GHz, preferably greater than 3 GHz, and preferably greater than 5 GHz.Preferably, the carrier frequency of the NB channel is selected close to the carrier frequency of the UWB channel so that the same antenna and the same transceiver components can be used for the NB channel and the UWB channel. Preferably, the carrier frequency of the NB channel is closer to the carrier frequency of the UWB channel than 2 GHz, preferably closer than 1 GHz, and preferably closer than 500 MHz. Theoretically, the same carrier frequency could be used for the NB channel and the UWB channel. However, for regulatory purposes and bandwidth sharing (e.g., multi-user), different carrier frequencies are preferred. The UWB channel may include different UWB subchannels.
[0047] As shown in Figure 6, a message M is transmitted from a transmitting device TX to a receiving device RX. The transmitting device may also be referred to as a transmitter TX for short, and / or the receiving device may also be referred to as a receiver RX for short. The transmitter TX may be described as a device having all the functionality necessary to transmit the message M, and the receiver RX may be described as a device having all the functionality necessary to receive the message M. However, in a preferred embodiment, the transmitting device TX may function as both a receiver RX and a transmitter TX, i.e., a transceiver. In a preferred embodiment, the receiving device RX may function as both a receiver RX and a transmitter TX, i.e., a transceiver. In such a case, the transceiver has the functionality of both a transmitting device and a receiving device.
[0048] A range pulse sequence is a sequence of UWB pulses used at the receiver RX to measure the arrival time of a received message M. The arrival time of a received message M can be used to calculate the time of flight, e.g., the time between the transmission of the previous message M and the measured arrival time (e.g., verifier time difference) or the time between the measured arrival time and the time the next message is sent (e.g., prover time difference). A range pulse sequence according to the present invention is always transmitted within a UWB channel. This arrival time measurement may also be referred to as a timestamp of the received message M. Therefore, other UWB pulses or NB symbols transmitted before or after a range pulse sequence that are not directly used to measure the arrival time are not considered a range pulse sequence. A range pulse sequence corresponds to a range bit sequence. Therefore, a range bit sequence refers to the bit sequence following a transmitted range pulse sequence. The number of pulses in a range pulse sequence is typically equal to the number of bits in the range bit sequence, but may be greater or less than the number of bits in the range bit sequence. In some embodiments, one bit in a range bit sequence corresponds to one UWB pulse in the range pulse sequence, resulting in a range bit sequence with the same number of bits as the number of pulses in the range pulse sequence. A UWB symbol typically contains one or more UWB pulses. Multiple bits may correspond to a particular UWB symbol. Furthermore, as with spreading codes, one bit in a distance bit sequence may correspond to a UWB symbol containing multiple UWB pulses. The order of the bits or spreading code typically corresponds to the order of the pulses in a distance pulse sequence. However, it is also possible to rearrange the order of the bits (or chips of the spreading code) in a distance pulse sequence, as described, for example, in International Publication No. 2017 / 121452. Therefore, the term distance pulse sequence preferably refers to the full sequence of UWB pulses used for time-of-arrival measurements, i.e., cross-correlation between the expected distance pulse sequence and the UWB signal transmitting the distance pulse sequence.The range pulse sequence is a translation of the range bit sequence in the physical layer of the OSI model, i.e., what is sent from the device. The term range bit sequence rather refers to the data after the range pulse sequence. These data or the range bit sequence may have already been sent before the actual range pulse sequence (but in encrypted form to keep the range bit sequence secret). The range bit sequence refers to the data carried by the range pulse sequence on the physical layer of the OSI model. The abbreviation range pulse / bit sequence shall mean the range pulse sequence and / or the range bit sequence.
[0049] In the current state of the art, the distance pulse / bit sequence used is well known to a third party and is often a periodic bit sequence, typically a preamble or sync pattern for UWB messages, to facilitate time-of-arrival detection. In the present invention, the distance bit / pulse sequence is secret and / or changes with each message. Therefore, a secret distance bit / pulse sequence means that a third-party device cannot know in advance that the distance pulse sequence used will impair the distance measurement, for example, by predicting the final part of the distance pulse sequence. The secret distance bit sequence is typically a cryptographically generated random number (nonce). It is also possible for only a portion of the distance bit / pulse sequence to be secret. In this case, the secret distance bit / pulse sequence includes at least one secret part and at least one known part. Theoretically, the secret distance bit / pulse can include one secret part and one known part, one after the other. Unlike the current state of the art, the secret part is also used to determine the time of arrival. However, it is preferable that the secret part be interleaved with the known part. Thus, the secret range pulse sequence includes known pulses and secret pulses, with the secret pulses interspersed among the known pulses. In one embodiment, more than 20%, preferably more than 30%, preferably more than 50%, preferably more than 70%, preferably more than 80%, preferably more than 90%, and preferably more than 95% of the pulses / bits of the range pulse / bit sequence are secret, i.e., unknown to an attacker. For example, the start of the range pulse / bit sequence may be periodic, while the subsequent secret portion is, for example, random. However, in such a case, both the non-secret and secret portions of the range pulse sequence are always fully utilized for arrival times and for the verification step (see below). Most preferably, the entire range bit / pulse sequence is secret. For simplicity, the secret range pulse / bit sequence will be referred to as a range pulse / bit sequence without the adjective "secret," but (unless otherwise specified) it is always intended to be a secret range pulse / bit sequence.
[0050] Range pulse sequences are most often transmitted equidistantly, i.e., by an equidistant sequence of pulses 41 with the same time difference between all pulses of the range pulse sequence, as shown in the example of FIG. 3. However, range pulse sequences can also be transmitted in a different time order than that of FIG. 3. An alternative is to transmit the pulses 41 of the range pulse sequence in pulse groups 42, as shown in FIG. 4, i.e., as a group pulse sequence. A group 42 comprises at least two pulses 41. A group pulse sequence comprises a sequence of at least two groups (multiple groups). The time difference between two subsequent pulses 41 of the same group 42 is the time difference T between two subsequent groups 42. GPulses 41 in the same group 42 are typically transmitted immediately one after the other. Preferably, subsequent pulses 41 in the same group 42 have a time difference between them that is less than 10 times the pulse 41 duration, preferably less than 8 times, preferably less than 6 times, preferably less than 5 times, preferably less than 4 times, and preferably less than 3 times the pulse 41 duration. The time difference between two subsequent pulses 41 in the same group 42 is preferably less than 10 times the pulse duration, preferably less than 5 times the pulse duration, preferably less than 3 times the pulse duration, preferably less than 2 times the pulse duration, and preferably less than 1 time the pulse duration. The time difference between subsequent pulses is the time difference between the same characteristic points of each pulse 41, e.g., the peaks of the pulses 41. The pulse duration is, for example, 2 ns, and pulses in a group 42 of pulses 41 are transmitted every 4 ns or 2 ns. Often, a group 42 of pulses 41 is a symbol for a bit, also called a burst or spreading code. The pulses 41 in this symbol or group 42 are often also called chips. Such spreading codes or bursts 42 facilitate reception of the transmitted bit sequence because the transmitted energy per bit is increased by a factor of the number of chips per symbol. However, the longer the symbol length, the greater the risk of manipulation of arrival times by malicious third parties. Therefore, pulses 41 are preferably transmitted as close together as possible to make manipulation of arrival times as difficult as possible. Group pulse sequences have the additional advantage that grouping pulses 41 results in a larger time difference between groups 42, thereby preventing previous groups 42 from generating noise for subsequent groups in environments with long channel impulse responses. This significantly facilitates signal reception and avoids complex and power-consuming post-processing of the received signal to remove the channel impulse response.
[0051] The term distance bit information is intended to denote any information that makes it possible to determine a (secret) distance bit sequence from the distance bit information. The distance bit information may be the distance bit sequence itself. In other embodiments, the distance bit information may be shorter than the distance bit sequence. For example, the distance bit information may be seed information that makes it possible to determine the distance bit information by a (cryptographic) function. The latter embodiment makes it possible to reduce the amount of data exchanged when the distance bit information has to be (secretly) exchanged between a sending device and a receiving device.
[0052] The previous description of the message M shall apply equally to the secure distance message M according to the present invention.
[0053] 5A shows a first example of a message frame for a secure distance message M according to the present invention. The secure distance message M is a standard UWB message containing a synchronization header SHR and an optional MAC header PHR. The (MAC) payload of message M contains a secure distance bit sequence transmitted together with a secure distance pulse sequence. The complete message M is transmitted within a UWB channel and the same UWB time slot and the same UWB subchannel.
[0054] 5B shows a preferred embodiment of a message frame or protocol for a secure distance message M. Message M includes a first information portion A and a second information portion B within a common message frame. The second information portion is always transmitted within the UWB channel.
[0055] In one embodiment, the first information portion is transmitted within the same UWB channel as the second information portion, but preferably within a different UWB frequency-time portion from the second information portion. A UWB frequency-time portion is defined as a portion of a UWB frequency-time region limited by a TX budget LB. Therefore, the two different UWB frequency-time portions each have an independent TX budget LB, allowing the two different UWB frequency-time portions to jointly transmit twice the energy of the TX budget LB within the UWB spectrum. The two different UWB frequency-time portions may be two different UWB subchannels or two different TX budget (time) slots. Two different UWB subchannels means that the first information portion A and the second information portion B are transmitted within different UWB subchannels of a UWB channel, i.e., at different carrier frequencies. Two different TX budget (time) slots means that the first information part A and the second information part B are transmitted in different UWB TX budget (time) slots, i.e., typically 1 ms after the start of the first information part A, so that the second information part B again has available TX budget. Such an embodiment is shown in Figure 7. In this embodiment, the first information part A is intended as the complete information of the message M to be transferred in a first UWB frequency-time part (before the second information part B), and the second information part B is intended as the complete information of the message M to be transferred in at least one second UWB frequency-time part (different from the first frequency-time part).
[0056] As shown in FIG. 8 , in another embodiment, the first information portion is transmitted in the NB channel. In this embodiment, the first information portion A is intended as the complete information of the message M transferred in the NB channel (before the second information portion), and the second information portion B is intended as the complete information of the message M transferred in the UWB channel. In a preferred embodiment, the message M does not include any portion other than the first information portion A and the second information portion B, so that the message consists of the first information portion A and the second information portion B. However, in another embodiment, it is also possible for the third information portion to be transmitted after the second information portion in the NB channel. Preferably, the first information portion A and the second information portion A are transmitted using the same oscillator / clock at the transmitter and received using the same oscillator / clock at the receiver RX. This makes it possible to determine the clock offset in the UWB channel by the clock offset recovered in the NB channel.
[0057] The first information portion A is transmitted (in the NB or UWB channel) before the second information portion B. Preferably, the second information portion B is transmitted after the first information portion A has been completely transmitted, i.e., the second information portion B is transmitted only after the end of the first information portion A has been transmitted. Preferably, the second information portion B has a well-defined time relationship with the first information portion A. The well-defined time relationship allows the receiver RX receiving the message M having the common frame to know / calculate the expected arrival of the second information portion B based on the arrival time of the first information portion and based on the well-defined time relationship. If the first information portion A is transmitted in the UWB channel, the second information portion B can be transmitted at least one TX budget time period after the start of the first information portion A so that the second information portion B again has the full TX budget available. The TX budget time period is a regulated time defined in the UWB wireless standard, after which the UWB channel again provides the full TX budget. Currently, the TX budget time period is 1 ms. If the first information portion A is transmitted in the NB channel, the well-defined time relationship may be, for example, a fixed time period between the end of the first information portion A and the start of the second information portion B. In one embodiment, the symbol lengths of the NB channel for the first information portion A and the second information portion B may be equal, so that the UWB symbols of the second information portion may be positioned at multiples of the symbol length after the NB symbols of the first information portion A. However, many other well-defined time relationships may be realized.
[0058] The first information portion A preferably includes synchronization information, preferably a synchronization header SHR, as in the classical frame shown in FIG. 2. The synchronization header or synchronization information preferably includes a preamble SYNC and an SFD. As explained above, the SHR or preamble SYNC can be used by the receiver RX to detect the message M in the wireless channel and determine the clock offset. The receiver RX can detect the message M in the wireless channel, for example, by correlating the received signal of the wireless channel with a reference signal corresponding to the wireless signal including the synchronization information, SHR, and / or preamble SYNC. When the correlation is high, the receiver RX knows that the message M has been received. Due to the longer symbols and sharper frequency shape of the symbols in the time domain, and due to the higher transmission amplitude (no energy limit per ms as in UWB), detecting the message M in the NB channel is much easier, consumes less power, and is less prone to errors than detecting the message or SHR in a UWB channel.
[0059] The transmitter TX, receiver RX, or transceiver typically has one oscillator that defines the clock of the transmitter TX, receiver RX, or transceiver. This clock or oscillator is used to generate the carrier frequency and determine the time of transmission or reception of signal bits, pulses, or symbols. The receiver RX determines the clock offset based on the first information portion A. In contrast to the arrival time of the NB message, the clock offset between the receiver RX and the transmitter TX can be determined more accurately than from the UWB portion of the message M. The receiver RX preferably determines the clock offset from the synchronization information, SHR, and / or preamble. The clock offset defines the offset of the receiver RX's system clock from the transmitter TX's system clock. When the transmitter TX has a different system clock (from the receiver RX), symbols may differ in length (time drift) and carrier phase (phase rotation) between the transmitter TX and the receiver RX, thereby reducing the TX budget and the maximum range of communication. Therefore, if the clock offset is not taken into account at the receiver RX, this will result in different lengths and / or different carrier phases of the symbols of the message M transmitted by the transmitter TX and expected at the receiver RX. Therefore, it is important for the receiver RX to know the clock offset so that the time reference of the receiver RX when the symbols are expected to be received at the receiver RX based on the above synchronization does not drift due to different system clocks. It is also important for the receiver RX to synchronize with the phase of the transmitter TX so that demodulation performance does not degrade in coherent signaling schemes. Therefore, the receiver RX detects the second information portion B of the message M using its system clock and the clock offset determined based on the first information portion A. The receiver RX adapts its system clock based on the clock offset and detects the second information portion B based on the adapted system clock. Alternatively, the receiver RX post-processes the UWB signal having the second information portion B based on the determined clock offset.
[0060] The receiver RX can also determine the frequency offset of the carrier signal frequency. The frequency offset can be determined from the determined clock offset, or vice versa. The receiver RX can then adapt the frequency of its oscillator to generate the carrier signal according to the determined frequency offset.
[0061] The first information part A preferably further comprises a PHR. The PHR preferably includes information about the length of the message M so that the receiver RX knows when the last symbol of the message M and / or the first information part A has been received. In one embodiment, the PHR may include only the length of the complete message M or any other information that allows the complete length of the message M to be determined. In a preferred embodiment, the PHR may include information about the length of the first information part A (or any other information that allows the length of the first information part A to be determined) and the length of the second information part B (or the length of a subpart thereof). Thus, the physical layer in the receiver RX could already determine from the PHR when the first information part A ends and therefore when the second information part B starts, and therefore when the receive mode of the UWB receiver RX must be switched on. However, it is also possible to include information about the length of the first information part A in the remaining first information part A, for example in the physical or MAC payload P.
[0062] The remainder of the message M comprises a physical payload P. The physical payload is divided into a first information portion, physical payload P1, which defines the remaining data of the first information portion A, and a second information portion, B. In another embodiment, the first information portion, physical payload P1, can be omitted and the complete physical payload P is transmitted within the second information portion or UWB channel.
[0063] The first information part A (physical payload P1) preferably includes (at least a portion of) a medium access control (MAC) frame. The MAC frame typically includes a MAC header (MHR) at the beginning of the MAC frame and a MAC payload and a MAC footer at the end of the MAC frame. The MHR is preferably the first information transmitted within the first information part physical payload. The MHR typically includes communication management information, such as a frame control counter, a sequence number, a source address, a destination address, and / or other communication management information. The MAC footer can be transmitted as the last information of the first information part A or as the last information of the second information part B. This depends on how the frame of the message M is defined: if the MAC frame spans both the first and second information parts, or only the first information part A.
[0064] The first information part A (physical payload P1), preferably a MAC payload, contains information to be exchanged with the message M, preferably further non-time related distance measurement information such as one or more of the SSID, distance bit information, and prover time difference. The distance bit information is preferably transmitted in encrypted form or such that a third party cannot derive the secret distance bit sequence from the distance bit information. However, the information is optional and can also be transmitted in an out-of-band message.
[0065] The second information portion B includes the range pulse sequence SEC as shown in FIG. 5B . Because the same secret range pulse sequence SEC is used for ranging and transmitter authentication, the fully available UWB TX budget of the second information portion B can be used for ranging and security at the same time. In a preferred embodiment, the second information portion B does not include a separate / full UWB message header with one or more of the following: a preamble (equivalent to SYNC), SFD, PHR, MHR, and SSID. This is possible when the header information is transmitted within the first information portion A. This allows for an increased TX budget for the range pulse sequence SEC of the message M or the second information portion B, which enables more robust / secure ranging. The TX budget of the range pulse sequence SEC can be increased by dedicating the full TX budget for that sequence, i.e., by using a range pulse sequence with a larger number of pulses and / or by using higher power / amplitude to transmit the pulses of the range pulse sequence. In one embodiment, the second information portion B includes only the range pulse sequence SEC, which allows for the fully available TX budget to be used for the range pulse sequence, for example. In another embodiment, other information can be transmitted in the second information portion B other than a pure ranging pulse sequence. For example, a reduced UWB message header can also be transmitted in the second information portion B. This reduced UWB message header can include only a SYNC pattern or even a reduced SYNC pattern. In one embodiment, the second information portion B is transmitted in the UWB channel without a message portion including a preamble, a start-of-frame delimiter (SFD), and a packet header (PHR). This message portion, including the preamble, SFD, and PHR, which are placed at the beginning of each UWB message according to the standard, is omitted in the second information portion B because it was already transmitted in the first information portion A. This embodiment without this message portion does not exclude a second information portion B including a reduced UWB message header that does not include at least one of the preamble, SFD, and PHR.For example, the second information portion B may have only a preamble. In another embodiment, the second information portion B does not include at least one of the preamble, the SFD, and the PHR, preferably does not include at least two of the preamble, the SFD, and the PHR, and preferably does not include all three of the preamble, the SFD, and the PHR.
[0066] The use of a different first information portion A has the advantage that the header information, including the SYNC pattern, can be transferred outside the TX budget of the second information portion B. This increases the TX budget available for the secure distance pulse sequence SEC and allows for pulse sequences with higher energy. This reduces the problem of false paths. This implementation is particularly advantageous because the SYNC pattern of the header information is no longer used for distance measurements in accordance with the present invention and can therefore be moved out of the TX budget of the second information portion B without the need to repeat such SYNC pattern for distance measurements in the second information portion B. Even if it is preferable that the secure distance message M includes the first information portion A (transmitted in the NB channel or in a separate UWB frequency-time portion) and the second information portion B can have the removed or reduced header information of the message M, it is also possible to transmit the message M without such a first information portion A so that the necessary header information is transmitted in the second information portion B in the same UWB frequency-time portion as SEC, as shown in FIG. 5A. However, this reduces the available length / power / TX budget of the distance pulse sequence SEC. The embodiment in which the first information part A is transmitted within the NB has the further advantage that the clock offset between the transmitter TX and the receiver RX can be determined with greater accuracy within the NB than within the UWB, so that the estimated arrival time of the second information (sub)part B and / or the instants of the pulses of the expected range pulse sequence SEC within the UWB signal can be determined with greater accuracy in this embodiment.
[0067] 7, 8, and 9 illustrate a preferred embodiment of the present invention in which the second information portion B includes multiple second information subportions B1, B2, ..., BY. Each second information subportion B1, ..., BY corresponds to a different UWB frequency-time portion. The different UWB frequency-time portions can be Y different UWB frequency portions transmitted within Y different subchannels, or Y different UWB time portions each corresponding to Y different UWB TX budget (time) slots, or a combination of the two with second information subportions B1, ..., BY transmitted within different UWB frequency portions and different UWB time portions. In the latter case, for example, each UWB TX budget slot can include two or more different UWB frequency portions each transmitted within a different UWB subchannel. In a preferred embodiment, each second information subportion B1, ..., BY corresponds to a different TX budget (time) slot. That is, Y second information sub-portions B1, ..., B1, are transmitted within Y different UWB TX budget time slots. The number Y is the number of sub-portions B1, ..., B1, where i = 1, ..., Y. In this embodiment, the range pulse sequence SEC includes a plurality of Y range pulse sub-sequences SEC1, ..., B1, and SECY. Each different range pulse sub-sequence SECi is transmitted within a different second information sub-portion B1, where i = 1, ..., Y. In other words, the first range pulse sub-sequence SEC1 is transmitted within the first second information sub-portion B1, the second range pulse sub-sequence SEC2 is transmitted within the second second information sub-portion B2, ..., B1, and Y-th range pulse sub-sequence SECY is transmitted within the Y-th second information sub-portion B1. The different range pulse sub-sequences SEC1, ..., B1, and SECY are preferably different from each other so that it is more difficult for a malicious third party to compromise the message M. However, it may also be possible for the different range pulse sub-sequences SEC1, ..., B1, and SECY to be the same. Y is preferably 2, 4, 6, or 8. Obviously, other numbers Y are possible. If Y is chosen to be 1, only one second information (sub)part B(1) is transmitted, as described in the above embodiment.
[0068] The present invention is particularly advantageous for highly secure and robust UWB distance measurements, which typically require 2X second information subportions Bi, where i=1,...,2X, and X second information subportions transmit a state-of-the-art periodic distance pulse sequence N, and the other X second information subportions transmit security distance information SEC1,...,SECX (not used for distance measurements). Therefore, for the same robustness and security, the state-of-the-art requires twice as many second information subportions Bi. However, if the number 2X of second information subportions Bi becomes too large, e.g., 16, drift in the clock offset can pose serious problems for the last second information subportion Bi. Because the present invention reduces the number of second information subportions Bi required by only two for the same level of security and robustness, the present invention is particularly interesting for those with multiple second information subportions Bi. Additionally, the use of a first information portion A and multiple second information subportions B1,...,B1, allows for the use of longer secret distance pulse sequences SEC as the TX budget of the secure distance message M increases, thereby reducing the size of false routes.
[0069] 9 shows an embodiment where there is no first information portion A but there is message header information, where a first secret range pulse subsequence SEC1 is transmitted within a first second information portion B1, and the remaining second information sub-portions B2, ..., BY transmit the remaining secret range pulse subsequences SEC1, ..., SECY. As in the previous embodiment, multiple UWB frequency-time portions allow increasing the available TX budget beyond regulatory limits to transmit even longer secret range pulse sequences that further reduce false peaks in the cross-correlation.
[0070] 10 illustrates a method according to the present invention for measuring the time of arrival of a secure distance message M. A transmitter TX transmits a secure distance message M comprising a distance pulse sequence SEC. The distance pulse sequence corresponds to a secret distance bit sequence. As previously explained, at least the distance pulse sequence SEC is transmitted in a UWB channel. The following steps correspond to one embodiment of a method for determining the time of arrival of a secure distance message M at a receiver:
[0071] In step S1, a secret distance bit sequence is provided at the receiver RX. The secret distance bit sequence can be determined from secret distance bit information. The secret distance bit information can be received from the transmitter TX. The secret distance bit information is preferably transmitted in such a way that a third party cannot determine the secret distance bit sequence based on the transmission form of the distance bit information. The distance bit information can be encrypted, for example, by a shared key between the transmitter TX and the receiver RX or by a public key of the receiver RX. The transmitter TX can transmit the secret distance bit information, for example, in the secure distance message M itself, for example, in the first information part A, preferably in the first information part payload P1. However, the transmitter TX can also transmit the distance bit information in another message, for example, in an out-of-band channel / message before or after transmitting the secure distance message M. The distance bit information can also be received by another party other than the transmitter TX, for example, a device that transmits the distance bit information (secretly) to the transmitter TX and the receiver RX.
[0072] In step S2, the receiver RX determines an expected range pulse sequence corresponding to the secret range bit sequence provided in step S1. The expected range pulse sequence corresponds to a UWB radio signal expected to be received in the UWB channel when the secure range message M is received. The expected range pulse sequence can be determined, for example, based on the secret range bit sequence provided in step S1 and a physical layer message protocol, i.e., the expected range pulse sequence corresponds to the UWB signal of the secret range pulse sequence transmitted from the transmitter TX. In a more complex solution, the expected range pulse sequence can be determined, for example, based on the secret range bit sequence provided in step S1 and a physical layer message protocol, as well as the channel impulse response (CIR) of the UWB channel used, i.e., the expected range pulse sequence also includes multiple paths of the CIR. In this case, the CIR is not explicitly determined from the range pulse sequence. If the first information portion A is transmitted in the UWB channel, the CIR can be determined based on the first information portion A, preferably based on synchronization information, preferably based on an SYNC pattern. When the first information portion A is transmitted in the NB channel, the CIR can be determined based on a known message portion / pattern transmitted in the UWB channel used to transmit the second information portion B. For example, the second information portion B can include a small SYNC pattern solely for determining the CIR for the UWB channel. Alternatively, the CIR can be extracted from a separate UWB message. In a simple embodiment, each bit of the secret distance bit sequence corresponds to a pulse of the secret distance pulse sequence having a pulse value corresponding to the bit value. However, it is also possible for a first number of bits of the secret distance bit sequence to correspond to a second number (different from the first number) of pulses of the secret distance pulse sequence. In the case of a secret distance pulse sequence transmitted via time hopping (see an embodiment described in more detail below), the positions of the pulses of the secret distance pulse sequence must be arranged as they are transmitted from the transmitter TX.
[0073] In step S3, a secure distance message M is received at a receiver RX from a transmitter TX.
[0074] If the secure distance message M has a first information portion A, the receiver RX receives the first information portion A in the NB or UWB channel. The receiver RX preferably determines the (rough) arrival time of the first information portion A and / or the clock offset between the receiver RX and the transmitter TX. Based on the determined arrival time and / or clock offset, the receiver RX determines the rough arrival time of the second information portion B, and, if Y>1, the arrival times of all Y second information sub-portions B1, ..., B1, ...., B1. This makes it possible, for example, to receive a UWB signal in the UWB channel only during the estimated time window in which the second information (sub-)portion B is expected. Since UWB receivers are quite energy intensive, this already saves some energy in the receiver RX. Because the receiver RX operates much more power-efficiently in the NB channel, an embodiment with the first information portion A transmitted in the NB significantly reduces the power consumption of the receiver RX, since the receiver RX is not forced to be switched on for a long time before finally receiving the secure distance message M. The UWB signal of the second information (sub)portion is preferably digitized by an analog-to-digital converter and subsequently digitally processed. However, subsequent processing steps of analog processing are also possible. In the case of multiple second information subportions B1, ..., B1, a UWB signal containing different distance pulse subsequences SEC1, ..., SECY can be a signal with signal "islands" B1, ..., B1, every ms. A signal "island" corresponds to a UWB signal portion carrying a second information subportion B1, ..., B1, .... However, if performed within an expected distance pulse sequence, it is also possible to shorten the time between the second information portions B1, ..., B1, .... by cutting out some or all of these (information-free) signal portions. While it is preferable to transmit a secure distance message with a preceding first information portion A in order to have the full TX budget or at least an increased TX budget available for the distance pulse sequence SEC, it is also possible to transmit a secure distance message M without such a first information portion A.The first information part A is particularly advantageous because the preamble of the second information (sub)part in the UWB channel is no longer needed for time-of-arrival measurements and can therefore be transmitted within the first information part A (in the NB or UWB channel). Thus, the TX budget of the second information (sub)part can be maximized for the secret distance pulse sequence SEC.
[0075] In step S4, the arrival time of the secure distance message M at the receiver RX is determined based on the expected distance pulse sequence and the UWB signal of the secure distance message M including the distance pulse sequence SEC. Preferably, the arrival time of the secure distance message M is determined at the receiver RX based on cross-correlation between the expected distance pulse sequence and the received UWB signal. The cross-correlation moves the expected distance pulse sequence on the UWB signal corresponding to the secure distance message M, more precisely, the second information (sub)part B. When the expected distance pulse sequence corresponds to the UWB signal, the cross-correlation exhibits a peak. Due to noise, the second best match, and different paths of the secure distance message M, the cross-correlation exhibits several peaks. The arrival time of the shortest or earliest path does not necessarily correspond to the highest peak. Several smaller and earlier peaks may correspond to weaker and earlier paths that are the true arrival time of the shortest path of the secure distance message M. Therefore, estimating the arrival time may include detecting weaker and earlier paths before the maximum peak of the cross-correlation. Preferably, the early path time window 7 is defined before the arrival time of the maximum peak (strongest path) of the cross-correlation. The end of the early path detection window is preferably the time of the maximum path, and the beginning may be defined by a certain time before the time of the maximum path. Such an early path time window 7 is exemplarily shown in FIG. 13. However, some smaller (false) peaks may be due to a second-best match between the expected range pulse sequence on the UWB signal and the offset of one or more pulses, as explained above, or simply due to the noise level. Therefore, the arrival time of the earliest peak greater than a certain threshold is often considered to be the arrival time of the secure range message M. If such a weaker early path is detected within the early path time window 7, the time of the early path is defined as the arrival time of the secure range message M. If the range pulse sequence includes multiple Y range pulse subsequences, the cross-correlation is based on a signal including all range pulse subsequences one after the other.This can be done by concatenating Y distance pulse subsequences SEC1, ..., SECY one after the other with full real-time signal blocking between the second information portions B1, ..., BY, with reduced signal blocking between them, or without signal blocking.
[0076] In step S5, the expected pulse time of the range pulse sequence SEC is determined within the UWB signal based on the determined arrival time of the UWB secure range message M. In other words, the time determined in this step corresponds to the arrival time of the secret range pulse sequence pulse of the message path associated with the determined arrival time. Since the message protocol / frame of the secure range message M is known, the time of each pulse of the range pulse sequence is known within the secure range message M. Once the arrival time of the secure range message M is determined, the time of each pulse can be calculated. Preferably, the time of each pulse is determined based on the arrival time of the secure range message M and a clock offset. This includes cases where the time is calculated using only the clock of the receiver RX, but also cases where the receiver clock has previously been adapted by a clock offset. In the embodiment described below using time hopping, the time position of each pulse of the secret range pulse sequence must be taken into account to determine the time of the secret range pulse sequence pulse. If the secret range pulse sequence has a known portion and a secret portion, it is sufficient to determine the time of the secret pulse.
[0077] In step S6, the received bit sequence is decoded from the UWB signal at the determined time points. The modulation parameters of the UWB signal at each time point are determined to determine the corresponding bit value of each pulse (or multiple pulses if several pulses correspond to one bit). Based on the modulation parameters of the UWB signal at each time point, the bit value of the pulse at that time point is determined. For example, in the case of binary amplitude modulation, a positive amplitude can represent a first bit value (e.g., 1), and a negative or zero amplitude can represent a second bit value (e.g., 0). For example, in the case of binary phase shift keying, a first phase can represent a first bit value (e.g., 1), and a second phase can represent a second bit value (e.g., 0). For example, in the case of binary frequency shift keying, a first frequency can represent a first bit value (e.g., 1), and a second frequency can represent a second bit value (e.g., 0). Preferably, only a small time window around each time point is used to decode the transmitted bit of each pulse received at that time point. In other words, only the pulses of the path associated with the determined arrival time are used to decode the secret distance bit sequence after the secret distance pulse sequence; other or strongest paths or the full CIR of the pulses are not used, as in normal UWB data decoding. The decoding time window around each point used to detect the bit value of the pulse is preferably less than 20 nanoseconds (ns), preferably less than 17 ns, preferably less than 9 ns, preferably less than 5 ns, and preferably less than 3 ns. The decoding time window can also depend on the security level, e.g., a 2 ns time window for highly secure applications and a 16 ns time window for less secure applications. A 16 ns time window could lead to a potential distance fraud of 3 to 5 meters. A further difference from the state-of-the-art in distance measurement is that the security fragment, in this case the secret distance pulse sequence, is decoded bit by bit and not checked by any statistical method, allowing for a multitude of attacks.In the state of the art, this is usually done by cross-correlation of the received UWB signal with the expected security fragment, which is not performed here to verify the authenticity of the transmitter. If the secret distance pulse sequence has a known and a secret part, it is sufficient to decode only the bit sequence from the secret pulse. However, it is also possible to use the complete sequence with known and secret pulses for verification.
[0078] In the present invention, it is important that the same secret distance pulse sequence SEC is used to decode (S6) the received bit sequence and to determine the time of arrival (step S4). Preferably, using the same secret distance pulse sequence SEC means that each pulse of the secret distance pulse sequence SEC is used once for the time of arrival measurement (S4) and once for the bit decoding (S6). However, in less preferred embodiments, it can also mean that a large proportion (more than 50%) of the pulses of the secret distance pulse sequence SEC are used for the time of arrival measurement (S4) and for the bit decoding (S6), preferably more than 70%, preferably more than 80%, preferably more than 90%, preferably more than 95%.
[0079] By actually decoding the bit sequence transmitted by the path associated with the determined arrival time, the arrival time measurement cannot be corrupted by a third party, as is the case with the state-of-the-art. Because each bit is counted only once and is independent of the pulse energy, attacks such as those described at the beginning of the patent cannot be used to infer the secret range pulse sequence. Because the same sequence is used for the arrival time measurement and bit decoding, potential drift between the range pulse sequence and the security pulse sequence is avoided, allowing the full TX budget of the UWB message to be used for the secret range pulse sequence.
[0080] In step S7, the received bit sequence decoded from the UWB signal is compared with the secret distance bit sequence. The comparison result is used to verify the authenticity of the transmitter TX. In a first embodiment, the transmitter TX is verified / authenticated by the receiver RX if the received bit sequence is exactly equal to the secret bit sequence. In a second preferred embodiment, the transmitter TX is verified / authenticated by the receiver RX if the received bit sequence exhibits a number of errors less than a threshold. The threshold depends on the number of bits in the secret distance bit sequence and the desired security level. The threshold or tolerable error rate k is calculated using the following formula:
number
[0081] As previously explained, by simultaneously using a secret distance pulse sequence to determine the time of arrival of a message and to verify the authenticity of the transmitter TX, it is possible to double the length / power / TX budget of the pulse sequence used for time-of-arrival measurement and the pulse sequence used for verification, compared to the prior art, in which two different pulse sequences are used. In particular, when using longer messages with multiple UWB frequency-time parts, this reduces the message length with the same security and robustness and avoids the problem of drift due to errors in clock offset detection. The embodiment in which the first information part A is transmitted within the NB is particularly advantageous for the present invention, as it allows for a more accurate determination of the clock offset and, therefore, the time point used to decode the received distance pulse sequence.
[0082] The use of a secret range pulse sequence for time-of-arrival measurements introduces the problem of false peaks in the cross-correlation, which can lead to false early paths. This problem is already reduced due to the longer secret range pulse sequence, which can benefit from the full TX budget available in the UWB message without reducing the TX budget with a separate specific range pulse sequence. The false path problem can be further reduced by the following two improved embodiments. Before describing the two improved embodiments, the false peak problem is better described in the noise-free simulation of FIG. 12 for a random range pulse sequence.
[0083] The first row shows the situation with only one path (free space line of sight situation with no reflections). The first column (of the first row) shows the received distance pulse sequence, which in this case is equal to the transmitted pulse sequence. The second column of the first row shows the cross-correlation between the transmitted and received pulse sequences, with the correlation value shown as positive or negative. The third column shows the absolute value of the cross-correlation function received at the receiver. At zero delay (zero distance), the correlation shows the highest peak 1, which corresponds to the true peak of the only path.
[0084] False peaks are not a problem in environments where a message is received only once via the shortest, direct path. However, in many situations, a message or range pulse sequence N is received at the receiver via multiple paths, such that the cross-correlation shows multiple "true" peaks. The false peaks can be confused with weaker true paths or further reduce the power of the true peak. This can be problematic when the shortest and earliest "true" path is not the strongest path, for example, due to some obstruction by a body (non-line-of-sight, NLOS). Rows 2 and 3 illustrate this phenomenon in simulations with the same random range pulse sequence received via two or three paths. Column 1 shows the multipath random pulse sequence, column 2 shows the cross-correlation values for each individual path, and column 3 shows the absolute cumulative cross-correlation value for all paths.
[0085] In the second row, a random distance pulse sequence is received via a weak early path (small dot) and a strong late path (large circle) that is received one interpulse distance later than the early path. The true late path 1 is clearly recognizable. However, the weak true early path 2 at position 1, although visible in the individual cross-correlation in column 2, is weakened in this simulation by the negative false path seen in column 3. On the other hand, the two negative false paths of the two paths at position 6 accumulate into the strong false path 3 in column 3. This shows that the false path can obtain a stronger peak than the true early path. The third row shows a similar situation with a strong early path (large circle), a first late path with a delay of two interpulse distances (small dot), and a third late path with a delay of three interpulse distances (cross) relative to the earliest path. As can be seen in columns 2 and 3, a false pathway among the three pathways at delay position 3 can generate a strong false peak 4, leading to a false "early pathway" that is not actually there. Thus, even a false peak in the late pathway can lead to the detection of a false early peak.
[0086] In a first improved embodiment, false peaks in the cross-correlation are reduced by applying time hopping to the transmitted pulses of the secret distance pulse sequence SEC. Instead of transmitting the pulses of the secret distance pulse sequence SEC always with the same inter-pulse sequence or always with the same two-pulse inter-pulse distance, as shown in FIG. 3, time hopping is applied such that there are three or more inter-pulse distances within the secret distance pulse sequence. Thus, the cross-correlation power of false peaks is divided at different time delays of the cross-correlation, and the power of false peaks is reduced on average. State-of-the-art security pulse sequences are transmitted using the STS method, i.e., transmitting one pulse / bit every eighth position of a normal UWB pulse. The position of each pulse can be randomly changed around this eighth position, for example, between the seventh and tenth positions (+ / -2 positions) or between the fifth and twelfth positions (+ / -4 positions), creating many different inter-pulse distances. The power of false peaks in the cross-correlation is divided among different false peaks, reducing their average energy / height. The periodicity of eight positions around which time hopping is applied is due to historical reasons and can be further increased to allow time hopping to be applied across more positions. However, this is only one embodiment. Other implementations of multiple different inter-pulse distances within the transmitted covert distance pulse sequence can also be used. Figure 13 shows the cross-correlation results 6 of a covert distance pulse sequence SEC transmitted with time hopping (position changes of + / - 4 positions) (indicated by small dots) and the cross-correlation results 5 of a standard covert distance pulse sequence SEC with always the same inter-pulse distance (indicated by large circles). The x-axis shows the time delay between the correlation functions, and the y-axis shows the magnitude of the cross-correlation relative to the maximum peak in decibels (dB). The cross-correlation results are primarily shown within the early path time window 7, which is used to determine potentially weaker early paths. It can be clearly seen that the number of false peaks 6 increases with time hopping, but their average peak value decreases, while the fewer false peaks 5, the higher their value.This is also indicated by the maximum false peak 8 appearing in the simulation without time hopping, which is 6 or 7 dB higher than the maximum false peak 9 appearing in the simulation with time hopping. The attenuation can be further increased by increasing the number of inter-pulse distances in the time hopping. This attenuation of 6 to 7 dB is very important because it enhances the ability to detect the real path above the false path floor. Without time hopping, there would be several false peaks (including one in the early path time frame) above the -30 dB noise level, which could lead to incorrect early path detection. The receiver RX must explicitly know the time hopping positions used to determine the correct expected secret distance pulse sequence in step S2 and / or to determine the time instants of the pulses in step S5. In a preferred embodiment, the time hopping positions of each pulse are randomly selected, i.e., different for each secure distance message M. The random time hopping positions used can be transferred from the transmitter TX to the receiver RX. Preferably, the random time hopping positions used are determined based on distance bit information. Therefore, the receiver RX can use the distance bit information to determine the secret distance bit sequence (and the corresponding secret distance pulse sequence) and the position of each pulse in the secret distance pulse sequence. The distance bit information can be, for example, seed information used to determine the position of the secret distance bit sequence and a bit sequence indicating the position of the pulse in the secret distance pulse sequence (corresponding to the secret distance bit sequence).
[0087] In a second improved embodiment, after detecting the strongest peak in the cross-correlation in step S4, a mismatch pulse sequence is generated to reduce the false peaks in the early path time frame. The mismatch pulse sequence corresponds to a covert distance pulse sequence in which one or more pulses are inverted to opposite values. Multiple mismatch pulses are tried, and their cross-correlation with the received UWB signal or with a theoretically expected covert distance pulse sequence is calculated within the early path time frame. One of the multiple tried mismatch pulses is selected to reduce the false path within the early path time frame. Fewer inverted pulses can significantly change the false path but do not significantly affect the true early path. Therefore, the selected mismatch pulse sequence is used to calculate the cross-correlation of the UWB signal within the early path time frame, and the early path is detected in this newly calculated cross-correlation.
[0088] In a third improved embodiment, the secret distance pulse sequence has a known portion and a secret portion, and the known portion has a special code, preferably an IPATOV code, that reduces or eliminates false peaks. The special code preferably includes a sequence of code values, which may be a first value, a second value, and a third value. The first value corresponds to a first bit value (e.g., 1) or a first pulse value, and the second value corresponds to a second bit value (e.g., 0) or a second pulse value. Once such a special code is transmitted, subsequent code values are transmitted at periodic times or positions, i.e., two subsequent code values are transmitted with the same time distance between them. All positions of the special code having a third value mean that no pulse is transmitted at this position. In a preferred embodiment, the pulses of the secret portion are transmitted at some or all positions of the special code corresponding to the third value. The positions (of the third value) of the special code where the secret pulses are transmitted can be fixed; only their values change each time. In another embodiment, the positions (of the third value) selected for transmitting the secret pulses can change from message to message. This embodiment has the advantage that spurious peaks are reduced due to the properties of the special code as opposed to a completely random sequence.
[0089] Any (sub)combination of the first, second and third improved embodiments is possible. For example, the time-hopped secret pulse sequence can be mismatched to reduce false peaks. It is also possible to apply time hopping to the position of the secret pulse in the special code (without changing the time position of the known pulse). This brings together the false path reduction effects of the different improved embodiments.
[0090] 11 illustrates the use of the above-described secure distance message M for UWB distance measurement, which shows a system and method for secure distance measurement using the above-described method of secure time-of-arrival measurement.
[0091] The system and / or method comprises a verifier V and a prover P.
[0092] The verifier V transmits a challenge message C having a challenge distance pulse sequence SECv to the prover P. The challenge message C is the secure distance message described above. The challenge distance pulse sequence SECv is the distance pulse sequence defined above. For the secure distance message C, the verifier V acts as a transmitter TX and the prover P acts as a receiver RX. The prover P receives the challenge message C, determines the arrival time of the challenge message C based on the challenge distance pulse sequence SECv, and verifies the authenticity of the verifier V or the challenge message C based on the same challenge distance pulse sequence SECv, as described in more detail in the above method shown in FIG. 10. The challenge distance pulse sequence SECv is preferably transmitted within the second information (sub)part B. The challenge distance bit information (corresponding to the challenge distance pulse sequence SECv) can be transmitted within the first information part and preferably encrypted. The encryption is based on a common key, preferably a symmetric key, known by both the verifier V and the prover P. However, it is also possible for the first distance bit information to be transmitted within a separate message before or after the first message C. The first information part A (payload P1) of the challenge message C preferably contains the identifier (SSID) of the verifier V / transmitter TX, the identifier (SSID) of the prover P / receiver RX, the SHR and / or the PHR.
[0093] The prover P determines the prover time difference DTp based on the arrival time of the challenge message C and the time it takes to return the response message R to the verifier V.
[0094] The prover P returns a response message R to the verifier V. Thus, the prover P is here a transmitter TX, the response message R is a secure distance message M, and the verifier V is a receiver RX. The verifier V receives the response message R, determines the arrival time of the response message R based on the response distance pulse sequence SECp, and verifies the authenticity of the prover P or the response message R based on the same response distance pulse sequence SECp, as described in more detail in the above method shown in FIG. 10. The response message R, preferably the second information (sub)part B, includes the response pulse sequence SECp. The response pulse sequence SECp is the distance pulse sequence defined above. The prover P transmits, preferably within the first information part A of the response message R, response distance bit information corresponding to the prover time difference DTp and / or the response distance pulse sequence SECp. The first information part A (payload P1) of the response message R preferably includes an identifier (SSID) of the verifier V / receiver RX, an identifier (SSID) of the prover P / transmitter TX, an SHR, and / or a PHR.
[0095] The verifier V determines a verifier time difference DTv between sending the challenge message C, in particular the challenge pulse sequence SECv, and receiving the reply message R, in particular the reply pulse sequence SECp, at the verifier V. The verifier V then calculates the time of flight ToF as the difference between the verifier time difference DTv and the prover time difference DTp. The prover time difference DTP is preferably received from the prover P. However, it is also possible that the prover time difference is fixed to a certain time difference that the prover P waits each time before sending back the reply message R.
[0096] If the time of flight ToF or the corresponding distance is less than a threshold, and if the authenticity of the prover P and the verifier V is confirmed at the respective receiver RX, then a particular request, e.g., opening a car door, can be approved. If the prover P cannot verify the authenticity of the verifier V, or if the verifier V cannot verify the authenticity of the prover P, then the process can be stopped or the particular request is rejected.
[0097] A wake-up message can be sent from the verifier V to the prover P to turn on the receiver RX of the prover P, especially when the first information part A is transmitted in a very power-consuming UWB channel.
[0098] It is to be understood that the invention is not limited to the described embodiments and that variations can be applied without departing from the scope of the claims.
Claims
1. 1. A method for UWB secure time-of-arrival measurement of a secure distance message, transmitting a distance pulse sequence corresponding to a secret distance bit sequence in a UWB channel from a transmitting device to a receiving device, the method comprising: providing (S1) at the receiving device the secret distance bit sequence; determining (S2) at the receiving device, upon receiving the secure distance message (M), an expected secret distance pulse sequence (SEC) corresponding to the secret distance bit sequence expected to be received in the UWB channel; receiving (S3) the secure distance message (M) from the transmitting device (TX) at the receiving device (RX), the received secure distance message (M) comprising a UWB signal including the secret distance pulse sequence (SEC) corresponding to the secret distance bit sequence; determining (S4) a time of arrival of a path of the secure distance message (M) at the receiving device (RX) based on the expected secret distance pulse sequence (SEC) and the UWB signal containing the secret distance pulse sequence (SEC) of the received secure distance message (M); determining (S5) the time instants of the pulses of the expected secret distance pulse sequence (SEC) of the path in the UWB signal based on the determined arrival times of the path of the secure distance message (M); (S6) decoding the respective bit values from the UWB signal at the determined times of each UWB pulse value to determine the bit sequence received over the path of the secure distance message (M); a step (S7) of comparing the received bit sequence decoded from the UWB signal with the secret distance bit sequence provided to verify the authenticity of the transmitting device (TX) and the integrity of the time-of-arrival measurement; A method comprising:
2. the step of comparing the received bit sequence decoded from the UWB signal with the provided secret distance bit sequence, determining a number of errors in a received bit sequence relative to said secret distance bit sequence; deeming the transmitter verified if the determined number of errors is below a threshold; Including, The method of claim 1.
3. At each determined time point of the UWB signal, bits at this time point are decoded from a time window of the UWB signal around the time point, the time window being 16 nanoseconds or less. The method of claim 1.
4. the same pulse of the secret ranging pulse sequence (SEC) is used once at the receiving device to detect the time of arrival and once at the receiving device to decode the bit value of the pulse; The method of claim 1.
5. the Secret Distance Pulse Sequence (SEC) is transmitted in the UWB channel using a time hopping method with two or more different inter-pulse distances, preferably three or more different inter-pulse distances; The method of claim 1.
6. the time of arrival of the secure range message at the receiving device (RX) is determined based on a cross-correlation between the expected secret range pulse sequence (SEC) and the received UWB signal. The method of claim 1.
7. an early path time window (7) before the maximum of the cross-correlation is determined, and a weaker early path is detected within the early path time window (7); The method of claim 6.
8. a mismatch distance pulse sequence is calculated that varies some pulse values of the secret pulse sequence to minimize spurious peaks in the cross-correlation within the early path time window (7); and the weak early path is determined based on the cross-correlation within the early path time window (7) between the mismatch distance pulse sequence and the received UWB signal. The method of claim 7.
9. each pulse of the secret distance pulse sequence has a first pulse value or a second pulse value, the secret distance pulse sequence includes known pulses and secret pulses, a known pulse is a pulse whose pulse value is known, a secret pulse is a pulse whose pulse value is secret, the known pulse follows a special code that reduces or removes false peaks, the special code includes a first code value corresponding to the first pulse value, a second code value corresponding to the second pulse value, and a third code value corresponding to sending no pulse, and the secret pulse is transmitted at at least some of the third code values within the special code. The method of claim 1.
10. the secure distance message (M) comprises a first information part (A; B1) followed by a second information part (B; B1, B2, ..., BY), the second information part (B; B1, B2, ..., BY) comprising the secure distance bit sequence, the first information part (A; B1) being used to detect the secure distance message (M) in a received signal and / or to determine a clock offset between a system clock of the receiving device (RX) and a system clock of the transmitting device (TX), The method of claim 1.
11. the secure distance message (M) comprises a message frame in the physical layer, the first information part (A) being transmitted in a narrowband channel and the second information part (B; B1, B2, ..., BY) being transmitted after the second information part in the UWB channel, the time relationship between the first information part (A) and the second information part (B; B1, B2, ..., BY) being defined by the message frame in the physical layer, or the secure distance message (M) comprises a message frame in the physical layer, the first information portion (B1) being transmitted within a first UWB frequency-time portion and the second information portion (B2, B3, ..., BY) being transmitted within at least one second UWB frequency-time portion, each UWB frequency-time portion being defined as a portion of the UWB frequency-time domain limited by a TX budget of the UWB channel, and the first UWB frequency-time portion being different from the second UWB frequency-time portion; The method of claim 10.
12. the second information portion (B1, B2, ..., BY) comprises a plurality of second information sub-portions (B1, B2, ..., BY) transmitted within different UWB frequency-time portions, each different UWB frequency-time portion being defined as a portion of the UWB frequency-time domain limited by the TX budget of the UWB channel, and the secret ranging pulse sequence (SEC) comprises a plurality of different secret ranging pulse sub-sequences (SEC1, SEC2, ..., SECY) transmitted within the different second information sub-portions (B1, B2, ..., BY); The method of claim 11.
13. the secret ranging pulse sequence (SEC) comprises a plurality of different secret ranging pulse subsequences (SEC1, SEC2, ..., SECY) transmitted within different UWB frequency-time portions of the UWB channel; The method of claim 1.
14. A method for distance measurement between a verifier (V) and a prover (P), said method comprising: sending a challenge message (C) having a challenge pulse sequence (SECv) from the verifier (V) to the prover (P); sending a response message (R) having a response pulse sequence (SECp) from the prover (P) to the verifier (V); 2. The method according to claim 1, further comprising the steps of: securely determining the time of arrival of the response message (R) at the verifier (V); measuring the distance (ToF) between the verifier (V) and the prover (P) based on the verifier time difference (DTv) between sending the challenge message (C) from the verifier (V) and the determined arrival time of the response message (R); A method comprising:
15. The prover (P) securely determines the arrival time of the challenge message (C) at the prover (P) according to the method of claim 1, and determines a prover time difference (DTp) between the determined arrival time of the challenge message (C) and sending of the response message (R) from the prover (P), a first information part (A) of the response message (R) containing prover time information (DTp), and the distance between the verifier (V) and the prover (P) is determined based on the verifier time difference (DTv) and the prover time difference (DTp).
15. The method of claim 14.