Reliable distance measuring system

KR103003587B1Active Publication Date: 2026-08-11KONINKLIJKE PHILIPS NV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
KR1020217029737
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-02-19
Filing Date
2020-02-17
Publication Date
2026-08-11
Estimated Expiration
2040-02-17

Smart Images

  • Figure 112021106739216-PCT00042_ABST
    Figure 112021106739216-PCT00042_ABST
Patent Text Reader

Abstract

The device is arranged to measure distance according to a ranging protocol using a measurement message from the second device. Based on the first arrival time of the measurement message, a first distance (151) between the first device (110) and the second device (120) is determined. The third device (130) operates as a cooperating device located at the trusted distance (150). The cooperating device determines the third arrival time of the same measurement message and transmits supporting data based on the third arrival time to the first device. The first device obtains a third distance (153) between the third device and the second device using the supporting data. Subsequently, a verification test is performed on the first distance (151), the trusted distance (150), and the third distance (153). The first distance is reliable when the distances correspond to an actionable spatial constellation (100) of the devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention relates to a device for measuring distance through wireless communication between a first device and a second device for wireless communication, wherein the wireless communication includes a ranging protocol for determining the distance between the first device and the second device based on the arrival time of a measurement message from the first device, and the protocol includes transmitting a measurement message by the second device. The present invention also relates to a distance measuring method and computer program products for use in a device or server.

[0002] The present invention generally relates to the field of positioning systems, and more specifically provides various devices and methods for verifying distance measurements, as well as corresponding computer program products. Background Technology

[0003] The need for location awareness services may exist in indoor areas. For example, wireless services may be provided to mobile devices in close proximity within large indoor complexes such as hospitals, universities, parking lots, shopping malls, and / or offices. Indoor location systems can provide services to consumers (hereinafter referred to as end users); services that end users will ultimately rely on. Such location-based services may be provided only to nearby devices, that is, devices within a limited distance from the service-providing device. In an additional example, an electronic wireless car door key must be close to the car before the door can be opened. A cheating door key can be tampered with using a distance measurement protocol so that the door can be opened when the key is much further away from the car than the required distance.

[0004] Therefore, reliability is important for distance measurement. In this context, reliability means that the responding device provides reliable and accurate distance or time-of-reach data as measured, in contrast to cases where distance or time-of-reach data is tampered with or falsified to intentionally produce a distance different from the actual distance for the responding device.

[0005] A known distance measurement system has recently been developed as a version of the wireless communication protocol defined in IEEE 802.11, and reference [802.11]. This version includes a ranging protocol for determining the distance between two devices and enables accurate distance measurement and the determination of the location of devices up to 1 meter or even lower resolution. The ranging protocol, referred to as the Fine Timing Measurement (FTM) procedure, is defined in Chapter 10.24.6 of [802.11] and determines the Round-Trip Time (RTT) of the signal by accurately measuring the arrival times of measurement messages, and derives the distance based on the measured arrival times of messages combined with the transmission timing. For example, assuming that a wireless signal propagates in free air at the speed of light, it takes 3.3 ns for radiation to cover a distance of 1 meter, whereas a Wi-Fi station can reach a time granularity of about 0.1 ns.

[0006] Note that this application is in the field of ranging protocols. These can correspond to what are known as time-of-flight measurements, which measure the time it takes for electromagnetic radiation to travel between a transmitter and a receiver. These are fundamentally different from distance measurements performed in the IP / HTTP protocol, known as ping times, which measure the time it takes for an IP data packet to be transmitted from a source device to a sink device in a network, and such transmission may involve multiple intermediate devices.

[0007] In order for two devices to determine the distance between each other based on time-of-arrival measurements, they need to operate according to a ranging protocol. For example, an initiating wireless device may initiate a request to start round-trip time measurements. A responding device may determine the interval between sending a message and receiving a request, and transmit the time interval to the initiating device.

[0008] However, by transmitting incorrect data, a device can claim to be closer or farther away than it actually is. Additionally, measurement messages may need to be transmitted at a predetermined time, for example, according to a timing grid. A malicious device may intentionally transmit measurement messages at different times. Such malicious behavior can lead to potential abuse of location-based services if the initiating device trusts the determined distance / location information as accurate. For example, location-based services may automatically initiate several transactions.

[0009] Therefore, in the disclosed systems, measurements or received distance data can be tampered with and thus cannot be fully trusted.

[0010] A first device that measures the distance to a second device using 802.11 Time Measurement (TM) or Fine Timing Measurement (FTM) methods may attempt to protect itself from forged time of arrival (TOA) and time of departure (TOD) data by malicious devices, and malicious devices want to be shown as different distances, particularly as shorter than they actually are.

[0011] Contrary to such behavior, the distance measurement system may involve a third device, and the third device also performs distance measurements to determine a second distance between the potentially malicious second device and the third device. By comparing the distances of both and knowing and trusting the distance between the first device and the cooperating device, a verification test can be performed on both determined distances. However, it may be more complex, but still possible, for a malicious device to tamper with both distance measurements so that they both pass the verification test.

[0012] The object of the present invention is to provide a system that makes time-of-arrival-based distance measurement more reliable. To this end, devices and methods as defined in the appended claims are provided.

[0013] According to a first aspect of the present invention, a device for measuring distance through wireless communication between a first device and a second device for wireless communication is provided, wherein the wireless communication includes a ranging protocol for determining the distance between the first device and the second device based on the arrival time of a measurement message from the first device, and the protocol includes transmitting a measurement message by the second device;

[0014] The device is,

[0015] - A first transceiver for transmitting and receiving messages,

[0016] - Includes a first message processor, and the first message processor

[0017] - Process messages according to the ranging protocol;

[0018] - Determine the first arrival time of a measurement message at the first device, and

[0019] - Arranged to determine a first distance between a first device and a second device based on a first arrival time;

[0020] The first message processor is arranged to communicate with a third device operating as a cooperative device located at a trusted distance from the first device, and

[0021] To evaluate the determined distance,

[0022] - Receive support data from the cooperating device based on the third arrival time of the first message at the cooperating device, and

[0023] - Obtain a third distance between the third device and the second device using support data, and

[0024] - Arranged to perform verification tests for a first distance, a trusted distance, and a third distance, and the verification test accepts the first distance as trusted when the distances correspond to an executable spatial constellation of a first device, a second device, and a cooperating device.

[0025] According to an additional aspect, a method for measuring distance through wireless communication between a first device and a second device is provided, and the method

[0026] - A step of obtaining a first distance between a first device and a second device based on a first arrival time of a measurement message at a first device,

[0027] - Includes the step of communicating with a third device operating as a cooperative device located at a trusted distance from the first device, and

[0028] The third device is

[0029] - Determine the third arrival time of the measurement message at the third device, and

[0030] - Arranged to provide supporting data based on the third time of arrival;

[0031] This method, in order to evaluate a determined distance,

[0032] - A step of obtaining a third distance between a third device and a second device using support data,

[0033] - Includes the step of performing a verification test for a first distance, a trusted distance, and a third distance, wherein the verification test accepts the first distance as trusted when the distances correspond to an executable spatial constellation of a first device, a second device, and a cooperating device.

[0034] According to an additional aspect, a method is provided for operating as a cooperative device in a distance measurement via wireless communication between a first device and a second device, wherein the cooperative device is located at a trusted distance from the first device. The wireless communication includes a ranging protocol for determining the distance between the first device and the second device based on the arrival time of a measurement message from the first device, and the protocol includes transmitting a measurement message by the second device. The first device is arranged to obtain a first distance between the first device and the second device based on the first arrival time of a measurement message from the first device. The present method comprises

[0035] - A step of determining the third arrival time of a measurement message in a cooperative device, and

[0036] - Includes the step of providing supporting data based on a third time of arrival. A first device is arranged to obtain a third distance between a cooperating device and a second device using the supporting data to evaluate a determined distance, and to perform a verification test for a first distance, a trusted distance, and a third distance, and the verification test accepts the first distance as trusted when the distances correspond to a viable spatial constellation of the first device, the second device, and the cooperating device.

[0037] The above features have the effect of enabling the first device to determine the distance according to the ranging protocol based on the first arrival time of a measurement message transmitted by the second device when the second device participates in the ranging protocol. Additionally, the third device determines the third arrival time of the same measurement message at the third device. The third device is located at a certain distance from the first device, and the certain distance is known to the first device and is trusted as reliable. Such a distance is referred to herein as the trusted distance. The trusted distance may be predetermined, measured separately, or entered by a user. Such a third device may be referred to herein as a cooperating device.

[0038] Note that the third device operating as a cooperative device does not perform additional distance measurements according to the ranging protocol using some additional measurement messages. Instead, the third device determines a third arrival time of the same measurement message at the third device and cooperates to transmit supporting data based on the third arrival time to the first device. For example, the supporting data may include third arrival time data regarding a reference clock or timing grid, or regarding the reception of some other messages also received by the first device. Alternatively, or additionally, the supporting data may include third distance data, and the third device may determine a third distance between the third device and the second device by using additional received messages and a trusted distance.

[0039] Upon receiving support data, the processor is able to use the support data to obtain a third distance between the third device and the second device. Subsequently, a verification test is performed for the first distance, the trusted distance, and the third distance. Advantageously, the verification test may accept the first distance as reliable when the distances correspond to a viable spatial constellation of the first device, the second device, and the cooperating device.

[0040] In one embodiment, the verification test includes a cosine law test or a triangle inequality test for a feasible spatial constellation. Advantageously, the test proves whether a spatial constellation of triangles can have their respective side lengths.

[0041] In one embodiment, the ranging protocol includes exchange messages that are encrypted based on key data, and a first message processor is arranged to share key data with a cooperating device so that a third message processor can encrypt the messages according to the ranging protocol. Advantageously, encrypting messages between the first device and the third device protects such messages from being potentially tampered with by a second malicious device.

[0042] In one embodiment, the first message processor is arranged to determine a trusted distance according to a ranging protocol. Advantageously, prior to actual measurements for the second device, the trusted distance is determined using the same ranging protocol.

[0043] In one embodiment, the device includes a clock unit for providing a time reference to determine the arrival times, and a first message processor is arranged to synchronize the time reference with a corresponding clock unit in a cooperating device. Advantageously, the time reference is shared between the first device and the third device. The third arrival time may be determined in relation to the time reference, which allows supporting data to include the third arrival time so determined and to be available by the first device in this way.

[0044] In one embodiment, the ranging protocol includes a first device, the first device operates as an initiating device and transmits an initiating message to a second device, while upon receiving the initiating message, the second device transmits a measurement message. A first message processor is arranged to exchange role-change data with a third device so that the third device can operate as an initiating device for distance measurement. When the third device receives the role-change data,

[0045] - Based on the second measurement message, obtain the third distance between the third device and the second device according to the ranging protocol, and

[0046] - It is arranged to transmit third support data representing the third distance to the first device. The first message processor is

[0047] - When the first device receives the second measurement message, the second distance between the first device and the second device is determined, and

[0048] - Receive third support data from a third device, and

[0049] - It is arranged to perform a verification test using the second distance and the third support data as well. Advantageously, by determining the second distance and verifying both distances together, it becomes more difficult for the second device to consistently tamper with both distance measurements.

[0050] In one embodiment, a third message processor is arranged to determine a third signal strength of at least one message received from a second device and is arranged to include the third signal strength data in support data for a first device. A first message processor is arranged to determine a first signal strength of at least one message received from a second device and to verify whether the determined distances are reliable by comparing the first signal strength and the third signal strength at the determined distances with their respective expected signal strengths. Optionally, both the first device and the third device can measure the signal strength of the same message from the second device. Advantageously, an additional independent mechanism is added to enable verification of the determined distances.

[0051] In one embodiment, the first message processor is arranged to require the second device to execute a different security protocol when the determined distance is evaluated as unreliable. Advantageously, alternatively, or additionally, the first message processor is arranged to request additional distance measurements using a different ranging protocol and / or a different type of wireless communication when the determined distance is evaluated as unreliable. Alternatively, or additionally, the first message processor is arranged to deny or restrict access to at least some data and / or at least one function in the first device when the determined distance is evaluated as unreliable. Advantageously, malicious access to or use thereof of any function or data in the first device is prevented.

[0052] According to a further aspect of the present invention, a system for reliable distance measurement comprises a device as described above, a third device, and a fourth device, wherein the fourth device, operating as a second cooperative device, is located at a second trusted distance from the first device and at a third trusted distance from the third device. The fourth device comprises a fourth wireless receiver for receiving messages,

[0053] It includes a fourth message processor arranged to determine a fourth arrival time of a measurement message at a fourth device and to transmit fourth support data based on the fourth arrival time to a first device. The first message processor is arranged to receive the fourth support data from a second cooperating device, obtain a fourth distance between the fourth device and the second device using the fourth support data, and perform a verification test using the second trusted distance and the fourth distance. Advantageously, by determining the additional distance and verifying all distances together, it becomes more difficult for the second device to consistently manipulate the distances.

[0054] Optionally, the verification test may use a combination of triangle inequalities for at least two spatial constellations, each constellation comprising two devices from a set of a second device, a first device, and cooperative devices. Optionally, the first message processor may be arranged to verify whether a first location of the second device according to the first spatial constellation corresponds to a second location of the second device according to the second spatial constellation.

[0055] Optionally, the first message processor may be arranged to perform a verification test using a mismatch check to detect whether all determined distances are greater than 0.

[0056] Optionally, the first message processor may be arranged to perform a verification test based on a setup in which the third device and the fourth device are arranged such that the trusted angle between the line from the third device to the first device and the line from the fourth device to the first device is at least 90 degrees.

[0057] Optionally, the first message processor may be configured to perform a verification test based on a setup in which the third device and the fourth device are arranged opposite each other with respect to the first device.

[0058] Optionally, the first message processor may be arranged to perform a verification test based on a setup corresponding to a second trusted distance.

[0059] In one embodiment, the system includes at least one additional device operating as an additional cooperative device, and the third device, the fourth device, and at least one additional device are arranged in a plane at the edges of the polygon, the first device is inside the polygon, and the first message processor is

[0060] - Arranged to perform a verification test using a combination of triangle inequalities for at least two spatial constellations, each constellation includes two devices from a set of a second device, a first device, and cooperative devices. Advantageously, by determining the additional distance and verifying all distances by combining them, it becomes more difficult for the second device to consistently manipulate the distances.

[0061] In one embodiment, the method comprises the step of instructing a first device to operate as an initiating device to provide a first time of arrival or a first distance. Alternatively or additionally, the method comprises the step of instructing a third device to operate as a cooperating device to provide supporting data based on a third time of arrival. Effectively, control of distance measurement is now performed by the instruction.

[0062] It should be noted above that, for reasons of clarity, a first device performing distance measurement and distance reliability verification has been described. However, it is also possible for the first device, a third device and / or additional cooperative devices to provide all required information to the control device performing distance measurement and distance reliability verification.

[0063] The method according to the present invention may be implemented as a computer-implemented method on a computer, on dedicated hardware, or in a combination of both. Executable code for the method according to the present invention may be stored in a computer program product. Examples of computer program products include memory devices such as memory sticks, optical storage devices such as optical discs, integrated circuits, servers, online software, etc. A computer program product may include non-transient program code means stored on a computer-readable medium to perform the method according to the present invention when said program product is executed on a computer. In an embodiment, the computer program includes computer program code means adapted to perform all steps or stages of the method according to the present invention when the computer program is executed on a computer. Preferably, the computer program is implemented on a computer-readable medium. A computer program product is provided that is downloadable from a network and / or stored on a computer-readable medium and / or a microprocessor executable medium, and the product includes program code instructions for implementing the method as described above when executed on a computer.

[0064] Another aspect of the present invention provides a method for making a computer program available for download, for example, included in a location-based application. This aspect is used when the computer program is uploaded, for example, to Apple’s App Store, Google’s Play Store, or Microsoft’s Windows Store, and when the computer program is available for download from such store.

[0065] Further preferred embodiments of the devices and methods according to the present invention are given in the appended claims, the disclosures of which are incorporated herein by reference. Brief explanation of the drawing

[0066] These and other aspects of the present invention will be apparent from the embodiments described by example in the following description and with reference to the accompanying drawings, and will be further explained with reference to such embodiments. FIG. 1 illustrates devices for wireless communication and distance measurement. Figure 2 illustrates a spatial constellation of a device for wireless communication and a cooperative device. Figure 3 illustrates a spatial constellation of two devices for wireless communication. Figure 4 illustrates an additional spatial constellation of two devices for wireless communication. FIG. 5 illustrates a spatial constellation having two cooperative devices. FIG. 6 illustrates a second spatial constellation having two cooperative devices. FIG. 7 illustrates an additional spatial constellation having two cooperative devices. Figure 8 illustrates a method for measuring distance. FIG. 9 illustrates a method of operating as a cooperative device in distance measurement. FIG. 10a illustrates a computer-readable medium. Figure 10b illustrates a schematic diagram of a processor system. The drawing is entirely schematic and is not drawn to a fixed scale. In the drawing, elements corresponding to elements already described may have the same drawing reference numeral. Specific details for implementing the invention

[0067] The distance measurement methods and devices using wireless communication described below provide at least a basic function, namely, providing information about the current distance between a mobile device and, for example, another device in a fixed position. Various protocols are now described as examples of appropriate ranging protocols using the arrival times of measurement messages, which can be improved using the embodiments described later.

[0068] A first example of distance measurement is described in [802.11]. Clause 11.24.6 specifies the fine timing measurement (FTM) procedure. The FTM mechanism is intended to measure the absolute time difference between the clocks of two devices so as to also compensate for the time it takes for RF waves to travel from one device to another at the speed of light. In the FTM procedure, one of the devices transmits the timestamps of its clock to the other device in the same way that the other device can measure the round-trip time (RTT) between the two devices (described later). Distance measurement between two devices using 802.11 (Wi-Fi) is performed by measuring the round-trip time (RTT) using the fine timing measurement (FTM) procedure specified in Clause 11.24.6 of [802.11], multiplying the RTT by the speed of light, and dividing by 2.

[0069] The following is a description of FTM in [802.11], with reference, for example, to FIGS. 11 through 35, FIGS. 11 through 36, FIGS. 11 through 37 and the surrounding text. The numbering of the timestamps below follows FIGS. 11 through 36. The initiating STA (station) wants to know the distance or RTT to another STA, the responding STA. To achieve this, the initiating STA sends an initial FTM request to the responding STA. The responding STA sends the FTM_1(0, 0) message to the initiating STA and measures the exact transmission time. The responding STA stores this time as t1_1. The initiating STA measures the reception of the FTM_1(0, 0) message as t2_1. This measures the transmission time of the resulting ACK as t3_1. However, the initiating STA cannot yet use the values ​​t2_1 and t3_1.

[0070] The response STA measures the reception time of the ACK received as a response to FTM_1(0, 0) and stores it as t4_1. After a short time (at least Min Delta FTM seconds), the response STA transmits FTM_2(t1_1, t4_1) and records the transmission time as t1_2. This initiating STA undergoes the same routine as described above, that is, the same routine of measuring the reception time of FTM_2(t1_1, t4_1) as t2_2 and the transmission time of the ACK as t3_2. However, at this time, the initiating STA can measure the RTT according to the following equation (11-5) from [802.11].

[0071] RTT = [ (t4_1 - t1_1) - (t3_1 - t2_1) ] (1)

[0072] Rearranging the right side of the above equation yields the following equation.

[0073] RTT = (t2_1 - t1_1) + (t4_1 - t3_1) (2)

[0074] Here, (t2_1 - t1_1) is the time it takes for an FTM frame to travel from the requesting STA to the initiating STA through the RF medium while transmitting the FTM frame, and (t4_1 - t3_1) is the time it takes for an ACK frame to travel from the initiating STA to the responding STA through the RF medium, so it can be easily seen that their sum is actually the round-trip time.

[0075] To increase accuracy, the above can be repeated, and RTT can be calculated as the average of all measurements.

[0076] t1_X is the Time of Departure (TOD). The TOD is defined in [802.11] as follows: "TOD [...] represents, in time terms, the time at which the beginning of the preamble of the last transmitted fine timing frame appears on the transmitting antenna connector." The preamble is the very beginning of the PHY frame, which means, among other things, that the transmitter does not transmit any RF energy immediately before the preamble. Therefore, the initiating STA must measure t3_X in the same way, namely, t3_X represents, in time terms, the time at which the beginning of the preamble of the last transmitted ACK frame appears on the transmitting antenna connector in response to the received fine timing frame.

[0077] t4_x is the time of arrival. The TOA is defined in [802.11] as follows: "TOA [...] represents, in time-based, the time when the start of the preamble of the Ack frame for the last transmitted fine timing measurement frame arrived at the receiving antenna connector." Therefore, the initiation STA must measure t2_X in the same way, namely, t2_X represents, in time-based, the time when the start of the preamble of the last received fine timing measurement frame arrived at the receiving antenna connector.

[0078] Therefore, the minimum time t3 - t2 is equal to the length of the received FTM(,) frame + SIFS, and the maximum time t3 - t2 is equal to the length of the received FTM(,) frame + DIFS. The lengths of the FTM(,) frames may vary. For the remainder of this specification, the following definitions are used:

[0079] - Use Lftm to represent the time length of the physical FTM frame as a result of the initiation STA measuring t2 and t3;

[0080] - The time elapsed from immediately after the last symbol of the physical FTM frame (i.e., the last symbol of the CRC check) reaches its receiving antenna connector until the TOD of the ACK frame sent by the initiator STA in response to the FTM frame, using the term, response time, or the initiator STA's response time and symbol, R. Since transmitting the ACK frame is a rather simple operation, it is likely to be performed by hardware and can therefore be constant.

[0081] Clause 11.24.5 of [802.11] specifies the timing measurement (TM) procedure. Although there are some differences from the FTM procedure, the most notable is the better resolution of the time stamps, which, in principle, enables more accurate distance measurements. The following examples can be used for TM in the same way as described herein for FTM.

[0082] An additional example of a distance measurement system similar to FTM is described in U.S. Patent No. 8762727B2. The difference is that the initiator STA is referred to as the source node and the responder STA is referred to as the target node, and the source node measures t1 and t4 and the target node measures t2 and t3 and transmits them to the source node.

[0083] An additional example of a distance measurement system is described in 3GPP as OTDOA (Observed Time Difference Of Arrival), and refers to [OTDOA], a positioning feature introduced in rel9 E-UTRA (LTE radio), and references [36.nnn] as described below. It is a multi-faceted method in which a User Equipment (UE) measures the time difference between several specific signals, called Positioning Reference Signals (PRS), from multiple eNodeBs (i.e., base stations) and reports these time differences to a specific device in the network, the location server (the Evolved Serving Mobile Location Center - E-SMLC). Based on these time differences and knowledge of the eNodeB locations, the E-SMLC calculates the position of the UEs. A description of the LTE Positioning Protocol (LPP) can be found in specification [36.355]. Precise details of PRS signals can be found in Section 6.10.4 of [36.211], and simple OTDOA procedures can be found in the descriptions of RAN5 OTDOA test cases in Section 9 of the [37.571-1] specification. As with measurements for Wi-Fi localization, mobile devices can falsify these OTDOA reports to appear on the network wherever they wish. The examples below can be used to protect against this type of cheating. Another term for the same measurements performed in OTDOA by the UE is RSTD (Reference Signal Time Difference). The accuracy requirements for RSTD measurements are specified in [36.133].

[0084] An additional example of distance measurement in 3GPP is based on the arrival times of messages relative to a time grid and is referred to as Enhanced Cell ID based, or E-CID. Cell ID based methods were already available prior to rel9. Enhanced Cell ID combines several already available measurements, some of which have increased accuracy requirements to improve positioning accuracy capabilities. Enhanced Cell ID, E-CellID, or E-CID is a positioning feature introduced in rel9 E-UTRA (LTE radio). The UE reports the serving cell ID, timing advance with respect to the serving cell (the difference between its transmit and receive times), reference (narrowband) signal received power (RSRP / NRSRP), and (narrowband) reference signal received quality (RSRQ / RSRQ) to the network (to the location server, the Evolved Serving Mobile Location Center (E-SMLC), via the serving cell or eNodeB). RSRP / NRSRP and RSRQ / RSRQ may be measured and reported from any neighboring cell, but the timing advance is measured only for the primary cell (serving cell). The serving cell or eNodeB may report additional information, such as the angle of reach, to the ESMLC. The ESMLC estimates the UE position based on this information and its knowledge of the cell positions.

[0085] Measuring timing advance is as follows. In LTE or GSM, a cell transmits a frequency-time grid of transmission or reception opportunities at fixed timing. In the case of LTE, the individual frequencies are the frequencies of OFDM subcarriers, typically spaced 15 kHz apart. The time domain consists of consecutive frames of 10 ms, each frame consisting of 10 subframes, and each subframe consisting of two slots of 0.5 ms. This frequency-time grid is maintained by the cell with very strict timing. For each grid element, the cell can broadcast to all mobile devices within range or to a single specific device. For some of the grid elements (frequency, subframe combination, or sometimes frequency-slot combination), the cell will always transmit as defined in the 3GPP specifications. Therefore, these grid elements are ideally suited for transmitting system information to mobile devices within the cell, as is the purpose of each flexibly usable grid element. In each of the other grid elements, and thus the elements that can be used more flexibly, the cell may be broadcasting to all mobile devices within the range, transmitting to a specific mobile device, or granting a specific mobile device permission to transmit to the cell or other mobile devices within the cell.

[0086] Because it takes time for RF waves to travel from the cell to the mobile device (approximately 300 meters per microsecond), the grid will appear to be delayed to the mobile device by this travel time. Assume this travel time is t seconds. When the mobile device starts transmitting exactly at the beginning of the subframe for which transmission is allowed, it starts transmitting t seconds later than the beginning of the subframe at the cell. It takes another t seconds for the signal transmitted by the mobile device to reach the cell. Therefore, the cell receives the transmission from the mobile device after 2t seconds, rather than starting exactly at the beginning of the subframe assigned to it. By measuring this delay, the cell can determine the distance to the mobile device.

[0087] When a mobile device is far from a cell, interference may occur because the end of the mobile device's transmission in a subframe may arrive later than the start of the next subframe. To overcome this problem, the cell may request the mobile device to use a certain amount of timing advance, coded as a so-called TA value in a timing advance command addressed to a specific mobile device. Subsequently, the mobile device begins its transmission TA before the start of the subframe as determined by the mobile device. The maximum possible value for the timing advance is 0.67 ms, which corresponds to a distance of slightly over 100 km from the mobile device to the cell. Technical specification 3GPP TS 36.321 [36.321], Section 6.1.3.5 "Timing Advance Command MAC Control Element" describes the procedures for adjusting TA values ​​for LTE.

[0088] A mobile device that is to appear at a different distance may start transmitting earlier than expected by the frequency-time grid and the TA value received from the cell when it is to appear closer to the cell, or it may start transmitting later than expected when it is to appear further from the cell than it actually is.

[0089] Precise and accurate distance measurement is important in various applications. For example, when using Wi-Fi FTM to measure the distance from a car to a key ring via Wi-Fi, and determining that the car will open its doors when the measured distance is less than the so-called 5 meters, it is important that the actual distance to the key ring is actually less than 5 meters. Another example could be a case where a device is allowed to stream copyrighted content to another device only if the other device is not located further than a certain distance away. Precise and accurate distance measurement can also be used to prevent man-in-the-middle attacks when setting up secure, authenticated channels. This is explained in the following paragraphs.

[0090] When two devices need to secure their wired or wireless communication, they can encrypt their communication. However, this requires both wireless devices to know the same key. Diffie-Hellman [DH] is a well-known technique for establishing a secret key between two parties, and the communication between the parties to establish the secret key does not disclose any information about the established secret key to third parties. The two parties each use their own public / private key pair and exchange their public keys. Each party can calculate the secret key using their own private key, the other party's public key, and possibly some other information, such as a temporary value (random number) from each party. Each party can generate a new key pair whenever performing Diffie-Hellman or reusing a previous key pair.

[0091] When performing Diffie-Hellman over a network, the device receiving the public key for the operation does not know which device the key originated from. This can be exploited by an attacker in a so-called man-in-the-middle attack. Attacker E can impersonate the actual device B that device A intends to connect to. Attacker E performs Diffie-Hellman with device A and establishes a secret key Kae with device A. Similarly, the attacker impersonates device A for device B and establishes a secret key Kbe with device B. When a message is received from either device A or B, the attacker decrypts the message using one secret key, encrypts the message using the other secret key, and forwards it to the other device. In this way, the devices (A and B) do not notice anything unusual in their communication, except for a slight additional delay. When they inspect their communication by transmitting the same information using different communication methods and comparing the results, they will not detect any tampering in their communication. However, the attacker has complete knowledge of what they have communicated.

[0092] In the Device Provisioning Protocol (DPP), the first step is to perform DPP bootstrapping, which is a procedure to obtain trust in another device's public bootstrapping key and to ensure that it is not the public key of the man-in-the-middle device. One of the bootstrapping methods is to scan a QR code containing another device's public bootstrapping key, as displayed by the other device or printed on the other device. The other device may also scan the first device's QR code (mutual authentication). Subsequently, the bootstrapping key(s) are used in the DPP authentication protocol, where it is checked whether the other device also possesses the private key belonging to the public bootstrapping key. If the public bootstrapping keys within the DPP were exchanged via Wi-Fi (any form of Wi-Fi, e.g., Neighbor Awareness Network (NAN)), they cannot be trusted because they may have been transmitted by any device within the RF range. If DPP is used continuously, the DPP authentication protocol will lead to the establishment of a common shared key Ke, but the device does not know whether it is sharing this key with the intended device or with a man-in-the-middle device. Similarly, when using Opportunistic Wireless Encryption (OWE), public keys are exchanged over Wi-Fi and using Diffie-Hellman, and a common shared key is established for the encryption of subsequent communications between two devices.

[0093] However, a method to limit the probability of setting up a common shared key with a man-in-the-middle device is for devices to measure the distance to another device, and if that distance is less than a certain distance, e.g., a few meters, as determined by the device's rules or its user, they trust the public key received from the other device. In this case, the user will know that the device that transmitted the public key via Wi-Fi—that is, the intended device or the man-in-the-middle device—is located within a distance limit. Subsequently, the user can determine whether there are any other devices within this range besides the intended device.

[0094] Limiting the probability of setting up a common shared key with a man-in-the-middle device using distance measurement can be accomplished by first exchanging public keys over Wi-Fi and then subsequently executing an FTM procedure using FTM_X frames encrypted with the determined shared session key by calculating a shared session key by, for example, the DPP authentication protocol part of OWE or DPP (where DPP bootstrapping is performed over Wi-Fi, e.g., Wi-Fi awareness), and by encrypting fields containing t1 and t4 values ​​in FTM_X frames by OWE (Opportunistic Wireless Encryption), DPP, or some other method. If the distance to the requesting STA measured in this way is less than x meters, the initiating STA may trust the received public key and proceed to communicate further with another device using the agreed session key. In the case of DPP, the additional communication will be the DPP configuration protocol. In the case of OWE, it will be an encrypted WAN connection between the AP and the STA. The initiating STA may also ask the user whether they are certain that there is only one Wi-Fi device within the measured distance to the responding STA, and if the user confirms this, the initiating STA proceeds using the shared session key.

[0095] As previously mentioned, the response STA may have reasons to cause the initiating STA to believe that it is at a different distance than it actually is. In particular, the response STA may cause the initiating STA to believe that it is closer than it actually is by decreasing the t4_X values ​​and / or increasing the t1_x values. This is easily apparent from [802.11] and from Equation (11-5).

[0096] RTT = [ (t4_X - t1_X) - (t3_X - t2_X) ] (3)

[0097] The distance between the two devices is as follows:

[0098] d = c * RTT / 2 (4)

[0099] Here , c is the speed of light (about 3 x 10^8 m / s).

[0100] To reduce the distance measured by the initiating STA by 1 meter, the response STA is approximately the difference between t4_Z and t1_X in their measured values.

[0101] delta_t = 2 * 1 m / 3*10^8 m / s = 2 * 3.33*10^-9 s = 6.66 ns (5)

[0102] It must be reduced by that amount.

[0103] However, the response STA must be careful not to reduce the difference between t4_X and t1_X too much when reporting the measured values ​​to the initiation STA, because the initiation STA will subsequently measure a negative RTT. When the reported difference between t4_Z and t1_X is equal to the initiation STA's reaction time, that is, the difference between t3_X and t2_X, the initiation STA will measure a round-trip time of 0. Therefore, for successful cheating, it is important for the response STA to know the difference between t3_X and t2_X of the initiation STA.

[0104] As mentioned above, the difference between t3_X and t2_X of the initiating STA consists of two parts: the length (Lftm) of the transmitted FTM PHY frame and the response time R. Since the responding STA transmitted the FTM frame itself, it knows the frame's time length (Lftm). Response time R It can be known to the response STA in various ways.

[0105] It is assumed that since the cheating device somehow knows the actual distance to the initiation STA, it can accurately falsify the distance the initiation STA measures by adapting the reported t1 and t4. Therefore, as previously mentioned, the problem when performing measurements using FTM is that a malicious response STA may manipulate its reported arrival times t1 and t4 so that it appears closer or farther from the initiation STA than it actually is.

[0106] To prevent the successful falsification of distances, the initiator device may be accompanied by one or more cooperating devices located in positions known to the initiator device. The cooperating devices may use clocks synchronized with the initiator device's clock or share some other time reference. The cooperating device(s) independently measure the arrival times(s) of measurement messages and report them to the initiator device. The initiator device attempts to detect arrival time measurements manipulated by the cheating response device using attributes from triangles. For 3GPP-based systems, the initiator device and one or more cooperating devices may be implemented by base stations, and the response device is implemented by the user equipment UE.

[0107] By making distance-based measurements more reliable, it becomes a viable tool for reliable proximity-based services. Some exemplary use cases are:

[0108] - If you connect to a nearby wireless keyboard, nearby wireless storage device, nearby sensor, or nearby wireless webcam, you want to ensure that you are connecting to the correct device, rather than connecting to some man-in-the-middle device that wants to monitor, copy, or track what you are doing.

[0109] If you want to meet your friend and access their phone to exchange some photos, you want to ensure that you are definitely accessing your friend's phone, not a middleman device.

[0110] - If you want to automatically turn on some devices at home or in a store, open some doors, or allow access to some services on a person's mobile device when they are nearby, you want to verify that the location of the mobile device is accurate and that it is not a fake device claiming to be nearby.

[0111] - If you are about to initiate a transaction at a store, for example, when you are near the register, you want to ensure that you are not being subjected to a "phishing" attack, as a phishing attack can cause the user to unknowingly connect to a phishing device located further away instead of the official service provided by the store.

[0112] FIG. 1 illustrates devices for wireless communication and distance measurement. A spatial constellation (100) of devices for wireless communication includes a first device (110) and a second device (120), and the devices are physically separated by a distance (151). The first device has a first transceiver (111) and a first message processor (112) for transmitting and receiving messages. The second device has a wireless receiver (121), or a second transceiver and a second message processor (122). Additionally, the third device has a third transceiver (131) and a third message processor (132). The devices are mounted for wireless communication as schematically illustrated by antennas (113, 123, 133) connected to the transceivers (111, 121, 131).

[0113] The devices are arranged for distance measurement via wireless communication according to a ranging protocol between the first device and the second device to determine the distance between the first device and the second device, as described in more detail below. The wireless communication includes a ranging protocol for determining the distance between the first device and the second device based on the arrival time of a measurement message from the first device. The protocol may include transmitting a measurement message by the second device. In examples, the wireless communication and the ranging protocol follow [802.11], but other wireless protocols, such as Bluetooth, may also be used, which provide an appropriate ranging protocol based on arrival time measurements.

[0114] A first message processor (112) is configured to process messages according to a ranging protocol, determine a first arrival time of a measurement message at the first device, and determine a first distance (151) between the first device and the second device based on the first arrival time. Additionally, the first message processor is configured to communicate with a third device (130). The third device operates as a cooperating device and is located at a trusted distance (150) from the first device. The trusted distance is known to the first device and is trusted to be reliable. The trusted distance may be predetermined, measured separately, or entered by a user. Optionally, the first message processor is configured to determine the trusted distance according to a ranging protocol executed by the third device. Prior to actual measurements for the second device, the trusted distance may be determined using the same or a different ranging protocol.

[0115] In a third device, also referred to as a cooperative device, a third message processor (132) is arranged to determine a third arrival time of a measurement message at the third device. In particular, the third device cooperates with the first device by determining a third arrival time of the same measurement message at the third device and by transmitting supporting data based on the third arrival time to the first device. For example, the supporting data may include third arrival time data for a reference clock or timing grid, or for the reception of some other message also received by the first device. Alternatively or additionally, the supporting data may include third distance data. Accordingly, the third device may determine a third distance between the third device and the second device by using, for example, additional received messages and a trusted distance.

[0116] A first message processor is arranged to receive supporting data from a cooperating device to evaluate a determined distance, and to use the supporting data to obtain a third distance (153) between a third device and a second device. The first message processor is subsequently arranged to perform a verification test for a first distance (151), a trusted distance (150), and a third distance (153). The verification test may accept the first distance as reliable when the distances correspond to a viable spatial constellation of the first device, the second device, and the cooperating device. For example, the verification test includes a cosine law test or a triangle inequality test for a viable spatial constellation, as further described below. The test aims to prove whether the actual spatial constellation of the triangle can have the respective lengths of its sides according to the determined distances.

[0117] The ranging protocol may include exchanging cryptographically protected messages based on key data. Optionally, the first message processor is arranged to share key data with a cooperating device so that the third message processor can cryptographically process messages according to the ranging protocol. Encrypting messages between the first device and the third device according to a known wireless communication protocol protects such messages from being potentially tampered with by a second malicious device.

[0118] Optionally, the device may have a clock unit that provides a time reference for determining the arrival times. The first message processor may be arranged to synchronize the time reference with a corresponding clock unit within a cooperating device, for example, synchronized with a protocol from [802.1AS]. Effectively, the time reference may be shared between the first device and the third device. A third arrival time may be determined against the time reference, which allows supporting data to include the third arrival time so determined and to make it available by the first device in this manner.

[0119] In the following, the method and scope thereof are described regarding how the addition of one or more cooperative STAs can help detect when response STAs are desired to appear closer to the initiating STA than they actually are. The following assumptions may apply:

[0120] The response STA knows how to adjust the measurements reported to the initiating STA so that this appears at a certain distance relative to the initiating STA;

[0121] The initiating STA and cooperating STA(s) may have their clocks that time the arrival and departure times of physical frames synchronized with the 802.1AS protocol [802.1AS], or communicate in other ways so that the initiating STA knows which measurements of the corresponding STA(s) will be combined with which measurements of its own;

[0122] The initiating STA and the cooperating STA(s) share information necessary for the cooperating STA(s) so that the cooperating STA(s) can receive, identify, and, if necessary, decrypt FTM(,) messages from the responding STA(s), and thus, the cooperating STA(s) can measure the arrival times of FTM(,) messages from the responding STA(s) and report them to the initiating STA(s), so that the initiating STA(s) can combine these arrival times with its own measurements for the same messages;

[0123] FTM measurements can be performed two or more times, and the measured and reported times t1, t2, t3, and t4 of all STAs can be averaged before they are used in distance and position calculations, so the measurement accuracy is sufficiently good to make the results reliable.

[0124] A good defense against a strong attack on STAs capable of performing only timing measurements is described below. In such a defense, the initiating STA works with one or more cooperating STAs and applies the triangle inequality as illustrated, and in the case of two or more cooperating STAs, applies discrepancies in the calculated positions. Detailed examples are given using the FTM protocol of [802.11]. However, it also works well with range measurement techniques using Wi-Fi, Bluetooth, or other wireless (also optical) technologies, where one device reports the start time, arrival time, or difference thereof of protocol messages to another device.

[0125] FIG. 2 illustrates a spatial constellation of devices and cooperative devices for wireless communication. The constellation (200) includes a first device (210) referred to as the initiating STA, a second device (220) referred to as the responding STA, and a third device (230) referred to as the cooperative STA, similar to the devices described with reference to FIG. 1. A first distance d1_c is determined between the first device (210) and the second device (220) at an actual distance d1 (or d). A third distance d2_c is determined between the third device (230) and the second device (220). A trusted distance L is between the first device (210) and the third device (230) at an actual distance d2.

[0126] In the example, the actual distance from the cheating response STA to the initiation STA is d This is also the distance from the cheating response STA to the cooperating STA. The initiating STA performs a distance measurement to the cheating response STA using any of the methods described above. In the remainder, the FTM protocol is assumed.

[0127] For each distance measurement, the initiating STA requests the cooperating STA to measure the time of arrival (t2_X) of the physical frame (t1_X, t4_X) transmitted by the cheating response STA. The distances with _c attached are the corresponding distances calculated by the device.

[0128] Next, the initiating STA typically calculates the distance d:

[0129] RTT = [ (t4_X - t1_X) - (t3_X - t2_X) ] (6)

[0130] The distance between the two devices is as follows:

[0131] d1_c = c * RTT / 2 = c* [ (t4_X - t1_X) - (t3_X - t2_X) ] / 2 (7)

[0132] Here , c is the speed of light (approximately 3 x 10^8 m / s). If all measurements were performed and reported accurately, the calculated d1_c is the actual distance within measurement accuracy d will respond to.

[0133] The cheating response STA, this d Instead, a forged street f Assume that the initiating STA wants to be considered as being in. The cheating response STA measured t4_X and t1_X. To do this, the response STA changes the values ​​of t4_r_X and t1_r_X so that the difference is 2 * ( d - f ) / c It is reported as such, which is smaller than the actually measured difference between t4_X and t1_X. Therefore, the times reported by the cheating response STA to the initiation STA are as follows:

[0134] (t4_r_X, t1_r_X) = (t4_X - (1 - α)*(2*( d - f ) / c ), t1_X + α*(2*( d - f ) / c )) (8)

[0135] Here, α can be freely chosen.

[0136] Using (t4_r_X, t1_r_X) as reported by the response STA, the initiating STA is the distance between the response STA and itself. d1_c It can be calculated as follows.

[0137] d1_c = c * RTT / 2

[0138] = c * [ (t4_X - (1 - α)*(2*( d - f ) / c) - (t1_X + α*(2*( d - f ) / c ))) - (t3_X - t2_X) ] / 2

[0139] = c * [ (t4_X - t1_X) - (t3_X - t2_X) - (2*( d - f ) / c ) ] / 2

[0140] = c * [ (t4_X - t1_X) - (t3_X - t2_X) ] / 2 - c * (2*( d - f ) / c ) / 2

[0141] = d - ( d - f )

[0142] = f (9)

[0143] This calculated distance is actually what the cheating response STA wanted the initiation STA to calculate.

[0144] Using (t4_r_X, t1_r_X) reported by the response STA and t2c_X obtained from the cooperative STA, the initiating STA is the distance between the response STA and the cooperative STA. d2_c It can be calculated as follows.

[0145] d2_c = d1_c + c * (t2c_X - t2_X) (10)

[0146] For any triangle with sides A, B and C, the following inequality must hold (triangle inequality).

[0147] |C| ≤ |A| + |B| (11)

[0148] Therefore, in the constellation of Fig. 2, the following two inequalities must be true not only for distances measured by the initiating STA but also for actual distances.

[0149] L ≤ d1 + d2 (12)

[0150] L ≤ 2 * d1 + c * (t2c_X - t2_X) (13)

[0151] The initial STA is the distances measured by the two inequalities above. d1_c and d2_c You can check whether it is established for.

[0152] L ≤ d1_c + d2_c (14)

[0153] L ≤ d1_c + d1_c + c * (t2c_X - t2_X) (15)

[0154] L ≤ 2 * f + c * (t2c_X - t2_X) (16)

[0155] In the constellation of FIG. 2, since d1 and d2 are identical, t2c_X and t2_X are identical. This means that if the cheating response STA chooses f as follows, inequality (16) no longer holds:

[0156] f < L / 2 (17)

[0157] This means that, in the constellation of FIG. 2, the initiating STA, the responding STA, with respect to the initiating STA L / This means that it is possible to detect that his measurements were falsified to appear closer than 2.

[0158] FIG. 3 illustrates a spatial constellation of two devices for wireless communication. The constellation (300) includes a first device (310) referred to as the initiating STA, a second device (320) referred to as the responding STA, and a third device (330) referred to as the cooperating STA, similar to the devices described with reference to FIG. 1. A first distance d1_c is determined between the first device (310) and the second device (320) at an actual distance d1 (or d). A third distance d2_c is determined between the third device (330) and the second device (320) at an actual distance d2. A trusted distance (L) is between the first device (310) and the third device (330).

[0159] In this example, the initiating STA is the distance to the cheating response STA. f It will measure as the distance between the cooperative STA and the cheating response STA. f - L will decide.

[0160] Now, the inequality (14) will be as follows.

[0161] L ≤ d1_c + d2_c (18)

[0162] L ≤ 2 * f - L (19)

[0163] L ≤ f (20)

[0164] This f go L It is valid only when it is greater than or equal to. Therefore, the proposed defense operates in the constellation of FIG. 3, where the initiating STA, and the responding STA, with respect to the initiating STA L It can be detected that his measurements were falsified to appear closer.

[0165] FIG. 4 illustrates an additional spatial constellation of two devices for wireless communication. The constellation (400) includes a first device (410) referred to as the initiating STA, a second device (420) referred to as the responding STA, and a third device (430) referred to as the cooperating STA, similar to the devices described with reference to FIG. 1. A first distance d1_c is determined between the first device (410) and the second device (420) at an actual distance d1 (or d). A third distance d2_c is determined between the third device (430) and the second device (420) at an actual distance d2. A trusted distance (L) is between the first device (410) and the third device (430).

[0166] In the example, the Law of Cosines is used. d2 is calculated as follows:

[0167] d2 2 = d1 2 + L 2 - 2 * d1 * L * cos(φ) (21)

[0168] Using α in the following way d1 class L It relates to.

[0169] d1 = α * L (22)

[0170] We obtain the following equation.

[0171] d2 = sqrt(( α * L) 2 + L 2 - 2 * α * L * L * cos(φ)

[0172] = L * sqrt( α 2 + 1 - 2 * α * cos(φ)) (23)

[0173] However, the cheating response STA changes the information it transmits to the initiating STA, thereby changing the distances d1_c and d2_c It will be as follows.

[0174] d1_c = d1 - ( d1 - f ) (24)

[0175] d2_c = d2 - ( d1 - f ) (25)

[0176] The initiating STA checks whether the inequality (14) holds for the distances that were measured.

[0177] L ≤ d1_c + d2_c (26)

[0178] L ≤ f + L * sqrt( α 2 + 1 - 2 * α * cos(φ)) - α * L + f (27)

[0179] L ≤ 2 * f + L * { sqrt( α 2 + 1 - 2 * α * cos(φ)) - α} (28)

[0180] f ≥ 0.5 * L * { 1 + α - sqrt( α 2 + 1 - 2 * α * cos(φ))} (29)

[0181] Therefore, the initiating STA will detect the response STA that falsifies its reported measurements when the response STA selects f as in the following inequality.

[0182] f / L < 0.5 * { 1 + α - sqrt( α 2 + 1 - 2 * α * cos(φ))} = T1 (30)

[0183] Table 1 is for combinations of α ≥ 0 and 0 ≤ φ ≤ 90 degrees T1 Represents the values ​​of.

[0184]

[0185] Table 2 is for combinations of α ≥ 0 and 90 ≤ φ ≤ 180 degrees T1 Represents the values ​​of.

[0186]

[0187] The response STA is that it is a distance of 0.5* L Or assume that there is interest in detecting that a counterfeit STA is intended to appear as if it is at a closer distance. Thus, if a counterfeit STA (0.5 L further away) is intended to appear 0.5 L closer, this can be detected if the counterfeit STA is within the non-shaded area. Therefore, the measured distance for these counterfeit STAs will be less than 0.5 L, because that distance is the intended distance.

[0188] STA is actually 0.5* L If it is within, there is no need to falsify it, so there is no shading in the area where α ≤ 0.5 in Table 1.

[0189] The gray shaded areas in Table 1 and Table 2 indicate the actual distance between the response STA and the initiation STA is 0.5* LIn the case where it is further away (therefore α > 0.5), and the initiating STA is, the response STA is 0.5* L This is a case where it is not possible to detect that the distance is to be represented as a distance below a certain value. The proposed method protects against cheating response STAs present in a wide area where 0 ≤ φ ≤ 90 degrees. However, the method does not protect against cheating response STAs in the area where 90 < φ ≤ 180 degrees. In this regard, the use of additional cooperative devices is proposed. Accordingly, a system for distance measurement may include a first device and at least two cooperative devices. Various examples are discussed below. In such a system, a fourth device acting as a second cooperative device may have a fourth message processor arranged to determine a fourth arrival time of a measurement message from the fourth device and to transmit fourth support data based on the fourth arrival time to the first device. The first message processor is arranged to receive the fourth support data from the second cooperative device, obtain a fourth distance between the fourth device and the second device using the fourth support data, and perform a verification test using the second trusted distance and the fourth distance.

[0190] In one embodiment, the verification test uses a combination of a first triangle inequality for a first spatial constellation of the first device, the second device, and the third device, and a second triangle inequality for a second spatial constellation of the first device, the second device, and the fourth device. The verification test may include the tests discussed in the paragraph below regarding the use of triangle inequalities and two cooperative STAs. Alternatively, the verification test may use two cooperative STAs as described in a later section, using triangle inequalities and two cooperative STAs in a better way. To this end, the distance between the two cooperative devices may be known by the first device.

[0191] In one embodiment, the verification test may verify whether a first position of a second device according to a first spatial constellation corresponds to a second position of a second device according to a second spatial constellation. Optionally, the verification test may use a mismatch check to detect whether all determined distances are greater than 0.

[0192] Additionally, the verification test may be based on the entire constellation of the first, third, and fourth devices, exceeding the first and second trusted distances. For example, this may be performed by using the trusted angle between the connection lines between both the initiating device and the cooperating devices. Optionally, the verification test may be based on a setup in which the third and fourth devices are arranged such that the trusted angle between the line from the third device to the first device and the line from the fourth device to the first device is at least 90 degrees. Optionally, the verification test may be based on a setup in which the third and fourth devices are arranged opposite each other with respect to the first device. Optionally, the verification test may be based on a setup in which the second trusted distance corresponds to the trusted distance. Various scenarios and calculations for the verification test are discussed in the following sections. The following example uses the triangle inequality and two cooperating STAs.

[0193] FIG. 5 illustrates a spatial constellation having two cooperative devices. The constellation (500) includes a first device marked as an 'initial STA' and two 'cooperative STAs', similar to the devices described with reference to FIG. 1. A first trusted distance (L) is between the first device and the first cooperative STA, while a second trusted distance (L) is between the first device and the second cooperative STA.

[0194] By using an exemplary constellation, and by using a second cooperative STA located exactly opposite the first cooperative STA, better performance is achieved in the case where 90 < φ ≤ 180. In that case, the initiating STA is 0.5* L It is possible to detect many, even if not all cheating response STAs that are intended to appear closer. In the case of such a constellation, the response STA is at a distance of 0.5 L The area you wish to forge as if it were closer to that is shown in gray in Fig. 5. This area resembles a ring with a wedge-shaped cross-section.

[0195] FIG. 6 illustrates a second spatial constellation having two cooperative devices. The constellation (600) includes a first device referred to as the initiating STA, and two cooperative STAs, similar to the devices described with reference to FIG. 1. A first trusted distance (L) is between the first device and the first cooperative STA, while a second trusted distance (L) is between the first device and the second cooperative STA.

[0196] Using an exemplary constellation, the initiating STA uses two cooperative STAs as described above, and the responding STA is 0.3 L Or, interest lies in the fact that one wishes to forge it as if it were at a closer distance. In such cases, from Table 1, at least 1.1 L All separated response STAs are found and 1.1 L It can be seen that many STAs are found closer.

[0197] FIG. 7 illustrates an additional spatial constellation having two cooperative devices. The constellation (700), similar to the devices described with reference to FIG. 1, includes a first device (710) referred to as the initiating STA, a second device (720) referred to as the responding device, and two cooperative STAs (730, 731). A first trusted distance (L) is between the first device and the first cooperative STA, while a second trusted distance (L) is between the first device and the second cooperative STA. In this particular constellation, it is noted that the second device (720) may be located somewhere within 3d of a circle whose center lies on the line connecting the first, third, and fourth devices. For this reason, the location of the second device is calculated here only by the 2d coordinates of the plane connecting the first, second, third, and fourth devices.

[0198] In an exemplary constellation, the triangle inequality and two cooperative STAs are used. The triangle inequality is used for measurements through cooperative STAs 1 and 2. Using the Law of Cosines, as follows: d2_1 It can calculate.

[0199] d2_1 2 = L * sqrt( α 2 + 1 - 2 * α * cos(φ)) (31)

[0200] And d2 _2 can calculate.

[0201] d2_2 2 = L * sqrt( α 2 + 1 - 2 * α * cos(180 - φ))

[0202] = L * sqrt( α 2 + 1 + 2 * α* cos(φ)) (32)

[0203] The cheating response STA is the distances at which the initiating STA becomes as in the following equation. d1_c , d2_1_c and d2_2_c Change the information transmitted to the initiation STA so that it becomes.

[0204] d1_c = d1 - ( d1 - f ) (33)

[0205] d2_1_c = d2_1 - ( d1 - f ) (34)

[0206] d2_2_c = d2_2 - ( d1 - f ) (35)

[0207] The initiating STA checks whether the inequality (14) holds for distances received from cooperative STAs 1 and 2.

[0208] 2*L ≤ d2_1_c + d2_2_c (36)

[0209] 2*L ≤ L * sqrt( α 2 + 1 - 2 * α * cos(φ)) + L * sqrt( α 2 + 1 + 2 * α * cos(φ)) - 2 * ( α * L - f ) (37)

[0210] L ≤ f + L * { sqrt( α 2 + 1 - 2 * α * cos(φ)) + sqrt( α 2 + 1 + 2 * α * cos(φ)) - 2 * α} / 2 (38)

[0211] f ≥ 0.5 * L * { 2 + 2 * α - sqrt( α 2 + 1 - 2 * α * cos(φ)) - sqrt( α 2 + 1 + 2 * α * cos(φ))} (39)

[0212] Therefore, the initiation STA is, as in the following inequality, the response STA f When selecting, it will detect a response STA that falsifies his reported measurements.

[0213] f / L < 0.5 * { 2 + 2 * α - sqrt( α 2 + 1 - 2 * α * cos(φ)) - sqrt( α 2 + 1 + 2 * α * cos(φ))} = T3 (40)

[0214] Table 3 shows the values ​​of T3 for combinations of α ≥ 0 and 0 ≤ φ ≤ 180 degrees. T3 The table of values ​​is symmetric about φ = 90 degrees.

[0215]

[0216] The response STA is that it is 0.5* L Or assume that you are interested in detecting that someone wants to forge it to appear as if it is at a closer distance. The STA is actually 0.5* L If it is within, there is no need to falsify it, so there is no shading in the area where α ≤ 0.5 in Table 3.

[0217] The gray shaded area in Table 3 indicates the actual distance between the response STA and the initiation STA is 0.5* L In the case where it is further away (therefore α > 0.5), and the initiating STA is, the response STA is 0.5* L This is a case where it is not possible to detect that it is desired to be represented by a distance below this level. It is evident that the proposed method protects against cheating response STAs present in a wide area where 0 ≤ φ ≤ 90 degrees, and that the area it does not protect (gray shaded area) is clearly much smaller than the area in Table 1.

[0218] In the constellation of FIG. 7, the positions (x, y) within the plane connecting the four devices can be calculated in various ways. If the response STA faithfully reports its measurements, these calculated positions will match, except for measurement errors. However, if the response STA falsifies its measurements, this will not be the case, especially when it intends to appear closer than it actually is.

[0219] Assume that the initiation STA is at (x, y) = (0, 0), the cooperative STA 1 is at (L, 0), and the cooperative STA 2 is at (-L, 0). Note that these STAs and the response STA are, of course, located in the 3-d world. Plane ( x , y ) can be any plane within 3-d, on which a line connecting the initiating STA and two cooperating STAs lies. In this section, the calculations for the y-coordinates involve two values ​​+ / - y ...must be calculated. Maintaining only positive solutions is when rotating the plane 180 degrees around the line connecting the initiating STA and the two cooperating STAs. y There is no problem because another solution for it is obtained.

[0220] First, as explained in the section "Relationship between the Law of Cosines and the Triangle Inequality Test" below, we check whether the distances determined by the starting STA are greater than 0.

[0221] d1_c > 0 (41)

[0222] d2_1_c > 0 (42)

[0223] d2_2_c > 0 (43)

[0224] If none of the three inequalities above hold, the cheating response STA is assumed.

[0225] If these three inequalities hold, the cosine law is used for combinations of four edges to calculate the position of the response STA.

[0226] cos ( ACB) = (|A| 2 + |B| 2 - |C| 2 ) / (2 * |A| * |B|) (44)

[0227] The inventors always use point b as the position of the response STA.

[0228] point a =( L , 0) and c Using =(0, 0), the response STA b 1=( x1 , y1 It can be measured as being in ).

[0229] cos_c1 = ( d1_c 2 + L 2 - d2_1_c 2 ) / (2 * d1_c * L ) (45)

[0230] point a =(- L , 0) and cUsing =(0, 0), the response STA b =( x2 , y2 It can be measured as being in ).

[0231] cos_c2 = ( d1_c 2 + L 2 - d2_2_c 2 ) / (2 * d1_c * L ) (46)

[0232] point a =( L , 0) and c =(- L Using , 0), the response STA b =( x3 , y3 It can be measured as being in ).

[0233] cos_c3 = ( d2_1_c 2 + 4 L 2 - d2_2_c 2 ) / (2 * d2_1_c * 2 L ) (47)

[0234] point a =(- L , 0) and c =( L Using , 0), the response STA b =( x4 , y4 It can be measured as being in ).

[0235] cos_c4 = ( d2_2_c 2 + 4 L 2 - d2_1_c 2 ) / (2 * d2_2_c * 2 L ) (48)

[0236] Next, we check whether all four of the calculated cosines are in the interval [-1, 1]. From the section "Relationship between the Law of Cosines test and the Triangle Inequality test" below, we know that we have performed the same tests as the triangle inequality tests so far, so the three tables above are applied together with the tests so far.

[0237] If all four calculated cosines are in the interval [-1, 1], then the four points for the position of the response STA are as follows b 1, b 2, b 3 and b Calculate 4.

[0238] x1 = cos_c1 * d1_c (49)

[0239] y1 = sqrt(1 - cos_c1 2 ) * d1_c (50)

[0240] x2 = - cos_c2 * d1_c (51)

[0241] y2 = sqrt(1 - cos_c2 2 ) * d1_c (52)

[0242] x3 = L - cos_c3 * d2_1_c (53)

[0243] y3 = sqrt(1 - cos_c3 2 ) * d2_1_c (54)

[0244] x4 = - L + cos_c4 * d2_2_c (55)

[0245] y4 = sqrt(1 - cos_c4 2 ) * d2_2_c (56)

[0246] If the responding STA has faithfully reported its time measurements, these four points should be identical, except for the influence of timing measurement errors. Note that, as explained elsewhere, measurement errors can be reduced by performing multiple measurements and averaging the results. However, these four points differ when the responding STA falsifies its measurements to appear closer than it actually is, and when the responding STA is not on the line connecting cooperative STA 1 and 2.

[0247] 4 points b1 class b2 and b3 and b4 The maximum value of all distances between them emax Calculate.

[0248] i ∈{1, 2, 3, 4} and j In the case of ∈{1, 2, 3, 4}, emax = MAX | bi - bj | (57)

[0249] b3 and b4 Since it will be calculated as the same point excluding numerical errors b4 Note that there is no need to calculate.

[0250] Table 4 excludes cases where any of the cosine tests failed emax / L The values ​​of are plotted, in this case, a value of 99 is plotted. The value f for which the cheating response STA is desired to be displayed is important for these tests. f Select 0.9 from Table 4.

[0251]

[0252] As can be seen from this table, for α > 0.9, the cells representing 99 correspond to the cells with values ​​greater than 0.9 in Table 3, which demonstrates the equivalence discussed in the section "Relationship between the Law of Cosines and the Triangle Inequality Test" below.

[0253] Actually 0.9 from the start STA L Since response STAs within the range do not need to falsify that they are within this range, this region is not shaded in Table 4. 0.25 as the threshold for the maximum discrepancy in the measurements b1, b2, b3, and b4 regarding the position of the response STA. L Using this, the area of ​​Table 4 where the cells have values ​​less than 0.25 and α > 0.9 was shaded.

[0254] This is, within the shaded area, therefore basically 0.9 from the starting STA. l and 1.2 L For response STAs located at a distance between, the proposed system allows these response STAs to be 0.9 from the initiating STA. L This means that it cannot be determined that they are falsifying their timing measurements to appear as if they are located within.

[0255] Therefore, distance from the start STA L Using two cooperative STAs located at opposite positions, the proposed system, from the initiating STA, 0.9 L As response STAs that are falsifying their timing measurements to appear as being located within 1.2 from the initiating STA. L Response STAs located at all distances further away can be detected.

[0256] The following section utilizes the triangle inequality and more than two cooperative STAs. Better performance can be achieved by placing more than two cooperative STAs around the initiating STA. To best detect cheating response STAs located at as many positions as possible around the initiating STA, it is best to place the initiating STA and the cooperative STAs on a single plane when using three cooperative STAs. This is because if the initiating STA is not on the plane connecting the three cooperative STAs, the cheating response STA will always be closer to the initiating STA than any of the three cooperative STAs, and thus the proposed method will not work in that volume (see, e.g., Table 2).

[0257] It is also possible to use two cooperative STAs and initiating STAs that are not positioned on a single line but form a triangle in a constellation. Using the distances d1, d2_1, d2_2 and the lengths of the sides of the triangle formed by the two cooperative STAs and the initiating STA, the initiating STA can perform tests using the cosine law for triangles formed by a pair of the second device and any device among the set of two cooperative STAs and the initiating STA.

[0258] When using four cooperative STAs, they should ideally be placed on the edges of a tetrahedron, and the initiating STA should be located at the center of the tetrahedron. Since this constellation is the most symmetrical possible, it provides optimal protection.

[0259] The vertices of a tetrahedron having four points on a unit sphere, with the origin as the center, horizontal, and lower face level, are given by the following equation.

[0260] A = (sqrt(8 / 9), 0, -1 / 3)

[0261] B = (-sqrt(2 / 9), sqrt(2 / 3), -1 / 3)

[0262] C = (-sqrt(2 / 9), -sqrt(2 / 3), -1 / 3)

[0263] D = (0, 0, 1)

[0264] Therefore, in this case, the cooperative STAs are at the vertex positions, the initiating STA is located at the origin, and the distance L is equal to 1. Since the greatest distance between any two STAs is the distance between any two cooperative STAs, the lengths of each edge of the tetrahedron are as follows.

[0265] || A-D|| = ||(sqrt(8 / 9), 0, -1 / 3) - (0, 0, 1)||

[0266] = ||(sqrt(8 / 9), 0, - 4 / 3)||

[0267] = sqrt(8 / 3) ≈ 1.63 (58)

[0268] The largest angle between any cooperative STA and the origin and the response STA occurs when the response STAA lies on the line connecting the origin and the center of any one of the four faces of the tetrahedron. The center of face ABD is as follows.

[0269] F = { (sqrt(8 / 9), 0, -1 / 3) + (-sqrt(2 / 9), sqrt(2 / 3), -1 / 3) + (0, 0, 1)} / 3

[0270] = (sqrt(8 / 9) - sqrt(2 / 9), sqrt(2 / 3), 1 / 3) / 3 (59)

[0271] Angles AOF, BOF and The DOF is all the same. These angles can be calculated using the cosine law.

[0272] cos( DOF) = (||D|| 2 + ||F|| 2 - ||D - F|| 2 ) / (2 * ||D|| * ||F||) (60)

[0273] ||D|| 2 = 1 (61)

[0274] ||F|| 2 = { (sqrt(8 / 9) - sqrt(2 / 9)) 2 + 2 / 3 + 1 / 9} / 9

[0275] = { 8 / 9 + 2 / 9 - 2 * sqrt(16 / 81) + 7 / 9} / 9

[0276] = 1 / 9 (62)

[0277] ||D - F|| 2 = { (sqrt(8 / 9) - sqrt(2 / 9)) 2 + 2 / 3} / 9 + (8 / 9) 2

[0278] = { 8 / 9 + 2 / 9 - 2 * sqrt(16 / 81) + 2 / 3} / 9 + 64 / 81

[0279] = { 2 / 9 + 6 / 9} / 9 + 64 / 81

[0280] = 72 / 81 = 8 / 9 (63)

[0281] thus

[0282] cos( DOF) = (1 + 1 / 9 - 8 / 9) / (2 * 1 * 1 / 3)

[0283] = 3 * (2 / 9) / 2

[0284] = 1 / 3 (64)

[0285] DOF) = arccos(1 / 3) = 70.53 degrees (65)

[0286] Therefore, using a constellation consisting of one initiation STA located at the center of the tetrahedron and four cooperative STAs located at the vertices of the tetrahedron at a distance L from the initiation STA, all response STAs intended to be forged to be closer than 0.5L with respect to the initiation STA can be detected if they are further than 1.5L from the initiation STA; refer to Table 1. 0.5 L and 1.5 L Many such STAs can be detected within the region between them.

[0287] Optionally, the defense can be improved by adding discrepancy checks in the calculated positions using the initiating STA and cooperating STA, similar to the defense described in the previous section.

[0288] In one embodiment, the ranging protocol may include a first device, the first device operating as an initiating device and transmitting an initiating message to a second device, while upon receiving the initiating message, the second device must transmit a measurement message. A first message processor is arranged to exchange role-change data with a third device so that the third device can operate as an initiating device for distance measurement. Accordingly, the third device is arranged to obtain a third distance between the third device and the second device according to a ranging protocol based on the second measurement message upon receiving the role-change data, and to transmit third support data representing the third distance to the first device. For example, the third support data may include t2 and t3 values ​​of the FTM protocol measured by the third device. t1 and t4 values ​​may also be part thereof, but this is not necessary because the first device can receive and use the original message from the second device containing t1 and t4.

[0289] Additionally, the first message processor is arranged to determine a second distance between the first device and the second device when receiving a second measurement message from the first device, receive third support data from the third device, and perform a verification test using the second distance and the third support data. In an embodiment, the initiating STA and the cooperating STA exchange roles—that is, in other words, calculate the position twice using two initiating STAs.

[0290] In the constellation of FIG. 4, there are now two devices (410, 430) acting as a first STA 1 and a second STA 2 working together to determine the distance to the response STA. In a series of measurements, STA 1 acts as the initiating STA and STA 2 acts as the cooperating STA, and in a second series of measurements, they assume opposite roles. To improve the distance measurement results, each series of individual time measurements is averaged before the distance is calculated. All of the first series of individual measurements can be performed before the second series of individual measurements are performed with the roles swapped. However, the role swapping can be performed after any number of individual measurements.

[0291] Using timing measurements from the first series of measurements, if STA 1 is the initiating STA, the position of the response STA using Equation (49) and Equation (50). r1 = ( x1 , y1 ) can be calculated. Using timing measurements from the second series of measurements, if STA 2 is the initiating STA, the position of the response STA can be calculated using similar equations. r2 = ( x2 , y2) can be calculated. Note that in this particular constellation, the second device (420) may be located somewhere within 3d of a circle with its center on the line connecting the first and third devices. For this reason, the position of the second device is calculated here using only the 2d coordinates of the plane connecting the first, second, and third devices.

[0292] Calculated points when the response STA faithfully reported its timing measurements (r1 , r2 ) should be the same except for measurement errors. However, this may differ when you want the response STA to appear closer than it actually is.

[0293] In the previous sections, the cheating response STA is the distance from the initiating STA. f Attempted to appear in. The response STA, unaware that the two STAs occasionally exchange roles, forged distance from each STA f Assume that it attempts to appear in . In this case, r1 and r2 will be clearly different, especially when f < 0.5 L.

[0294] Therefore, using two or more STAs, each acting as a starter STA, and using the distances measured by each of the starter STAs to calculate the position of the response STA and determine the difference between the calculated positions is a good idea for detecting response STAs that falsify their timing measurements.

[0295] However, the aforementioned attack is not the best possible attack in this situation. A better attack is when the responding STA knows which initiating STA is executing the FTM protocol, and the responding STA knows the constellation parameters (i.e. L and φ or d1 and d2...knowing ). While this may be difficult to know in practice, it is not impossible. It is good security practice to assume that the attacker knows everything, except for secret encryption keys. Therefore, defenses as described in the previous sections are preferably used.

[0296] The next section discusses the relationship between the Law of Cosines test and the triangle inequality test. Checking whether triangle inequalities hold for three lengths |A|, |B|, and |C| is

[0297] |C| ≤ |A| + |B| (66)

[0298] |A| ≤ |B| + |C| (67)

[0299] |B| ≤ |A| + |C| (68)

[0300] It is equivalent to checking whether the following equation holds true.

[0301] -1 ≤ cos ( ACB) ≤ 1 (69)

[0302] angle The cosine law for ACB is as follows:

[0303] cos ( ACB) = (|A| 2 + |B| 2 - |C| 2 ) / (2 * |A| * |B|) (70)

[0304] Checking whether the cosine is greater than or equal to -1 is as follows.

[0305] cos ( ACB) ≥ -1

[0306] (|A| 2 + |B| 2 - |C| 2 ) / (2 * |A| * |B|) ≥ -1 (71)

[0307] Only when (|A| * |B|) > 0 can the following inequality be derived from inequality (71).

[0308] (|A| 2 + |B| 2 - |C| 2 ) ≥ -2 * |A| * |B|

[0309] (|A| 2 + |B| 2 + 2 * |A| * |B| - |C| 2 ) ≥ 0

[0310] (|A| + |B|) 2 - |C| 2 ≥ 0

[0311] (|A| + |B|) 2 ≥ |C| 2

[0312] |C| ≤ (|A| + |B|) (72)

[0313] This is the same as inequality (66).

[0314] Similarly, checking whether the cosine is 1 or less is as follows.

[0315] cos ( ACB) ≤ 1

[0316] (|A| - |B|) 2 - |C| 2 ≤ 0

[0317] (|A| - |B|) 2 ≤ |C| 2

[0318] abs(|A| - |B|) ≤ |C|

[0319] |A| ≤ (|B| + |C|) & |B| ≤ (|A| + |C|) (73)

[0320] Two inequalities must also hold for triangles.

[0321] Note that the actual distances are always greater than or equal to 0. The above reasoning holds for positive distances but not for negative distances. When the response STA falsifies its measurements to be closer, the distances obtained by the initiating STA can be negative. Therefore, checking for the three triangle inequalities is equivalent to checking whether the three measured distances are greater than or equal to 0 and whether the cosine inequality (69) holds.

[0322] In one embodiment, a third message processor is arranged to determine a third signal strength of at least one message received from a second device and is arranged to include the third signal strength data in support data for a first device. A first message processor is arranged to determine a first signal strength of at least one message received from a second device and to verify whether the determined distances are reliable by comparing the first signal strength and the third signal strength at the determined distances with their respective expected signal strengths. In an embodiment, distance measurements based on signal strengths are additionally performed to increase reliability. In addition to arrival time and transmission time, the received signal strength may also be used as a distance measurement. A device may include transmission power in the message that causes one message to be transmitted to another device, another device may measure the received signal strength, and another device may determine the distance based on transmitter antenna properties (e.g., omnidirectional) and the assumption that the signal strength decreases by a power of 2 with respect to distance. If at least one cooperating device measures the signal strength of the same message and includes this data in the support data as transmitted to the first device, the first device can determine the ratio of distances from the second device based on the received signal strengths.

[0323] In one embodiment, the first and third devices may be implemented by base stations in a 3GPP network, while the second device is implemented by a UE. 3GPP base stations transmit and receive in a time-frequency grid referred to as so-called resource elements. Some of the positions in the time-frequency grid are fixed by 3GPP standards and are used to broadcast system information to all UEs within the base station's range, the system information being, for example, information on when and on which frequencies a base station will transmit something to a specific UE (downlink), and when and on which frequencies a specific UE can transmit something to the base station (uplink) or to a specific other UE (sidelink). When base stations cooperate according to the present invention, their time-frequency grids must be aligned and synchronized so that they each make the same time-frequency positions (resource elements) available within the grid, so that they can all measure the arrival time or received signal strength of the same message from the same UE.

[0324] In a further embodiment, the ranging protocol includes additional attributes or additional messages that may be added to the ranging protocol, for example, as defined in [802.11], which include credentials (e.g., a public key) or a hash of the credentials or encrypted credentials. Such messages are examples of messages that are password-protected based on key data. A second device may include such credentials or a hash of the credentials or encrypted credentials as part of a message exchange for the ranging protocol. To be symmetric, the first device may also include such credentials, a hash of the credentials or encrypted credentials in an additional message. Since a preferred field containing credentials or a hash of the credentials or encrypted credentials in a message of the ranging protocol is a field where at least a part of the signal of that field or the signal carrying that field is used to measure the transmission or arrival time of the message, it is very difficult, if not impossible, for another device to insert its credentials or a hash of its credentials or its encrypted credentials into a message used to measure the distance between the first device and the second device. The closer the signal returning the credential, the hash of the credential, or the encrypted credential is (in time) to the signal used to measure the range, or the greater the overlap between these signals, the better. In this way, the first device can be confident that the credential, the hash of the credential, or the encrypted credential within the message of the ranging protocol is actually one of the second devices running the range measurement protocol.In one embodiment, a first message processor is arranged to process such credentials or hashes of credentials or encrypted credentials and, for example, by using a Wi-Fi protection setup protocol, a device provisioning protocol, a Diffie-Hellman key exchange and / or a 4-way WPA2 handshake, verifies whether they match credentials previously used by a device that has successfully performed device authentication and established mutual trust. If a match is found, the first device may assume that distance measurements between the first device and the second device can be trusted and considered reliable. If no match is found, the first device will distrust the distance measurements between the first device and the second device and perform additional steps to verify the reliability of the distance measurements using mechanisms such as those described in other embodiments. In another embodiment, the measured values ​​(e.g., first time data and / or second time data) are encrypted using a key derived from credentials agreed upon or agreed upon between the first device and the second device, which were established during a previous device authentication procedure performed between the first device and the second device.

[0325] In an alternative embodiment, the second device may include a credential, a hash of the credential, or an encrypted credential to be used during a subsequent connection setup. The first message processor is arranged to process and store the received credential, the hash of the credential, or the encrypted credential together with the measured distance between the first device and the second device in order to securely correlate the measured distances with the specific device connecting to the credential. When setting up a connection between the first device and the second device, the first device verifies whether the same credential or its derivative is used during the execution of device authentication, for example, during the execution of a Wi-Fi protection setup protocol, a device provisioning protocol, a Diffie-Hellman key exchange, and / or during the execution of a 4-way WPA2 handshake. By doing so, the first device can determine that the device it is connecting to is the same device on which the specific distance measurement was performed. In particular, if the credential was a public key and setting up the connection between the first device and the second device involved the second device successfully proving to Device 1 that it possesses a private key belonging to the public key as the credential in the range measurement, the first device can be confident that the second device is the device that measured the range and is not a fraudster.

[0326] In one embodiment, the first message processor is arranged to proceed to a different process or function, data, or function access denial instead of the intended process when the determined distance is evaluated as unreliable. For example, a normal distance-based process may be to allow access to location-based services or local peripherals. Additionally, routing to or from the first device over other networks, such as Ethernet, the Internet, or a 3GPP core network, may be controlled or denied based on the distance measurement. If the determined distance is deemed unreliable, all further communication and / or access may be denied and / or a warning message may be sent to a management system or security guard. Additionally, the first message processor may be arranged to engage a different security protocol that the second device may execute, such as requesting additional credentials and / or personal identification of the user before proceeding with any normal distance-based process. The different security protocol may be an additional process or a more enhanced implementation of the main protocol, and may, for example, introduce a stricter or more difficult step in the general security process. Optionally, the first message processor is arranged to request additional distance measurements from a human operator of a second device, using a different ranging protocol and / or a different type of wireless communication, e.g., NFC at very close distances, or providing some identification and / or biometric data such as fingerprints. Additionally, the first message processor may be arranged to deny or restrict access to at least some data and / or at least one application of the first device before proceeding to any normal distance-based process. For example, basic services may be provided even when the distance is considered unreliable, whereas extended services are provided when the distance is considered reliable.

[0327] FIG. 8 illustrates a method for measuring distance via wireless communication between a first device and a second device, wherein the wireless communication includes a ranging protocol as described above. The first device and the second device are similar to the first and second devices illustrated and further described with reference to FIG. 1. A third device operates as a cooperating device located at a trusted distance from the first device. The method may be executed by a processor within the first device, but may also be processed by a processor within a different device and / or at different times based on received arrival times and supporting data. For example, the method may be executed in an additional device that does not actively participate in the ranging protocol but receives all messages and recognizes the trusted distance.

[0328] The method starts at node START (801). At the first stage RNGP (802), the method executes a ranging protocol and can perform time-of-arrival measurements as described with reference to FIG. 1. The method continues to stage OD1 (803) by obtaining a first distance between the first device and the second device based on the first time-of-arrival of a measurement message at the first device, and then communicates with a cooperating device at stage CO_COP (804). The cooperating device is arranged to determine a third time-of-arrival of a measurement message at the cooperating device and provide supporting data based on the third time-of-arrival. The method then continues to the step of evaluating the determined distance. At the next stage OD3 (805), a third distance between the third device and the second device is obtained using supporting data calculated, for example, based on the third time-of-arrival and transmission time of the measurement message. Finally, at stage VERT (806), a verification test is performed for the first distance, the trusted distance, and the third distance. The verification test accepts the first distance as reliable when the distances correspond to a viable spatial constellation of the first device, the second device, and the cooperative device. The test may be based on the triangle inequality and mismatch check as described above.

[0329] In one embodiment, the method may include a preparation stage in which a first device is instructed to operate as an initiating device to provide a first time of arrival or a first distance. Similarly, a third device may be instructed to operate as a cooperating device to provide supporting data based on a third time of arrival. The preparation stage may be executed by a separate control device, computer, or server. Alternatively, the first device or the third device may execute the instruction.

[0330] FIG. 9 illustrates a method of operating as a cooperative device in distance measurement via wireless communication between a first device and a second device as described in FIG. 8. The cooperative device may be located at a trusted distance from the first device.

[0331] The method starts at node START (901). At the first stage RNGP (902), the method can monitor a ranging protocol as performed by the first and second devices. The method continues to stage ARR3 (903) by determining the third arrival time of a measurement message at the cooperating device. Subsequently, at stage CO_IN (904), the cooperating side subsequently communicates with the first device, for example, using a wireless protocol or a wired connection. Next, at stage SUP (905), the method provides support data to the first device. The support data is based on the third arrival time. Subsequently, the method at the cooperating side ends at node END (906). As described above, the first device is arranged to use the support data to obtain the third distance between the cooperating device and the second device, and to perform a verification test for the first distance, the trusted distance, and the third distance.

[0332] FIG. 10a illustrates a computer-readable medium (1000) having a writable portion (1010) comprising a computer program (1020), wherein the computer program (1020) comprises instructions that cause a processor system to perform one or more of the methods described in the system as described with reference to FIG. 9 and FIG. 10. The computer program (1020) may be implemented on the computer-readable medium (1000) as physical marks or by magnetization of the computer-readable medium (1000). However, any other suitable embodiment may also be conceived. Additionally, although the computer-readable medium (1000) is illustrated herein as an optical disk, it will be recognized that the computer-readable medium (1000) may be any suitable computer-readable medium such as a hard disk, solid-state memory, flash memory, etc., and may be non-writable or writable. The computer program (1020) comprises instructions that cause a processor system to perform the methods.

[0333] FIG. 10b illustrates a schematic diagram of a processor system (1100) according to an embodiment of a device or server as described with reference to FIG. 9 and FIG. 10. The processor system includes one or more integrated circuits (1110). The architecture of one or more integrated circuits (1110) is schematically illustrated in the drawing. The circuit (1110) includes a processing unit (1120), e.g., a CPU, for executing computer program components to execute a method according to an embodiment and / or to implement its modules or units. The circuit (1110) includes a memory (1122) for storing programming code, data, etc. Part of the memory (1122) may be read-only. The circuit (1110) may include a communication element (1126), e.g., an antenna, a connector, or both. The circuit (1110) may include a dedicated integrated circuit (1124) for performing part or all of the processing defined in the method. The processor (1120), memory (1122), dedicated IC (1124), and communication element (1126) can be connected to each other via an interconnection section (1130), i.e., a bus. The processor system (1110) can be arranged for contact and / or non-contact communication using antennas and / or connectors, respectively.

[0334] Computer program products are provided that are downloadable from a network and / or stored on a computer-readable medium and / or a microprocessor executable medium, and the computer program products include program code instructions for implementing the above methods when executed on a computer to protect location information as further described below.

[0335] Any method according to the present invention may be executed using software comprising instructions for a processor system to perform the respective method. The software may include only such steps taken by a specific subentity of the system. The software may be stored on a suitable storage medium such as a hard disk, floppy disk, memory, etc. The software may be transmitted as a signal over a wired or wireless connection or using a data network such as the Internet, for example. The software may be available for download and / or remote use on a server. To perform the method according to the present invention, the method may be executed using a bitstream arranged to form programmable logic, such as a field-programmable gate array (FPGA). It will be recognized that the software may be in the form of source code, object code, intermediate source code and object code such as a partially compiled form, or any other form suitable for use in the implementation of the method according to the present invention. An embodiment relating to a computer program product includes computer-executable instructions corresponding to each of at least one processing step of the described methods. These instructions may be stored in one or more files that may be subdivided into subroutines and / or linked statically or dynamically. Another embodiment relating to a computer program product includes computer-executable instructions corresponding to each of at least one means among the described systems and / or products.

[0336] For clarity, it will be recognized that the foregoing description describes embodiments of the invention with reference to different functional units and processors. However, it will be apparent that any suitable distribution of functions among different functional units or processors may be used without departing from the invention. For example, functions exemplified to be performed by distinct units, processors, or controllers may be performed by the same processor or controller. Accordingly, references to specific functional units should be regarded as references to suitable means for providing the described functions, rather than merely indicating a strict logical or physical structure or organization. The invention may be implemented in any suitable form, including hardware, software, firmware, or any combination thereof.

[0337] Note that in this specification, the word 'comprising' does not exclude the presence of elements or steps other than those enumerated, the word 'a' or 'an' preceding an element does not exclude the presence of multiple such elements, any reference numerals do not limit the scope of the claims, the invention may be implemented by both hardware and software, multiple 'means' or 'units' may be represented by the same item of hardware or software, and a processor may possibly perform the function of one or more units in cooperation with hardware elements. Furthermore, the invention is not limited to embodiments, and the invention exists in each and all novel features or combinations of features described above or in the different dependent claims.

[0338] References:

[0339] [36.133] 3GPP TS 36.133: "Evolved Universal Terrestrial Radio Access (E-UTRA); Requirements for support of radio resource management".

[0340] [36.211] 3GPP TS 36.211: "Evolved Universal Terrestrial Radio Access (E-UTRA); Physical Channels and Modulation".

[0341] [36.214] 3GPP TS 36.214: "Evolved Universal Terrestrial Radio Access (E-UTRA); Physical layer - Measurements".

[0342] [36.321] 3GPP TS 36.321: "3rd Generation Partnership Project; Technical Specification Group Radio Access Network; Evolved Universal Terrestrial Radio Access (E-UTRA); Medium Access Control (MAC) protocol specification".

[0343] [36.355] 3GPP TS 36.355: "Evolved Universal Terrestrial Radio Access (E-UTRA); LTE Positioning Protocol (LPP)".

[0344] [37.571-1] 3GPP TS 37.571-1: "Universal Terrestrial Radio Access (UTRA) and Evolved UTRA (E-UTRA) and Evolved Packet Core (EPC); User Equipment (UE) conformance specification for UE positioning; Part 1: Conformance test specification"

[0345] [802.11] IEEE Computer Society, "IEEE Standard for Information Technology- telecommunications and Information Exchange Between Systems - Local and Metropolitan Area Networks - Specific requirements Part 11: Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) Specifications," (IEEE Std. 802.11-2016), December 2016

[0346] [802.1AS] Information technology - telecommunications and information exchange between systems - Local and metropolitan area networks - Part 1AS: Timing and synchronization for time sensitive applications in bridged local area networks, Reference number ISO / IEC / IEEE 8802-1AS:2014(E)

[0347] [DH] Diffie, W.; Hellman, M. (1976), "New directions in cryptography", IEEE Transactions on Information Theory, 22 (6): 644-654

[0348] [DPP] Device Provisioning Protocol - Technical Specification - Version 1.0, Wi-Fi Alliance, 2018, https: / / www.wi-fi.org / file-member / device-provisioning-protocol-specification .

[0349] [NAN] Neighbor Awareness Networking - technical Specification - Version 2.0, Wi-Fi Alliance, 2017, https: / / www.wi-fi.org / file-member / wi-fi-nan-technical-specification .

[0350] [OTDOA] Sven Fischer, "Observed Time Difference Of Arrival (OTDOA) Positioning in 3GPP LTE", Qualcomm Technologies, Inc., June 6, 2014.

[0351] [OWE] Opportunistic Wireless Encryption - technical Specification - Version 1.0, Wi-Fi Alliance, 2018, https: / / www.wi-fi.org / file-member / opportunistic-wireless-encryption-specification .

Claims

Claim 1 A device for measuring distance via wireless communication between a device operating as a first device (110) and a second device (120) for wireless communication, wherein the wireless communication includes a ranging protocol for determining the distance between the first device and the second device based on the arrival time of a measurement message from the first device, and the protocol includes transmitting the measurement message by the second device; the device includes a first transceiver (111) for transmitting and receiving messages, and a first message processor (112), wherein the first message processor (112) is configured to process the messages according to the ranging protocol, determine a first arrival time of the measurement message from the first device, and determine a first distance (151) between the first device and the second device based on the first arrival time; and the first message processor (112) is configured to operate as a third device (130) operating as a cooperative device located at a trusted distance (150) from the first device and The first message processor (112) is configured to communicate, and to evaluate the determined distance, the first message processor (112) receives support data from the cooperative device based on the third arrival time of the first message at the cooperative device, the third distance (153) between the third device and the second device using the support data, and is configured to perform a verification test for the first distance (151), the trusted distance (150), and the third distance (153), wherein the verification test accepts the first distance as reliable when the distances correspond to an executable spatial constellation (100) of the first device, the second device, and the cooperative device;The third device (130) comprises a third transceiver (131) and a third message processor (132), the ranging protocol comprises exchange messages protected by encryption based on key data, and the first message processor (112) is configured to share the key data with the cooperating device so as to enable the third message processor (132) to process the messages by encryption according to the ranging protocol. Claim 2 A device according to claim 1, wherein the verification test includes a cosine law test or a triangle inequality test for the executable spatial constellation. Claim 3 delete Claim 4 A device according to claim 1 or 2, wherein the first message processor (112) is configured to determine the trusted distance according to the ranging protocol. Claim 5 A device according to claim 1 or 2, wherein the device comprises a clock unit for providing a time reference for determining the arrival times, and the first message processor (112) is configured to synchronize the time reference with a corresponding clock unit within the cooperative device. Claim 6 In claim 1 or 2, the ranging protocol comprises the first device operating as an initiating device and transmitting an initiating message to the second device, while upon receiving the initiating message, the second device must transmit the measurement message, and the first message processor (112) is configured to exchange role-change data with the third device to enable the third device to operate as the initiating device for distance measurement; the third device is configured to, upon receiving the role-change data, obtain a third distance between the third device and the second device according to the ranging protocol based on the second measurement message, and transmit third support data representing the third distance to the first device; meanwhile, the first message processor (112) is configured to determine a second distance between the first device and the second device upon receiving the second measurement message from the first device, receive the third support data from the third device, and also perform the verification test using the second distance and the third support data. The thing, device. Claim 7 A device according to claim 1 or 2, wherein the third message processor (132) is configured to determine a third signal strength of at least one message received from the second device and to include the third signal strength data in the support data for the first device, and the first message processor (112) is configured to determine a first signal strength of at least one message received from the second device and to verify whether the determined distances are reliable by comparing the first signal strength and the third signal strength with their respective expected signal strengths at the determined distances. Claim 8 A device configured such that, in claim 1 or 2, the first message processor (112) performs at least one of the following when the determined distance is evaluated as unreliable: - requiring the second device to execute a different security protocol; - requesting additional distance measurement using a different ranging protocol and / or a different type of wireless communication; - denying or restricting access to at least some data and / or at least one function in the first device. Claim 9 A reliable distance measurement system comprising a device described in claim 1 or 2, said third device, and a fourth device operating as a second cooperative device located at a second trusted distance from said first device or said third device, wherein the fourth device comprises: a fourth wireless receiver (141) for receiving messages; a fourth message processor (142), wherein the fourth message processor (142) is configured to determine a fourth arrival time of said measurement message at said fourth device and to transmit a fourth support data based on said fourth arrival time to said first device; and wherein the first message processor (112) is configured to receive said fourth support data from said second cooperative device, obtain a fourth distance between said fourth device and said second device using said fourth support data, and also to perform said verification test using said second trusted distance and said fourth distance. Claim 10 In claim 9, the first message processor (112) performs the verification test using a combination of a first triangle inequality for a first spatial constellation of the first device, the second device, and the third device, and a second triangle inequality for a second spatial constellation of the first device, the second device, and the fourth device; or verifies whether a first position of the second device according to the first spatial constellation corresponds to a second position of the second device according to the second spatial constellation; or performs the verification test using a mismatch check to detect whether all determined distances are greater than zero; or performs the verification test based on a setup in which the third device and the fourth device are positioned such that the trusted angle between the line from the third device to the first device and the line from the fourth device to the first device is at least 90 degrees; Or— performing the verification test based on a setup in which the third device and the fourth device are positioned opposite each other with respect to the first device; or— a system configured to perform the verification test based on a setup in which the second trusted distance corresponds to the trusted distance. Claim 11 In claim 9, the system comprises at least one additional device operating as an additional cooperative device, wherein the third device, the fourth device and the at least one additional device are positioned within a plane at the edges of a polygon, the first device is inside the polygon, and the first message processor (112) is configured to perform the verification test using a combination of triangle inequalities for at least two spatial constellations, each constellation comprising two devices from the set of the second device and the first device and the cooperative devices. Claim 12 A method for measuring distance through wireless communication between a first device (110) and a second device (120), wherein the wireless communication includes a ranging protocol for determining a distance (140) between the first device and the second device based on the arrival time of a measurement message from the first device, and the protocol includes transmitting the measurement message by the second device; the method comprises: - obtaining a first distance between the first device and the second device based on the first arrival time of the measurement message from the first device; - communicating with a third device (130) operating as a cooperative device located at a trusted distance from the first device, wherein the third device is configured to: - determine a third arrival time of the measurement message from the third device; and - provide supporting data based on the third arrival time; and the method comprises, to evaluate the determined distance, - obtaining a third distance between the third device and the second device using the supporting data; and - performing a verification test for the first distance, the trusted distance, and the third distance, wherein the verification A method wherein the test accepts the first distance as reliable when the distances correspond to an executable spatial constellation of the first device, the second device, and the cooperative device, the ranging protocol includes exchange messages protected by encryption based on key data, and the first message processor (112) of the first device (110) is configured to share the key data with the cooperative device so as to enable the message processor of the cooperative device to process the messages by encryption according to the ranging protocol. Claim 13 In claim 12, the method comprises the step of instructing the first device to operate as an initiating device for providing the first arrival time or the first distance, or the step of instructing the third device to operate as a cooperating device for providing the support data based on the third arrival time. Claim 14 A method for operating as a cooperative device in distance measurement via wireless communication between a first device (110) and a second device (120), wherein the cooperative device is located at a trusted distance from the first device, and the wireless communication includes a ranging protocol for determining the distance between the first device and the second device based on the arrival time of a measurement message from the first device, and the protocol includes transmitting the measurement message by the second device; the first device is configured to obtain a first distance between the first device and the second device based on a first arrival time of the measurement message from the first device, and the method includes the steps of: determining a third arrival time of the measurement message from the cooperative device; and providing supporting data based on the third arrival time; the first device is configured to obtain a third distance between the cooperative device and the second device using the supporting data to evaluate the determined distance, and to perform a verification test for the first distance, the trusted distance, and the third distance, wherein the verification test is such that the distances are between the first device and the second A method in which the first distance is accepted as reliable when corresponding to a device and an executable spatial constellation of the cooperative device, the ranging protocol includes exchange messages protected by encryption based on key data, and the first message processor (112) of the first device (110) is configured to share the key data with the cooperative device so as to enable the message processor of the cooperative device to process the messages by encryption according to the ranging protocol. Claim 15 A computer program stored on a computer-readable medium comprising program code instructions for implementing a method according to any one of claims 12 to 14 when executed on a computer.

Citation Information

Patent Citations

  • Adaptive positioning method, device, and system by integration of TOA (time of arrival) and RSS (received signal strength)

    JP2009210582A