Establishing secure communications between a host device and a peripheral device

A challenge-response procedure with cryptographically-protected data layer communication and event-specific interleavers addresses vulnerabilities in proximity verification, providing secure and efficient communication against relay attacks in low-cost peripheral devices.

WO2025176287A1PCT designated stage Publication Date: 2025-08-28TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/054277
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-20
Publication Date
2025-08-28

AI Technical Summary

Technical Problem

Existing short-range wireless communication systems for proximity verification between a host device and a peripheral device, such as a vehicle and key fob, are vulnerable to distance modification attacks that manipulate physical layer signal properties, and alternative methods using location-specific information are costly and complex.

Method used

A challenge-response procedure with cryptographically-protected data layer communication that includes randomly-selected challenges and time information, using event-specific interleavers to detect and deter relay attacks without additional location-specific measurements.

Benefits of technology

Provides four layers of security protection against distance modification attacks, ensuring secure communication with low complexity and low power consumption, suitable for low-cost peripheral devices like key fobs, without environmental constraints.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024054277_28082025_PF_FP_ABST
    Figure EP2024054277_28082025_PF_FP_ABST
Patent Text Reader

Abstract

According to an aspect, there is provided a method performed by a peripheral device for establishing secure communications with a host device. The method comprises: receiving (1101) a connection instruction message from the host device, wherein the connection instruction message comprises a data element; generating (1103) an interleaver using the data element; using (1101) the generated interleaver to encode a response message for transmission to the host device; and transmitting the encoded response message to the host device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Establishing secure communications between a host device and a peripheral device

[0002] Technical Field

[0003] This disclosure relates to establishing communications between a host device and a peripheral device, for example a vehicle and key fob respectively, and in particular to establishing communications that are more robust against a distance modification attack.

[0004] A class of short-range wireless communication systems are designed for exclusive and secure access and / or connection and / or activation of a host device, for the holder of a specific peripheral device when both devices are in close proximity of each other. The host device may also be referred to as a verifier, security-checker, interrogator, etc. and the peripheral device may also be referred to as a prover, token, key fob, tag, etc.

[0005] Contactless access tokens are used prevalently in these systems, such as for device-to- device (D2D) automatic connection in a private wireless network (e.g. involving headphones, glasses, watches, etc.), smart physical access and authentication control, car user identification, Passive Keyless Entry System (PKES), Active Keyless Entry System (AKES), wireless payment system, electronic passports and many other systems.

[0006] Despite the diverse applications, the systems require the physical proximity of the connecting devices for a secure operation, and thus proximity verification between the host and the peripheral is of high importance for these systems.

[0007] Currently there are two main categories of methods for proximity verification.

[0008] The first category only makes use of physical layer properties of the short-range radio. For short-range radios, the transmission power of the signals may be limited by regulations such an access regulation determining radio transmission rules for usage of a certain radio access frequency band. Physical layer properties such as signal strength, phase variations and propagation delay time of the radio signal are indications of the distance between the communicating devices. These properties are often utilized in many existing systems where physical layer signal measurement-based distance estimation is used for proximity verification. These include Received Signal Strength Indicator (RSSI) based distance estimation, phasebased distance estimation and Time of Flight (ToF) based distance estimation. For a ToF based system, the host measures the round-trip delay of the communicating radio signals. Since a round trip ToF consists of signal timing of two active radio transmissions, the measurement also includes the time required for the processing and transmission of the response by the peripheral device. This time not only dominates the total time elapsed of the round-trip signals due to the short range communication distance assumed in this category, but is also often subject to the signal conditions of the communication such as Signal to Noise Ratio (SNR) / Signal to Interference and Noise Ratio (SINR) since peripheral devices typically have complexity / power constraints.

[0009] Despite being widely used by many existing systems, physical layer signal measurements for proximity verification can be manipulated by attackers in a class of attacks known as distance modification attack. These are described in the paper “Are We Really Close? Verifying Proximity in Wireless Systems” by A Ranganathan, S. Capkun, IEEE Security & Privacy, v.15, no. 3, 2017. Examples of these attacks include amplification-relay which attacks an RSSI-based system, phase wrapping relay which attacks a phase-based system, and response manipulation relay which attacks ToF-based system. Thus, proximity verifications utilising only physical layer signal properties are considered vulnerable and are often subject to distance modification attacks.

[0010] Fig. 1 illustrates a relay implementation of a distance modification attack for a vehicle 102 and the associated key fob 104. The attack is carried out by two colluding attackers, or at least two colluding attacker devices. In this example a first attacker 106 is in proximity of the host device, which is the vehicle 102 in this example, and a second attacker 108 in proximity of the peripheral device, illustrated by the key fob 104 in this example. The second attacker 108 intercepts a radio signal transmitted by the key fob 104 relays it to the first attacker 106, which transmits it to the vehicle 102 and unlocks it. In this case, the short-range radio link designed for direct communication between the host 102 and the peripheral device 104 then effectively communicates over a long range via a relay channel between the attackers 106, 108 without the knowledge of the user of the key fob 104 or vehicle 102. The attack can be successfully carried out even if the data layer of the communication is encrypted.

[0011] In view of the vulnerability of using only physical layer properties for proximity verification, many modified approaches utilise encrypted messages in the communication. Thus, the second category of proximity verification methods make use of encryption in the data layer of the hostperipheral communications, and the exchange of location-specific information. The host and the peripheral devices then utilise the encrypted channel to exchange certain location-specific and dynamic information acquired simultaneously by the host and the peripheral devices. The location-specific information can be, for example, the RSSI of a given spectrum, the Angle of Arrival (AoA) of ambient broadcasting / mobile communication signals which may, for example, be used by a third party at the location being determined in a certain frequency band, noise level variation over time at a specific frequency, local temperature, local audio / mechanical vibrations, various images and even Global Navigation Satellite System (GNSS) location measurement, e.g. a Global Positioning System (GPS) location measurement, etc.

[0012] Proximity verification utilising the AoA of multiple mobile communication base stations has been proposed in US Patent No. 11 ,023,600.

[0013] The first category of proximity verification relies only on the properties in the physical layer of the short-range radio and is known to be vulnerable. However, the second category that utilises the simultaneously-acquired location specific information also has many defects. Devices using the second category are much more expensive to implement and are subject to many restrictions in real applications. The drawbacks and limitations can be summarised as:

[0014] • It will substantially raise the requirement of processing and sensing capabilities for both host and peripheral devices. The complexity, cost and power consumption increase due to these requirements are very challenging for the system implementation, especially for peripheral devices. For example, the radio components are more complicated if they are required to determine if the signal AoAs of external mobile communications are consistent (as proposed in US 11 ,023,600), and if both devices are required to listen to and demodulate / decode signals from a licensed band in addition to, e.g., an Industrial, Scientific, and Medical (ISM) band. For the second category, both the host and the periphery have to be: o equipped with an array antenna or array of antennas and associated Radio Frequency (RF) front end for AoA measurement; o able to listen to and interpret the signals in a specific band, which can be licensed or subscription limited; o able to identify the source of the signal for AoA determination, which implies a fairly complicated signal processing capability that may not be available in the peripheral device; o accurately synchronised in both frequency and time to locate and extract signature signals.

[0015] • In certain locations, the required measurement cannot easily be performed; for example in an underground car parking area, measuring signal AoA of external mobile communications is very difficult.

[0016] • Other types of location-specific measurement are also subject to the condition / environment of the host / peripheral location. For example, GPS location may not be available in certain locations or during certain time periods.

[0017] • Since the cross-check requires simultaneous measurements at both the host and the peripheral, similar sensing capability, accurate synchronisation and coordination are required. This disclosure analyses the constraints and actions of a proximity attack e.g. a distance modification attack, and it is demonstrated that a form of signal relay is indispensable for the enaction of a distance modification attack. Thus, relay detection is an important feature for prevention of the distance modification attack, and embodiments of this disclosure provide techniques that enable relays to be detected. Some embodiments also provide for the hiding of certain information / data to further enable the detection or deterrence of a distance modification attack.

[0018] In embodiments of the techniques described herein, a challenge-response procedure is performed between the host device and the peripheral. A bootstrapping procedure can be performed to establish or exchange the information required for the challenge-response procedure. A prerequisite for the bootstrapping procedure is that a base of mutual trust anchor has already been provisioned, for example in the form of certificates allowing asymmetric cryptography-based key establishment, or via a shared key stored by both parties.

[0019] In the challenge-response procedure the host generates a challenge for which the peripheral is supposed to be able to derive a valid response that can be verified by the host device. In some embodiments, they both store a codebook (e.g. being an indexed list) of valid challenge / response pairs for checking and handshaking. The codebook may comprise random sequences. Alternatively, a cryptographic primitive, e.g., a Hash-based Message Authentication Code (HMAC) with a shared key, is used to generate the response, and where the host / verifier performs the same computation and compares the result from the response. In another alternative, asymmetric signatures are used to sign the challenge, which can be verified by the host device. In yet other alternatives, a Physically Unclonable Function (PUF), implemented on the peripheral device, can receive the challenge as input and generate a response. The host device may have a pre-shared list of challenge-response pairs or a mathematical model of the PUF to verify the authenticity of the response.

[0020] In some examples the connection between the host device and peripheral device is initiated by a connection request from the peripheral device. The host may, while acknowledging the connection request from the peripheral, also indicate, through the encrypted channel, not only the challenge, but also the time points of host transmissions. The time point(s) of host transmission can be randomly chosen, but the use of time points should include the maximum processing and responding time of the devices. In alternative embodiments the process may be initiated by the host in a periphery discovering / detection process. In some embodiments, the host device can also indicate a time point for the peripheral device transmission. Again, this can be randomly chosen, but take into account the maximum processing and responding time of the devices. The connection and authentication can be rejected by either the host device or peripheral device if any of following occur:

[0021] • the peripheral device detects excessive link time between a transmission by the host device and the signal arriving at the peripheral device;

[0022] • the host device determines that the authenticity or integrity of the data sent by the peripheral device is wrong / fails;

[0023] • the peripheral device determines that the authenticity or integrity of the data sent by the host device is wrong / fails;

[0024] • the response to the challenge is not correct; or

[0025] • the time that the host device receives the response from the peripheral device is significantly off from the expected time, i.e. it is not received at the time interval expected after the peripheral device transmission.

[0026] In the embodiments that provide for the ‘hiding’ of certain information / data, an ‘eventspecific’ interleaver can be generated by the peripheral device under an encrypted instruction from the host and used for channel coding. This is in addition to the provision and checking of a host transmission time and / or a peripheral response time. In particular, while acknowledging the connection request from the peripheral, the host device can indicate, through the encrypted channel, a randomly chosen ‘seed’ that enables the generation of a unique event-specific interleaver. The host device and peripheral device may store a specific ‘mother’ interleaver for channel coding that supports a procedure to generate multiple interleavers, for example as used for user separation in an Interleave Division Multiple Access (IDMA) system (as described in “Interleave-Division Multiple-Access” by L. Ping, L. Liu, K. Wu, and W. K. Leung, IEEE TRANS ON WIRELESS COMMUNICATIONS, vol. 5, no. 4, April 2006). Alternatively, a shared secret can be used as a basis to generate random interleavers. Both the host and the peripheral use the same random parameters to instantiate the interleaver, so the computations can be based on the shared secret and the randomly chosen seed, e.g., by using a Pseudo-Random Function (PRF).

[0027] In the case of the event-specific interleaver and use of the host transmission time and peripheral response time, the connection and authentication can be rejected / aborted by either the host device or the peripheral device if any of following happens:

[0028] • the peripheral device detects excessive link time between a transmission by the host device and the signal arriving at the peripheral device;

[0029] • the host device finds that an integrity check (e.g. a Cyclic Redundancy Check (CRC)) of the data frame sent by the peripheral device fails, e.g. as described in “Cryptographically Secure CRC for Lightweight Message Authentication” by E. Dubrova, M. Naslund, G. Selander and F. Lindqvist, https: / / eprint.iacr.org / 2015 / 035.pdf. The integrity check / CRC error may be due to the use of the incorrect interleaver for the channel encoding of the communication;

[0030] • the peripheral device determines that the authenticity or integrity of the data sent by the host device is wrong / fails;

[0031] • the peripheral device determines, e.g. through post checking, that the time from host transmission to peripheral reception is excessive;

[0032] • the host device determines that the authenticity or integrity of the data sent by the peripheral device is wrong / fails; and

[0033] • the host device finds that the time of reception of the transmission by the peripheral device is significantly off the expected time i.e. it is not received within the expected interval after the peripheral response time, which is conveyed to the host with encryption, or there is no response from the peripheral device, i.e. not responding within the host determined response time.

[0034] The techniques described herein are based on the insight that since a form of signal relay is indispensable for enacting a distance modification attack on the short-range radio communications between the host device and peripheral device, the detection and deterrent of relay operations is useful and can be used to prevent or detect the occurrence of a distance modification attack.

[0035] Instead of exchanging a location specific measurement as in some conventional systems, embodiments provide that the host device generates mathematically randomised information, and sends this information through a cryptographically-protected data layer communication, together with specific time information for communications, which prevents any forgery and relaying attacks from the distance modification attackers.

[0036] The cryptographically-protected data layer communication can use Transport Layer Security (TLS) or Datagram TLS (DTLS), which, apart from hiding data through encryption, also include authentication and integrity protection that prevents any forgery attacks.

[0037] Thus, embodiments of the proposed techniques exchange some or all of the following information that is not readable and not modifiable by attackers performing a distance modification attack: a randomly-selected challenge, the time elapsed for the transmission from the host device acknowledging the connection request and the reception of this transmission by the peripheral device, and the randomly-selected time for the peripheral device to start sending the responding transmission.

[0038] With the techniques proposed, a relay attack can be detected by either the host device or the peripheral device using the same radio to check if the communication response is correct in both content and time, without any extra location specific measurement, thus providing an effective, efficient and low complexity solution.

[0039] As noted above, the randomised information can be a seed for a random parameter generation for construction / generation of an event-specific interleaver for the channel encoding, which further deters the acquisition of communication data by attackers, thereby further improving the security of the communications.

[0040] Certain embodiments may provide one or more of the following technical advantage(s) over conventional systems and techniques.

[0041] One advantage is that embodiments provide four layers of checkable security protection against distance modification attack in just one pair of radio links.

[0042] Mutual authentication provides confidentiality and an integrity-protected data channel.

[0043] For embodiments that use an undisclosed and randomly selected event-specific interleaver, the interleaver provides an additional protection layer for the raw data bit-stream.

[0044] Another advantage is that there is one protection layer for which the frame time of the host transmission is checked.

[0045] Another advantage is that there is one protection layer for which the frame time of the peripheral transmission is checked.

[0046] In embodiments where the information for the construction of the interleaver for channel encoding and the transmission times of both host and periphery are passed through the secure data layer providing authenticated encryption, an attacker cannot reproduce the interleaved data packet through channel decoding. This means that the content of the host-peripheral communication is protected by two layers of defence from any attacker.

[0047] In embodiments where the challenge and the transmission times of both host and periphery are passed through the secure data layer providing authenticated encryption, an attacker cannot extract or reproduce the required randomly selected challenge and relay sequence in the host transmission time, providing protection against a distance modification attack.

[0048] The techniques enable the peripheral device to discover that a message has been relayed (i.e. attacked) by checking the difference between the host transmission time and the peripheral receiving time. In addition, the measurement / logging of the receiving time, and / or the time synchronisation between the peripheral device and the host device does not need to be exact. Instead, a time threshold such as half of the corresponding packet time can be used to measure the time elapsed between the expected transmission time of the corresponding message and the reception time, according to the utilized transmission protocol in the system can be sufficient to detect whether the message has been relayed. Another advantage is that only one pair of radio channels is used for communication between host and peripheral devices after a successful bootstrapping procedure. No additional measurement of any type needs to be performed.

[0049] The procedure described herein can be particularly suitable for a low complexity, low power implementation of the peripheral devices, for example a key fob for a vehicle, or a security token.

[0050] Another advantage relates to the lack of location-specific information in the procedure, which means that there are no environmental constraints to the location-specific information which might impair the reliability of the attack prevention scheme.

[0051] Another advantage is that since no extra measurement is performed, the procedure is less vulnerable to attempts to tamper with the existing physical signals, such as false GPS signals.

[0052] According to a first aspect of the techniques described herein, there is provided a method performed by a peripheral device for establishing secure communications with a host device. The method comprises: receiving a connection instruction message from the host device, wherein the connection instruction message comprises a data element; generating an interleaver using the data element; using the generated interleaver to encode a response message for transmission to the host device; and transmitting the encoded response message to the host device.

[0053] According to a second aspect, there is provided a method performed by a host device for establishing secure communications with a peripheral device. The method comprises: sending a connection instruction message to the peripheral device, wherein the connection instruction message comprises a data element; generating an interleaver using the data element; receiving a response message from the peripheral device; and using the generated interleaver to decode the response message.

[0054] According to a third aspect, there is provided a method performed by a peripheral device for establishing secure communications with a host device. The method comprises: receiving a connection instruction message from the host device, wherein the content of the connection instruction message is encrypted and indicates a host transmission time relating to a timing of the transmission of the connection instruction message by the host device; comparing the host transmission time to a time at which the connection instruction message was received by the peripheral device; if the time elapsed since the host transmission time satisfies an attack criterion, transmitting an attack report to the host device indicating that communications with the peripheral device are not secure; and if the time elapsed since the host transmission time does not satisfy the attack criterion, transmitting a response message to the host device to continue the establishment of secure communications with the host device.

[0055] According to a fourth aspect, there is provided a method performed by a host device for establishing secure communications with a peripheral device. The method comprises: transmitting a connection instruction message to the peripheral device, wherein the content of the connection instruction message is encrypted and indicates a host transmission time relating to a timing of the transmission of the connection instruction message by the host device; receiving, from the peripheral device, one of: an attack report indicating that communications with the peripheral device are not secure; and a response message that continues the establishment of secure communications with the peripheral device.

[0056] According to a fifth aspect, there is provided a method performed by a host device for establishing secure communications with a peripheral device. The method comprises: transmitting a connection instruction message to the peripheral device, wherein the content of the connection instruction message is encrypted and indicates a peripheral response time relating to a timing of the transmission of a response to the connection instruction message by the peripheral device; receiving a response message from the peripheral device that continues the establishment of secure communications with the peripheral device; comparing the peripheral response time to a time at which the response message was received by the host device; if the time elapsed since the peripheral response time satisfies an attack criterion, transmitting a rejection message to the peripheral device indicating that communications with the peripheral device are rejected; and if the time elapsed since the peripheral response time does not satisfy the attack criterion, transmitting an acknowledgement message to the peripheral device to continue the establishment of secure communications with the peripheral device.

[0057] According to a sixth aspect, there is provided a computer program product comprising a computer readable medium having computer readable code embodied therein, the computer readable code being configured such that, on execution by a suitable computer or processor, the computer or processor is caused to perform the method of any of the first, second, third, fourth or fifth aspects, or any embodiments thereof.

[0058] According to a seventh aspect, there is provided a peripheral device configured to perform the method according to the first aspect, the third aspect, or any embodiments thereof.

[0059] According to an eighth aspect, there is provided a peripheral device, comprising a processor and a memory, said memory containing instructions executable by said processor whereby said peripheral device is operative to perform the method according to the first aspect, the third aspect, or any embodiments thereof.

[0060] According to a ninth aspect, there is provided a host device configured to perform the method according to the second aspect, the fourth aspect, the fifth aspect, or any embodiments thereof.

[0061] According to a tenth aspect, there is provided a host device comprising a processor and a memory, said memory containing instructions executable by said processor whereby said host device is operative to perform the method according to the second aspect, the fourth aspect, the fifth aspect, or any embodiments thereof.

[0062] Brief Description of the Drawings

[0063] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings, in which:

[0064] Fig. 1 illustrates a relay implementation of a distance modification attack for a vehicle and the associated key fob;

[0065] Fig. 2 is a block diagram of a transceiver that encrypts / decrypts data;

[0066] Fig. 3 shows the signalling between a host device and a peripheral device in a bootstrapping procedure and a challenge-response procedure;

[0067] Fig. 4 is a signalling diagram showing operations of a host device and a peripheral device according to various embodiments;

[0068] Fig. 5 shows an example of the construction of an event-specific interleaver;

[0069] Fig. 6 is a block diagram of another transceiver that encrypts / decrypts data;

[0070] Fig. 7 shows the signalling between a host device and a peripheral device in a bootstrapping procedure and an authenticated encryption procedure;

[0071] Fig. 8 is a signalling diagram showing operations of a host device and a peripheral device according to various embodiments;

[0072] Fig. 9 is a flow chart illustrating a method performed by a peripheral device in accordance with some embodiments;

[0073] Fig. 10 is a flow chart illustrating a method performed by a host device in accordance with some embodiments;

[0074] Fig. 11 is a flow chart illustrating an alternative method performed by a peripheral device in accordance with some embodiments;

[0075] Fig. 12 is a flow chart illustrating another method performed by a host device in accordance with some embodiments; and

[0076] Fig. 13 is a block diagram of an apparatus configured or operable to perform the methods described herein.

[0077] Detailed Description

[0078] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0079] A fundamental aspect of the proximity verification between a host device and a peripheral device lies in their capability to communicate with each other. This implies that both devices have to be able to provide the requested / required information, and the information is received at the requested time.

[0080] The impact to host device-peripheral device communications due to a relay attack is discussed below, along with the techniques presented by this disclosure that enable the relay attack to be detected.

[0081] This disclosure mainly focuses on a relay attack that utilises a digital relay technique which, given a sufficiently large delay tolerance, can relay signals of a short-range radio accurately over an almost unlimited distance to carry out a distance modification attack. A direct analog relay can, in principle, relay a signal over quite a distance, e.g. when the colluding attackers each have a parabolic antenna that are aligned over a line of sight (LoS) distance. However, in practice, an attack using an analog relay is not executable except in few very rare scenarios.

[0082] Fig. 2 is a block diagram of a transceiver 200 that encrypts / decrypts data. Fig. 2 shows an exemplary chain of processing blocks for a generalised digital transceiver 200 that utilises encryption for protecting the data layer. The operations of both the host device and the peripheral device can be abstracted in the form shown in Fig. 2, although with different performances in, for example, sensitivity and processing speed, as the host device and peripheral device are subject to different constraints in complexity, cost and power consumption.

[0083] The transceiver 200 in Fig. 2 is shown as having separate chains for transmission and reception (labelled with reference numerals 202 and 204 respectively). The transmission chain 202 is conceptually divided into an encrypted payload section 206 in which data to be transmitted is encrypted, and a physical layer processing section 208. In the physical layer processing section 208 one or more of the following functions may be performed: channel encoding, interleaving, formatting and insertion of reference signal(s), modulation and radio frequency (RF) processing, before transmission via an antenna. The receiver chain 204 performs the inverse of the operations performed in the transmission chain 202, typically in the reverse order. Thus, a signal is received via an antenna, the signal is processed in a physical layer processing section 210 which may include a RF processing block, followed by demodulation, frequency and time synchronisation, deinterleaving, and channel decoding. The output of the channel decoding is an encrypted payload, which is passed to encrypted payload section 212 in which decryption is performed to extract the data.

[0084] Although the transmission chain 202 and reception chain 204 are shown as being separate, it will be appreciated that, in practice, components can be shared between the chains 202, 204.

[0085] It should also be noted that in the physical layer (layer 1) processing section 208, some pilot / reference signal sequence is inserted for time and frequency synchronisation of the communicating devices, which can be used when timing the arrival of the signal from the other device.

[0086] Although the encryption / cryptographic scheme used in the encrypted payload blocks 206, 212 can be public, an undisclosed secret key is required for decryption. The encryption scheme provides both authenticity, integrity, and confidentiality protection, e.g. realised by a symmetric cipher in Authenticated Encryption with Associated Data (AEAD) mode. The key exchange procedure is outside the scope of this disclosure (although well known to those skilled in the art), but could be a shared symmetric key pair that is provisioned during manufacture of the host device and peripheral device.

[0087] Without the secret key, the authenticated encryption is considered to be unbreakable. The physical layer processing of the short-range radio signals, as shown in physical layer processing sections 208, 210, is usually ‘public’, and the frame structure, coding scheme, interleaving format, and modulation constellations are all known, or standardised, and can be performed by different devices. Thus, the conceptual separation of the transmission and reception chains 202, 204 into encrypted payload section 206 / 212 and physical layer processing section 208 / 210 shows the parts of the chain protected from attackers.

[0088] In a distance modification attack, shown as in Fig. 1 , a new radio link is introduced by the colluding attackers 106, 108 to relay the signals of the short-range radio to / from the key fob 104 and to / from the vehicle 102. For the downlink direction (meaning the host device (vehicle 102) to peripheral device (key fob 104) relay), for example, the device 106 of the first attacker receives the radio signal of the host device 102, performs physical signal processing of the reception chain as shown in Fig. 2 until the encrypted data payload is obtained. Since the attackers 106, 108 do not have access to the decryption key, the decryption cannot be performed. Instead, the encrypted payload data is repacked and sent out through a new radio link to the second attacker 108, possibly with a higher bandwidth to reduce the delay. The second attacker 108 then unpacks and reconstructs the packet according to the protocol of the short-range radio they are attacking, i.e. the radio link between the key fob 104 and the vehicle 102. In this way the second attacker 108 is reproducing a legitimate radio signal to the peripheral device 104. If the host device and peripheral device are unaware of the relaying operation, the devices are linked falsely due to the distance modification attack. Since the attackers do not need to decrypt the data payload, the attack can be successfully implemented without possession of the decryption key. It can be assumed that the attackers 106, 108 have access to wideband radio resources, with which the relay transmission between the attackers can be completed almost instantly (i.e. with a minimum additional delay to the radio wave propagation time).

[0089] Inspection of the transceiver physical layer processing section 208 shows that the relay attack will still leave a trace in terms of excessive latency. This is due to the need for any intervening receiver to decode the transmitting frame correctly, and this requires interleaving and channel decoding to be performed. However, decoding cannot start before the deinterleaving operation is finished, which means, for a typical interleaver, the whole frame of the data has to be received. Thus, correct (channel) decoding of the packet requires the whole frame to be completely received. Completing this processing will introduce a frame delay, counted by the transmission rate of the short-range radio. In other words, for correct reception of a channel encoded packet with any receiver, a frame delay has to be introduced, which is counted with the symbol rate of the short-range radio and is independent of the processing power of the receiver, and correct deinterleaving has to be performed.

[0090] In view of the above, this disclosure presents techniques for detecting and deterring use of a distance modification attack. Embodiments of the techniques provide one or more ways to detect and / or deter relay attacks, and in particular the checking of the timing of either or both of host to peripheral communications and peripheral to host communications. Further embodiments provide for an identity (ID) check that is usually applied, and the checking of the content of the communications. In addition, embodiments provide for the adaptation of the interleaver / deinterleaver for channel encoding / decoding respectively to further secure the communication link against a relay attack.

[0091] Before describing particular embodiments of the techniques described herein, the general bootstrapping and challenge-response procedures are briefly discussed with reference to Fig. 3. Fig. 3 shows the signalling between host device 301 and peripheral device 303 in a bootstrapping procedure 310 and a challenge-response procedure 312. In the bootstrapping procedure 310, a key or other form of secret is established and / or shared between the host 301 and peripheral device 303. This key establishment is shown by arrow 314, and results in both the host device 301 and peripheral device 303 having a shared key 316, with the key denoted k.

[0092] In the challenge-response procedure 312, the host device 301 sends a challenge 318 to the peripheral device 303. In step 320 the peripheral device 303 determines the appropriate response to the challenge, and forms a response message H that is a function of the received challenge 318, and the shared key, k. It will be appreciated that the challenge response can take a number of different forms that depends on the challenge-response procedure being used. For example, the response can be extracted from a codebook that lists valid challenge-response pairs, and in another example the response can be derived from the challenge through a known transformation, function or encryption with the shared key 316.

[0093] In step 322, which is optional depending on the particular type of challenge-response procedure being used, the host device 301 determines an expected response to the challenge. The expected response can be determined in a similar way to how the peripheral device 303 determines the response in step 320.

[0094] The peripheral device 303 transmits the response message 324 to the host device 301 .

[0095] In step 326, which is optional along with step 322, the host device 301 determines if the received challenge response matches the expected response. If the received challenge response does match the expected response, then the peripheral device 303 has successfully authenticated itself to the host device 301.

[0096] As noted below, the above challenge-response procedure is integrated into the wider procedure for detecting occurrence of a distance modification attack.

[0097] One embodiment of the techniques described herein is illustrated in Fig. 4 in the form of a Message Sequence Chart (MSC), which closely resembles that supported by Specification Description Language-Real Time (SDL-RT) (as described in SDL-RT v2.4, Sept. 20, 2021 , found at: http: / / www.sdl-rt.org). SDL-RT is an extension to the International Telecommunication Union (ITU) standardisation sector (ITU-T) standard SDL. Fig. 4 shows the signalling between a host device 401 and a peripheral device 403, and uses a number of special components, such as semaphore, timer, lifeline tail / stopper and state, that are fundamental to the SDL-RT (MSC). Two types of timer-conditioned task blocks are also introduced. The first type of timer-task block, which is labelled with *|T, will perform the task and then stay idle (pause) while checking whether the timer (which must be set to be longer than the task operation time) has expired. The composite operations HProc|T and Pproc|T shown in Fig. 4 are examples of this type of timertask block. The second type of timer-task block, labelled with *&T, will check the timer during the operation, and if the timer is up (expires) before the task is completed, the operation will be aborted and the process will enter an interrupt procedure. An example of this type of timer-task block is the composite operation Q&T shown in Fig. 4.

[0098] In the specific embodiment illustrated in Fig. 4, a relay attack is detected by checking the ID of the peripheral device 403, along with checking the timing of both host to peripheral communications and peripheral to host communications.

[0099] Initially, as indicated by blocks 405 and 407 respectively, both the host device 401 and the peripheral device 403 are in an unconnected state (“uncon”).

[0100] Communications between the peripheral device 403 and the host device 401 are initiated by the peripheral device 403 sending a connection request 409 to the host device 401. The connection request 409 can comprise an identifier (ID) for the peripheral device 403, and optionally also information indicating a class of the peripheral device 403. The class of the peripheral device 403 can indicate, for example, a processing capability or complexity, which can subsequently be used by the host device 401 to adjust parameters of the communications. In the case of a vehicle 401 and key fob 403, the class information may be predetermined, or determined in the setting up / initialisation procedure, and so may not be required.

[0101] In an alternative embodiment to that shown in Fig. 4, the host device 401 can initiate the communications with the peripheral device 403, for example by the host device 401 performing a peripheral device discovery operation.

[0102] In decision block 411 , the host device 401 checks the ID of the sender of the connection request 409. If the ID is valid, then the process passes to block 413. If the ID is not valid, for example it does not match the ID of any known or expected peripheral devices 403, then the host device 401 ceases communication with the peripheral device 403 and the process ends.

[0103] At block 413, a specific semaphore process is created to handle the connection with the specified ID.

[0104] A host transmission time, Th, is determined. The host transmission time is the time at which the host device 401 is to transmit a connection instruction message to the peripheral device 403, e.g. 1pm. The host transmission time Th is determined based on the current time, the (approximate) time taken for the host device 401 to process data ready for transmission (e.g. to complete all the processing according to the transmission chain 202 in Fig. 2), and optionally a time margin to allow for unexpected delays.

[0105] At block 415, a timer (with value T1 ) is started to track the host transmission time Th, and so determine the time at which the host device 401 is to transmit a connection instruction message to the peripheral device 403.

[0106] While the timer is running, the host device 401 prepares the message for transmission (block 417). In block 417 (Hproc|T), the data for the connection instruction message is processed according to the transmission chain 202 in Fig. 2.

[0107] At the host transmission time, the host device 401 transmits a connection instruction message 419 to the peripheral device 403. The connection instruction message 419 includes the host transmission time (Th), a value for a peripheral response time (Tr), and a challenge (Qk). The payload of the connection instruction message 419 comprising the host transmission time, peripheral response time and the challenge is encrypted, so even if an attacker 106, 108 does intercept the connection instruction message 419, they are not able to determine the host transmission time, the peripheral response time or the challenge.

[0108] The challenge Qk can be randomly selected by the host device 401 .

[0109] The peripheral response time Tr represents the maximum time (duration) that the host device 401 will wait after Th for a response from the peripheral device 403, and in particular indicates the maximum amount of time the host device 401 will wait for the peripheral device 403 to transmit a reply to the connection instruction message 419. The peripheral response time can be determined by the host device 401 based on the time taken for the peripheral device 403 to receive the connection instruction message 419, process and decrypt the connection instruction message 419 and determine a suitable response message. The time taken for the peripheral device 403 to perform these processing operations is referred to as the peripheral processing time, and is denoted Pproc. Preferably the peripheral response time is also determined based on a randomly selected interval, to make it difficult for an attacker to ‘guess’ the other elements contributing to the peripheral response time.

[0110] The peripheral device 403 receives the connection instruction message 419 and extracts / decrypts the data, including the host transmission time Th. The processing blocks performed to extract / decrypt the data are shown in the top half of the expanded version of Pproc|T block 431. In particular, the peripheral device 403 performs demodulation, deinterleaving, channel decoding, and decryption to obtain the data contained in the connection instruction message 419.

[0111] The peripheral device 403 also notes the time at which the connection instruction message 419 was received.

[0112] At decision block 421 , the peripheral device 403 checks an attack criterion to determine whether a relay attack may have occurred on the host-to-peripheral communication link. The attack criterion relates to the time of receipt of the connection instruction message 419 and the host transmission time. In particular the attack criterion can check for an ‘excessive’ delay in the receipt of the connection instruction message 419 after the host transmission time. For example, the attack criterion can be expressed as a threshold (e.g. half of the required transmission time of the message according to the utilized communication protocol), and if the difference between the receipt time and the host transmission time exceeds the threshold, the delay can be deemed excessive.

[0113] If the attack criterion is met / satisfied (i.e. the delay in receiving the connection instruction message 419 is excessive), then the peripheral device 403 can send an attack report 423 to the host device 401 indicating that communications with the peripheral device 403 are not secure, and a relay attack may be taking place.

[0114] At decision block 425 the host device 401 determines if an attack report has been received. If an attack report has been received from the peripheral device 403, then the host device 401 ceases communication with the peripheral device 403 and the process ends.

[0115] Assuming no attack report has been received, following the transmission of the connection instruction message 419, the host device 401 starts a timer T2 that has a duration based on the peripheral response time T r and a packet time Tf. Timer T2 is used to check whether a reply from the peripheral device 403 is received in time, and is represented by block 427. If at block 421 the peripheral device 403 determines that the attack criterion is not met or satisfied (i.e. the delay in receiving the connection instruction message 419 is not excessive), then at block 429 the peripheral device 403 starts a timer T3 track the peripheral response time Tr, and so determine the time by which the peripheral device 403 is to transmit a response to the connection instruction message to the host device 401.

[0116] While the timer 429 is running, the peripheral device 403 processes the received connection instruction message 419 and determines a response. This processing is represented by block 431. In block 431 the peripheral device 403 can determine the response to the challenge Qk, for example selecting the correct challenge response Q from a stored codebook (this is shown as a processing block in the middle of the expanded version of block 431 (Pproc|T) in Fig. 4.

[0117] The processing blocks in the bottom half of the expanded version of block 431 (Pproc|T) in Fig. 4 show the subsequent processing by the peripheral device 403 to generate and transmit the response message to the connection instruction message 419. Thus, the peripheral device 403 encrypts the content of the response message (i.e. the challenge response), performs channel encoding, interleaving and modulation. Once the timer T3 that was initiated in block 429 expires, i.e. it is time for the peripheral device 403 to transmit the response message, the peripheral device 403 enables the transmitter and transmits the response message to the host device 401. This response message is shown as ConChk(Q) message 433. The time that the peripheral device 403 transmits the response message 433 is referred to as the peripheral transmission time, Tp.

[0118] The host device 401 receives the response message 433. The host device 401 notes the time at which the response message 433 was received.

[0119] In Q&T (‘Q evaluation with timer condition’) block 435, the host device 401 checks an attack criterion to determine whether a relay attack may have occurred on the peripheral-to-host communication link. The attack criterion relates to the time of receipt of the response message 433, the peripheral response time, and optionally the time since the host device 401 transmitted the connection instruction message 419. In particular the attack criterion can check for an ‘excessive’ delay in the receipt of the response message 433 after the time allowed by the peripheral response time. This check can be performed by determining if the timer T2 (that was initiated in block 427) has expired, or performed by checking the receipt time against the time that the response was expected to be received (which is based on the host transmission time and the peripheral response time). If the timer T2 has expired or the receipt time exceeds a threshold (with the threshold being based on the peripheral response time plus a half frame time (Tf / 2)), the delay can be deemed excessive (e.g. due to the presence of intervening attacker devices), and the communications between the host device 401 and peripheral device 403 can be aborted.

[0120] It will be noted that if no response message 433 is received from the peripheral device 403 within the threshold time, Q&T block 435 will also abort the communications.

[0121] Otherwise, the host device 401 can proceed to extract / decrypt the data in the response message 433 in Q&T block 435, and in particular extracts the challenge response Q. The processing steps performed at block 435 are shown in the expanded version of Q&T block 435. The processing blocks performed to extract / decrypt the data include demodulation, deinterleaving, channel decoding, evaluating a CRC and, if passed, decrypting the data contained in the response message 433.

[0122] The host device 401 than checks the validity of the challenge response Q. If the challenge response Q is incorrect or does not match the response that the host device 401 expected, the host device 401 rejects the connection with the peripheral device 403, and sends a rejection message 437 (e.g. a negative acknowledgement, NACK) to the peripheral device 403. If the challenge response Q is correct, the host device 401 accepts the connection with the peripheral device 403, and sends an acceptance message 439 (e.g. a positive acknowledgement, ACK to the peripheral device 403. The host device 401 then change to a connected state 441 (pIDcon).

[0123] At the peripheral device 403, if a rejection message 437 is received which is checked at block 443, then the peripheral device 403 aborts the communications with the host device 401. If an acceptance message 439 is received as checked at block 443, then the peripheral device 403 changes to a connected state 445 (Hcon).

[0124] Once the host device 401 and peripheral device 403 are in connected states, further communications can be performed between the devices, such as the key fob unlocking and / or starting the vehicle.

[0125] Thus, the procedure in Fig. 4 enables a relay attack to be detected, and for the host device 401 and / or peripheral device 403 to trigger the cessation of communications in the event that an attack is detected.

[0126] As noted above, some embodiments provide for the adaptation of the interleaver / deinterleaver for channel encoding / decoding respectively to further secure the communication link against a relay attack. These embodiments are described with respect to Figs. 5-8.

[0127] First, an event-specific interleaver that can be concealed from potential attackers is introduced, which prevents an attacker from performing correct channel decoding. The eventspecific interleaver can be configured with just a few parameters randomly selected by the host device, that are encrypted and sent to the peripheral for encoding operations. The event-specific interleaver utilises characteristics from user-specific interleavers employed in IDMA systems.

[0128] A multi-user IDMA system, as described in “Interleave-Division Multiple Access” referenced above has been the subject of research activities in the wireless communication society for some time. IDMA, like Code Division Multiple Access (CDMA), is a spectrum spreading multiple access scheme which utilises asymptotic orthogonal interleavers to accommodate multiple users. Unlike interleavers for burst error prevention in a classical channel encoder, multiple user-specific interleavers are of vital importance for IDMA for user separation and system performance. Constructing multiple mutually-distinguishable interleavers is often expensive in terms of parameter communication, computation and memory requirements. Some research has concentrated on low complexity solutions of this problem, for example as described in “Simple Construction of Multiple Interleavers: Cyclically Shifting a Single Interleaver” by K. Kusume and G. Bauch, in IEEE TRANS ON COMMUNICATIONS, vol. 56, no. 9, Sept. 2008.

[0129] In the present case, the event-specific interleaver is for peripheral-host communications rather than for user separation. In particular, the unique interleaver is to be used to conceal the decoding operations from potential attackers. Therefore, the orthogonality of interleavers for user separation is also a desired property for the event-specific interleaver. Simple and effective configuration is also required for low complexity peripheral devices. Thus, the event specific interleaver concealed from attackers can be constructed with a similar approach as in “Simple Construction of Multiple Interleavers: Cyclically Shifting a Single Interleaver” referenced above.

[0130] Fig. 5 shows an example of the construction of an event-specific interleaver with D-step operations, where D > 3, as it has been found that the generated interleavers are independent when D > 3. A mother interleaver, e.g. a random interleaver, is public and stored by both the host device and the peripheral device (or is otherwise accessible to these devices), which is also used in the initial communications. When the peripheral device receives an instruction and suitable parameters from the host device, the peripheral transmission channel encoding interleaving operation is performed accordingly, where all the kie{i,D} are derived from a random seed parameter sent by the host device via an encrypted communication. The generation of the eventspecific interleaver can be as follows:

[0131] 1. Set i = 1 ,

[0132] 2. Interleave with the mother interleaver ir (labelled 501 in Fig. 5),

[0133] 3. Cyclic shift with parameter ki = kj% / V, where % denotes moduli operation and / V is the frame size,

[0134] 4. Set i = i+1 , repeat step 2 and 3, until i > D.

[0135] Due to the concealed event specific interleaver, the physical layer of the peripheral-host communication exposed to the attackers is significantly reduced, as shown in Fig. 6.

[0136] Fig. 6 is a block diagram of a transceiver 600 that encrypts / decrypts data, and that generally corresponds to the transceiver 200 shown in Fig. 2. Fig. 6 shows an exemplary chain of processing blocks for a generalised digital transceiver 600 that utilises encryption and adaptive interleaving for protecting the data layer. The operations of both the host device and the peripheral device can be abstracted in the form shown in Fig. 6, although with different performances in, for example, sensitivity and processing speed, as the host device and peripheral device are subject to different constraints in complexity, cost and power consumption.

[0137] The transceiver 600 in Fig. 6 is shown as having separate chains for transmission and reception, labelled with reference numerals 602 and 604 respectively. The transmission chain 602 is conceptually divided into an encrypted / non-decodable payload section 606 in which data to be transmitted is encrypted, channel encoded and interleaved using an event-specific interleaver, and a physical layer processing section 608. In the physical layer processing section 608 the following functions are performed: formatting and insertion of reference signal(s), modulation and RF processing, before transmission via an antenna. The receiver chain 604 performs the inverse of the operations performed in the transmission chain 602, in the reverse order. Thus, a signal is received via an antenna, the signal is processed in a physical layer processing section 610 by a RF processing block, followed by demodulation, frequency and time synchronisation. In the encrypted / non-decodable payload section 612, deinterleaving, channel decoding and decryption is performed to extract the data.

[0138] As with Fig. 2, although the transmission chain 602 and reception chain 604 are shown as being separate, it will be appreciated that, in practice, components can be shared between the chains 602, 604.

[0139] It should also be noted that in the physical layer (layer 1) processing section 608, some pilot / reference signal sequence is inserted for time and frequency synchronisation of the communicating devices, which can be used when timing the arrival of the signal from the other device.

[0140] Although the encryption / cryptographic scheme used in the encrypted payload blocks 606, 612 can be public, an undisclosed, secret key is required for decryption. The encryption / cryptographic scheme provides both authenticity, integrity, and confidentiality protection, e.g. realised by a symmetric cipher in Authenticated Encryption with Associated Data (AEAD) mode. The key exchange procedure is outside the scope of this disclosure (although well known to those skilled in the art), but could be a shared symmetric key pair that is provisioned during manufacture of the host device and peripheral device.

[0141] Without the secret key, the authenticated encryption is considered to be unbreakable, and without knowledge of the event-specific interleaver, deinterleaving and channel decoding cannot be performed. Thus, the conceptual separation of the transmission / reception chains 602, 604 into encrypted payload section 606 / 612 and physical layer processing section 608 / 610 shows the parts of the chain protected from attackers.

[0142] Before describing a particular embodiment of the event-specific interleaver technique described herein, the general bootstrapping and authenticated encryption procedures are briefly discussed with reference to Fig. 7. Fig. 7 shows the signalling between host device 701 and peripheral device 703 in a bootstrapping procedure 710 and an authenticated encryption procedure 712. In the bootstrapping procedure 710, a key or other form of secret is established and / or shared between the host 701 and peripheral device 703. This key establishment is shown by arrow 714, and results in both the host device 701 and peripheral device 703 having a shared key 716, with the key denoted k.

[0143] In the authenticated encryption procedure 712, the peripheral device 703 sends a connection request 718 to the host device 701 . In step 720 the host device 701 sends a random seed e.g. a random number and the transmission time point (e.g. the host transmission time and / or peripheral response time) to the peripheral device 703. In step 722 the peripheral device 703 generates the random parameters (or secret parameters) required for generating the eventspecific interleaver from the seed and the shared key 716. The random or secret parameters can be generated using a Pseudo-Random Function (PRF) that takes the seed and key 716 as inputs. In step 724 the host device 701 also generates the random or secret parameters required for generating the event-specific interleaver from the seed and the shared key 716, thereby enabling the host device 701 and peripheral device 703 to generate the same interleaver.

[0144] As noted below, the above authenticated encryption procedure is integrated into the wider procedure for detecting and deterring occurrence of a distance modification attack.

[0145] One embodiment of the techniques described herein is illustrated in Fig. 8 in the form of a MSC. Fig. 8 shows the signalling between a host device 801 and a peripheral device 803, and uses a number of special components, such as semaphore, timer, lifeline tail / stopper and state, that are fundamental to the SDL-RT (MSC). The two types of timer-conditioned task blocks introduced above (*|T and *&T) are also present in Fig. 8.

[0146] In the specific embodiment illustrated in Fig. 8, a relay attack is detected by checking the ID of the peripheral device 803, along with checking the timing of both host to peripheral communications and peripheral to host communications, and the channel encoding and content of the peripheral-host communications are confined to the peripheral device and host device.

[0147] In the embodiment shown in Fig. 8, it is assumed that both the host device 801 and peripheral device 803 have stored, or otherwise have access to, the mother interleaver that is to be used to generate the event-specific interleaver.

[0148] Initially, as indicated by blocks 805 and 807 respectively, both the host device 801 and the peripheral device 803 are in an unconnected state (“uncon”). Communications between the peripheral device 803 and the host device 801 are initiated by the peripheral device 803 sending a connection request 809 to the host device 801. The connection request 809 can comprise an identifier (ID) for the peripheral device 803, and optionally also information indicating a class of the peripheral device 803. The class of the peripheral device 803 can indicate, for example, a processing capability or complexity, which can subsequently be used by the host device 801 to adjust parameters of the communications. In the case of a vehicle 801 and key fob 803, the class information may be predetermined, or determined in the setting up / initialisation procedure, and so may not be required.

[0149] In an alternative embodiment to that shown in Fig. 8, the host device 801 can initiate the communications with the peripheral device 803, for example by the host device 801 performing a peripheral device discovery operation.

[0150] In decision block 811 , the host device 801 checks the ID of the sender of the connection request 809. If the ID is valid, then the process passes to block 813. If the ID is not valid, for example it does not match the ID of any known or expected peripheral devices 803, then the host device 801 ceases communication with the peripheral device 803 and the process ends.

[0151] At block 813, a specific semaphore process is created to handle the connection with the specified ID.

[0152] A host transmission time, Th, is determined. The host transmission time is time at which the host device 801 is to transmit a connection instruction message to the peripheral device 803. The host transmission time Th is determined based on the current time, the (approximate) time taken for the host device 801 to process data ready for transmission (e.g. to complete all the processing according to the transmission chain 602 in Fig. 6), and optionally a time margin to allow for unexpected delays.

[0153] At block 815, a timer (with value T1 ) is started to track the host transmission time Th, and so determine the time at which the host device 801 is to transmit a connection instruction message to the peripheral device 803.

[0154] While the timer is running, the host device 801 prepares the message for transmission (block 817). In block 817 (Hproc|T) the data for the connection instruction message is processed according to the transmission chain 602 in Fig. 6.

[0155] At the host transmission time, the host device 801 transmits a connection instruction message 819 to the peripheral device 803. The connection instruction message 819 includes the host transmission time (Th), a value for a peripheral response time (Tr), a challenge, and a random seed (ki) that is to be used to construct the event-specific interleaver. The connection instruction message can be interleaved using the mother interleaver. The payload of the connection instruction message 819 comprising the host transmission time, peripheral response time, the challenge and the seed is encrypted, so even if an attacker 106, 108 does intercept the connection instruction message 819, they are not able to determine the host transmission time, the peripheral response time, the challenge, or the seed.

[0156] The challenge can be randomly selected by the host device 801.

[0157] Similar to the host transmission time, the peripheral response time Tr represents the maximum time (duration) that the host device 401 will wait for a response from the peripheral device 403 after Th, and in particular indicates the maximum amount of time the host device 801 will wait for the peripheral device 803 to transmit a reply to the connection instruction message 819. The peripheral response time can be determined by the host device 801 based on the time taken for the peripheral device 803 to receive the connection instruction message 819, process and decrypt the connection instruction message 819 and determine a suitable response message. The time taken for the peripheral device 803 to perform these processing operations is referred to as the peripheral processing time, and is denoted Pproc. Preferably the peripheral response time is also determined based on a randomly selected interval, to make it difficult for an attacker to ‘guess’ the other elements contributing to the peripheral response time.

[0158] The peripheral device 803 receives the connection instruction message 819 and extracts / decrypts the data, including the host transmission time Th. The processing blocks performed to extract / decrypt the data are shown in the top half of the expanded version of Pproc|T block 831. In particular, the peripheral device 803 performs demodulation, deinterleaving (according to the mother interleaver), channel decoding, and decryption to obtain the data contained in the connection instruction message 819.

[0159] The peripheral device 803 also notes the time at which the connection instruction message 819 was received.

[0160] At decision block 821 , the peripheral device 803 checks an attack criterion to determine whether a relay attack may have occurred on the host-to-peripheral communication link. The attack criterion relates to the time of receipt of the connection instruction message 819 and the host transmission time. In particular the attack criterion can check for an ‘excessive’ delay in the receipt of the connection instruction message 819 after the host transmission time. For example, the attack criterion can be expressed as a threshold, e.g. half the required time to transmit the message according to the utilized communication protocol, and if the difference between the receipt time and the host transmission time exceeds the threshold, the delay can be deemed excessive.

[0161] If the attack criterion is met / satisfied (i.e. the delay in receiving the connection instruction message 819 is excessive), then the peripheral device 803 can send an attack report 823 to the host device 801 indicating that communications with the peripheral device 803 are not secure, and a relay attack may be taking place.

[0162] At decision block 825 the host device 801 determines if an attack report has been received. If an attack report has been received from the peripheral device 803, then the host device 801 ceases communication with the peripheral device 803 and the process ends.

[0163] Assuming no attack report has been received, following the transmission of the connection instruction message 819, the host device 801 starts a timer T2 that has a duration based on the peripheral response time Tr and a packet time Tf (block 827). Timer T2 is used to check whether a reply from the peripheral device 803 is received in time, and is represented by block 827.

[0164] If at block 821 the peripheral device 803 determines that the attack criterion is not met or satisfied (i.e. the delay in receiving the connection instruction message 819 is not excessive), then at block 829 the peripheral device 803 starts a timer T3 track the peripheral response time Tr, and so determine the time by which the peripheral device 803 is to transmit a response to the connection instruction message to the host device 801.

[0165] While the timer 829 is running, the peripheral device 803 processes the received connection instruction message 819 and determines a response. This processing is represented by block 831. In block 831 the peripheral device 803 can determine the response to the challenge, for example selecting the correct challenge response Q from a stored codebook (this is shown as a processing block in the middle of the expanded version of block 831 (Pproc|T) in Fig. 8.

[0166] The peripheral device 803 constructs / generates the event-specific interleaver (shortened to ESITL in the figures) using the random seed ki included in the connection instruction message 819 and a key (e.g. that was shared during bootstrapping procedure 710). In particular, the peripheral device 803 can generate a parameter from the seed and the shared key, and use the parameter for generating the event-specific interleaver. The parameter can be generated using a PRF that takes the seed and key as inputs. The peripheral device 803 then uses the parameter Q to generate the event-specific interleaver.

[0167] The processing blocks in the bottom half of the expanded version of block 831 (Pproc|T) in Fig. 8 show the subsequent processing by the peripheral device 803 to generate and transmit the response message to the connection instruction message 819. Thus, the peripheral device 803 encrypts the content of the response message i.e. including the challenge response Q, performs channel encoding, interleaving using the generated event-specific interleaver and modulation.

[0168] Once the timer T3 that was initiated in block 829 expires, i.e. it is time for the peripheral device 803 to transmit the response message, the peripheral device 803 enables the transmitter and transmits the response message to the host device 801. This response message is shown as ConChk(Q) message 833. The time that the peripheral device 803 transmits the response message 833 is referred to as the peripheral transmission time, Tp. The host device 801 receives the response message 833. The host device 801 notes the time at which the response message 833 was received.

[0169] In Q&T block 835, the host device 801 checks an attack criterion to determine whether a relay attack may have occurred on the peripheral-to-host communication link. The attack criterion relates to the time of receipt of the response message 833, the peripheral response time, and optionally the time since the host device 801 transmitted the connection instruction message 819. In particular the attack criterion can check for an ‘excessive’ delay in the receipt of the response message 833 after the time allowed by the peripheral response time. This check can be performed by determining if the timer T2 (that was initiated in block 827) has expired, or performed by checking the receipt time against the time that the response was expected to be received (which is based on the host transmission time and the peripheral response time). If the timer T2 has expired or the receipt time exceeds a threshold (with the threshold being based on the peripheral response time plus a half frame time (Tf / 2), the delay can be deemed excessive (e.g. due to the presence of intervening attacker devices), and the communications between the host device 801 and peripheral device 803 can be aborted.

[0170] It will be noted that if no response message 833 is received from the peripheral device 803 within the threshold time, Q&T block 835 will also abort the communications.

[0171] Otherwise, the host device 801 can proceed to extract / decrypt the data in the response message 833 in Q&T block 835. The processing steps performed at block 835 are shown in the expanded version of Q&T block 835, and it will be appreciated that the host device 801 has also constructed / generated the event-specific interleaver using the random seed ki sent in the connection instruction message 819 and the shared key e.g. that was shared during the bootstrapping procedure 710, so the deinterleaving of the response message 833 is performed using the event-specific (de)interleaver. The processing blocks performed to extract / decrypt the data include demodulation, deinterleaving using the event-specific interleaver, channel decoding, evaluating a CRC and, if passed, decrypting the data contained in the response message 833.

[0172] The host device 801 then checks the validity of the challenge response Q. If the challenge response Q is incorrect or does not match the response that the host device 801 expected, the host device 801 rejects the connection with the peripheral device 803, and sends a rejection message 837 e.g. a negative acknowledgement, NACK to the peripheral device 803. If the challenge response Q is correct, the host device 801 accepts the connection with the peripheral device 803, and sends an acceptance message 839, e.g. a positive acknowledgement, ACK, to the peripheral device 803. The host device 801 then change to a connected state 881 (pIDcon).

[0173] At the peripheral device 803, if a rejection message 837 is received (which is checked at block 883), then the peripheral device 803 aborts the communications with the host device 801. If an acceptance message 839 is received, as checked at block 883, then the peripheral device 803 changes to a connected state 885 (Hcon).

[0174] Once the host device 801 and peripheral device 803 are in connected states, further communications can be performed between the devices, such as the key fob unlocking and / or starting the vehicle.

[0175] Thus, the procedure in Fig. 8 enables a relay attack to be detected, and for the host device 801 and / or peripheral device 803 to trigger the cessation of communications in the event that an attack is detected.

[0176] Fig. 9 is a flow chart illustrating a method of operating a peripheral device for establishing secure communications with a host device according to various embodiments. The peripheral device can be any of peripheral device 303, 403, 703 and 803. The host device can be any of host device 301 , 401 , 701 and 801. The peripheral device may perform the method in response to executing suitably formulated computer readable code. The computer readable code may be embodied or stored on a computer readable medium, such as a memory chip, optical disc, or other storage medium. The computer readable medium may be part of a computer program product.

[0177] In particular embodiments, the peripheral device is a key or key fob, and the host device is a vehicle.

[0178] In step 901 , the peripheral device receives a connection instruction message from the host device. The content of the connection instruction message is encrypted and indicates a host transmission time relating to a timing of the transmission of the connection instruction message by the host device. The connection instruction message may be the Conlnst message 419 in Fig. 4 or the Conlnst message 819 in Fig. 8.

[0179] In step 903, the peripheral device compares the host transmission time to a time at which the connection instruction message was received by the peripheral device.

[0180] In step 905, it is determined whether the time elapsed since the host transmission time satisfies an attack criterion. The attack criterion provides a way to determine if the time elapsed shows evidence of an attack (e.g. a relay attack). Thus, the attack criterion can be based on an expected propagation time between the host device and the peripheral device.

[0181] If the time elapsed since the host transmission time satisfies the attack criterion, then in step 907 the peripheral device transmits an attack report to the host device indicating that communications with the peripheral device are not secure. The attack report can be the R-att report 423 in Fig. 4 or the R-att report 823 in Fig. 8. In some embodiments, after sending the attack report, the peripheral device can stop communications with the host device (e.g. temporarily deactivate a transceiver of the peripheral device). However, if the time elapsed since the host transmission time does not satisfy the attack criterion, then in step 909 the peripheral device transmits a response message to the host device to continue the establishment of secure communications with the host device. The response message can be the ConChk message 433 in Fig. 4 or the ConChk message 833 in Fig. 8. The content of the response message may be encrypted.

[0182] The encrypted content of the connection instruction message received in step 901 may also comprise a peripheral response time relating to a timing of the transmission of the response message by the peripheral device. In this case, the peripheral device transmits the response message in step 909 according to the peripheral response time (e.g. the peripheral device transmits the response message within the time limit provided for by the peripheral response time).

[0183] The establishment of secure communications with a host device may further comprise a challenge-response procedure. In this case, the connection instruction message received in step 901 can comprise a challenge, and the peripheral device can determine a challenge response to the challenge. The response message sent in step 909 can comprise the determined challenge response. In some cases, the challenge response may only be determined if the time elapsed since the host transmission time does not satisfy the attack criterion.

[0184] For the challenge-response procedure, the peripheral device may have a stored codebook that comprises a plurality of challenges and a corresponding plurality of challenge responses. In this case, the challenge response can be determined by looking up the challenge response in the codebook corresponding to the received challenge.

[0185] As an alternative to having a stored codebook, the peripheral device may determine the challenge response by generating the challenge response from the received challenge. For example, the challenge response can be determined by signing the challenge using a cryptographic key, generating the challenge response using a hash function, or generating the challenge response from a PUF.

[0186] After sending the response message in step 909, the peripheral device may receive a further message from the host device. This further message indicates whether or not the communications between the host device and the peripheral device are secure. For example, this message can be the Nack message 437, 837 described above, indicating that the communications are not secure, or the Ack message 439, 839 described above, indicating that the communications are secure.

[0187] If the further message indicates that communications between the host device and the peripheral device are not secure, the peripheral device stops communications with the host device. For example, the peripheral device could temporarily deactivate its transceiver, so that no further communications by the peripheral device are possible.

[0188] The method in Fig. 9 may be initiated by the peripheral device transmitting a connection request message to the host device. The connection request message may be the ConReq message 409 in Fig. 4, of the ConReq message 809 in Fig. 8. The connection request message may comprise an identifier for the peripheral device. The connection request message may also or alternatively comprise a classification index related to a processing capability of the peripheral device.

[0189] In particular embodiments, the connection instruction message received in step 901 further comprises a data element, for example a cryptographic key or a random seed. The peripheral device uses the data element to generate an interleaver, for example using an I DMA technique. The interleaver can be generated from a mother interleaver known to the peripheral device and the host device. The generated interleaver is used to encode the attack message or response message for transmission to the host device. In some cases, the interleaver is only generated if the time elapsed since the host transmission time does not satisfy the attack criterion.

[0190] In alternative embodiments, an event-specific interleaver is not used, and instead messages are interleaved using a standard or known interleaver.

[0191] Fig. 10 is a flow chart illustrating a method of operating a host device for establishing secure communications with a peripheral device according to various embodiments. The method by the host device in Fig. 10 can be performed in conjunction with the method by the peripheral device described above with reference to Fig. 9. The host device can be any of host device 301 , 401 , 701 and 801. The peripheral device can be any of peripheral device 303, 403, 703 and 803. The host device may perform the method in response to executing suitably formulated computer readable code. The computer readable code may be embodied or stored on a computer readable medium, such as a memory chip, optical disc, or other storage medium. The computer readable medium may be part of a computer program product.

[0192] In particular embodiments, the peripheral device is a key or key fob, and the host device is a vehicle.

[0193] In step 1001 , the host device transmits a connection instruction message to the peripheral device. The content of the connection instruction message is encrypted and indicates one or both of (i) a host transmission time relating to a timing of the transmission of the connection instruction message by the host device, and (ii) a peripheral response time relating to a timing of the transmission of a response to the connection instruction message by the peripheral device. The connection instruction message may be the Conlnst message 419 in Fig. 4 or the Conlnst message 819 in Fig. 8. In step 1003, the host device receives a message from the peripheral device. The content of the message may be encrypted.

[0194] In some embodiments of step 1003, the received message is one of (i) an attack report indicating that communications with the peripheral device are not secure; and (ii) a response message that continues the establishment of secure communications with the peripheral device.

[0195] The attack report can be the R-att report 423 in Fig. 4 or the R-att report 823 in Fig. 8. In some embodiments, after receiving the attack report, the host device can stop communications with the peripheral device. The response message can be the ConChk message 433 in Fig. 4 or the ConChk message 833 in Fig. 8.

[0196] In embodiments where the connection instruction message sent in step 1001 indicates a peripheral response time, the peripheral response time may have been determined by the host device. The peripheral response time can be determined based on an expected propagation time between the host device and the peripheral device, and / or a time required for the peripheral device to process the connection instruction message and transmit the message received in step 1003.

[0197] Optional steps 1005-1009 can typically be applied when the message received in step 1003 is the response message (e.g. ConChk message 433, 833), although it is possible to perform steps 1005-1009 if the received message is the attack report, in which case the host device is double checking or verifying that an attack is taking place.

[0198] In step 1005, the host device determines whether the time at which the message (response message or attack report) was received by the host device satisfies an attack criterion. The attack criterion provides a way to determine if the time elapsed shows evidence of an attack (e.g. a relay attack). Thus, the attack criterion can be based on a peripheral response time that relates to an expected amount of time taken for the peripheral device to receive the connection instruction message transmitted in step 1001 , determine the required response, and send the message that is received in step 1003.

[0199] Step 1005 generally corresponds to steps 435 and 835 in Figs. 4 and 8 respectively.

[0200] If the time at which the message was received by the host device satisfies the attack criterion (i.e. the time of receipt was later than expected according to the peripheral response time, indicating that an attack may be taking place), then in step 1007 the host device transmits a rejection message to the peripheral device indicating that communications with the host device are not secure. The rejection message can be the Nack 437, 837 in Figs. 4 and 8 respectively. In some embodiments, after sending the rejection message, the host device can stop communications with the peripheral device.

[0201] However, if the time at which the message was received by the host device does not satisfy the attack criterion (i.e. the time of receipt was within the times expected according to the peripheral response time, indicating that no attack appears to be taking place), then in step 1009 the host device transmits an acknowledgement message to the peripheral device to continue the establishment of secure communications with the peripheral device. The acknowledgement message can be the Ack 439, 839.

[0202] The establishment of secure communications with a peripheral device may further comprise a challenge-response procedure. In this case, the connection instruction message sent in step 1001 can comprise a challenge, and the peripheral device can determine a challenge response to the challenge. The message received in step 1003 can comprise the determined challenge response.

[0203] For the challenge-response procedure, the host device and the peripheral device may have a shared stored codebook that comprises a plurality of challenges and a corresponding plurality of challenge responses. In this case, the host device can check the validity of the received challenge response can be determined by looking up the challenge response in the codebook corresponding to the challenge.

[0204] As an alternative to having a stored codebook, the peripheral device may have determined the challenge response by generating the challenge response from the received challenge. The host device checks the validity of the challenge response.

[0205] The method in Fig. 10 may be initiated by the host device receiving a connection request message from the peripheral device. The connection request message may be the ConReq message 409 in Fig. 4, of the ConReq message 809 in Fig. 8. The connection request message may comprise an identifier for the peripheral device. The connection request message may also or alternatively comprise a classification index related to a processing capability of the peripheral device.

[0206] In particular embodiments, the connection instruction message sent in step 1001 further comprises a data element, for example a cryptographic key or a random seed. The peripheral device will use the data element to generate an interleaver, for example from a mother interleaver using an I DMA technique, and use the generated interleaver to encode the message that is received by the host device in step 1003. In some embodiments, the connection instruction message sent in step 1001 can be interleaved using the mother interleaver known to the host device and peripheral device.

[0207] The host device also uses the data element to generate the same interleaver as that generated by the peripheral device. Again, the interleaver can be generated using an I DMA technique, for example from the mother interleaver known to the peripheral device and the host device. The generated interleaver is used to decode the message received from the peripheral device in step 1003. If the host device is unable to successfully decode the received message using the generated interleaver, then it is possible that the incorrect interleaving has been used, and the host device can determine that an attack is taking place.

[0208] In alternative embodiments, an event-specific interleaver is not used, and instead messages are interleaved using a standard or known interleaver.

[0209] Fig. 11 is a flow chart illustrating another method of operating a peripheral device for establishing secure communications with a host device according to various embodiments. The peripheral device can be any of peripheral device 303, 403, 703 and 803. The host device can be any of host device 301 , 401 , 701 and 801 . The peripheral device may perform the method in response to executing suitably formulated computer readable code. The computer readable code may be embodied or stored on a computer readable medium, such as a memory chip, optical disc, or other storage medium. The computer readable medium may be part of a computer program product.

[0210] In particular embodiments, the peripheral device is a key or key fob, and the host device is a vehicle.

[0211] In step 1101 , the peripheral device receives a connection instruction message from the host device. The connection instruction message comprises a data element, for example a cryptographic key or a random seed. The connection instruction message (or the content thereof) may be encrypted.

[0212] In step 1103, the peripheral device uses the data element to generate an interleaver, for example using an I DMA technique. The interleaver can be generated from a mother interleaver known to the peripheral device and the host device.

[0213] In step 1105, the generated interleaver is used to encode a response message for transmission to the host device. The content of the response message may be encrypted.

[0214] In some embodiments, the content of the connection instruction message received in step 1101 may be comprise a peripheral response time relating to a timing of the transmission of the response message by the peripheral device. In this case, the peripheral device transmits the response message in step 1105 according to the peripheral response time (e.g. the peripheral device transmits the response message within the time limit provided for by the peripheral response time).

[0215] In addition or alternatively, the content of the connection instruction message received in step 1101 may be encrypted and indicate a host transmission time relating to a timing of the transmission of the connection instruction message by the host device. In this case, step 1103 can be performed if the time elapsed since the host transmission time does not satisfy an attack criterion. The attack criterion provides a way to determine if the time elapsed shows evidence of an attack, e.g. a relay attack. Thus, the attack criterion can be based on an expected propagation time between the host device and the peripheral device, with the attack criterion being satisfied (i.e. indicating an attack) if the time elapsed is too high / exceeds a threshold.

[0216] If the time elapsed since the host transmission time satisfies the attack criterion, then the response message transmitted by the peripheral device in step 1105 can be an attack report indicating that communications with the peripheral device are not secure. The attack report can be the R-att report 423 in Fig. 4 or the R-att report 823 in Fig. 8. In some embodiments, after sending the attack report, the peripheral device can stop communications with the host device (e.g. temporarily deactivate a transceiver of the peripheral device).

[0217] If the time elapsed since the host transmission time does not satisfy the attack criterion, then the response message sent by the peripheral device in step 1105 can be a response message that continues the establishment of secure communications with the host device.

[0218] The establishment of secure communications with a host device may further comprise a challenge-response procedure. In this case, the connection instruction message received in step 1101 can comprise a challenge, and the peripheral device can determine a challenge response to the challenge. The response message can comprise the determined challenge response. Thus, the response message can be the ConChk message 433 in Fig. 4 or the ConChk message 833 in Fig. 8. The content of the response message may be encrypted.

[0219] In cases where the attack criterion is evaluated, the challenge response may only be determined if the time elapsed since the host transmission time does not satisfy the attack criterion.

[0220] For the challenge-response procedure, the peripheral device may have a stored codebook that comprises a plurality of challenges and a corresponding plurality of challenge responses. In this case, the challenge response can be determined by looking up the challenge response in the codebook corresponding to the received challenge.

[0221] As an alternative to having a stored codebook, the peripheral device may determine the challenge response by generating the challenge response from the received challenge. For example, the challenge response can be determined by signing the challenge using a cryptographic key, generating the challenge response using a hash function, or generating the challenge response from a PUF.

[0222] After the response message is sent to the host device, the peripheral device may receive a further message from the host device. This further message indicates whether or not the communications between the host device and the peripheral device are secure. For example, this message can be the NACK message 437, 837 described above, indicating that the communications are not secure, or the ACK message 439, 839 described above, indicating that the communications are secure.

[0223] If the further message indicates that communications between the host device and the peripheral device are not secure, the peripheral device stops communications with the host device. For example, the peripheral device could (temporarily) deactivate its transceiver, so that no further communications by the peripheral device are possible.

[0224] The method in Fig. 11 may be initiated by the peripheral device transmitting a connection request message to the host device. The connection request message may be the ConReq message 409 in Fig. 4, of the ConReq message 809 in Fig. 8. The connection request message may comprise an identifier for the peripheral device. The connection request message may also or alternatively comprise a classification index related to a processing capability of the peripheral device.

[0225] Fig. 12 is a flow chart illustrating a method of operating a host device for establishing secure communications with a peripheral device according to various embodiments. The method by the host device in Fig. 12 can be performed in conjunction with the method by the peripheral device described above with reference to Fig. 11. The host device can be any of host device 301 , 401 , 701 and 801. The peripheral device can be any of peripheral device 303, 403, 703 and 803. The host device may perform the method in response to executing suitably formulated computer readable code. The computer readable code may be embodied or stored on a computer readable medium, such as a memory chip, optical disc, or other storage medium. The computer readable medium may be part of a computer program product.

[0226] In particular embodiments, the peripheral device is a key or key fob, and the host device is a vehicle.

[0227] In step 1201 , the host device sends a connection instruction message to the peripheral device. The connection instruction message comprises a data element, for example a cryptographic key or a random seed. The connection instruction message can be interleaved using a mother interleaver known to the peripheral device and the host device.

[0228] In step 1203, the host device generates an interleaver using the data element. The interleaver can be generated using an I DMA technique. The interleaver can be generated from the mother interleaver known to the peripheral device and the host device.

[0229] In step 1205, the host device receives a message from the peripheral device. The content of the received message may be encrypted.

[0230] In step 1207, the host device uses the generated interleaver to decode the message. If the host device is unable to successfully decode the received message using the generated interleaver, then it is possible that the incorrect interleaving has been used, and the host device can determine that an attack is taking place. Successful decoding of the received message using the generated interleaver can indicate to the host device that no attack is taking place.

[0231] In some embodiments of step 1205, the received message is one of (i) an attack report indicating that communications with the peripheral device are not secure; and (ii) a response message that continues the establishment of secure communications with the peripheral device.

[0232] The attack report can be the R-att report 423 in Fig. 4 or the R-att report 823 in Fig. 8. In some embodiments, after receiving an attack report, the host device can stop communications with the peripheral device. The response message can be the ConChk message 433 in Fig. 4 or the ConChk message 833 in Fig. 8.

[0233] In some embodiments, the content of the connection instruction message sent in step 1201 may be encrypted and comprise a peripheral response time relating to a timing of the transmission of the (response) message by the peripheral device. In this case, the peripheral device should transmit the response message to the host device according to the peripheral response time (e.g. the peripheral device transmits the response message within the time limit indicated by the peripheral response time).

[0234] The host device can determine whether the time at which the message (response message or attack report) was received by the host device satisfies an attack criterion. The attack criterion provides a way to determine if the time elapsed shows evidence of an attack (e.g. a relay attack). Thus, the attack criterion can be based on a peripheral response time that relates to an expected amount of time taken for the peripheral device to receive the connection instruction message transmitted in step 1201 , determine the required response, and send the message that is received in step 1205.

[0235] If the time at which the message was received by the host device satisfies the attack criterion (i.e. the time of receipt was later than expected according to the peripheral response time, indicating that an attack may be taking place), then the host device may transmit a rejection message to the peripheral device indicating that communications with the host device are not secure. The rejection message can be the NACK 437, 837 in Figs. 4 and 8 respectively. The rejection message can be interleaved using the interleaver generated in step 1203. In some embodiments, after sending the rejection message, the host device can stop communications with the peripheral device.

[0236] However, if the time at which the message received in step 1205 by the host device does not satisfy the attack criterion (i.e. the time of receipt was within the times expected according to the peripheral response time, indicating that no attack appears to be taking place), then the host device can transmit an acknowledgement message to the peripheral device to continue the establishment of secure communications with the peripheral device. The acknowledgement message can be the ACK 439, 839. The acknowledgement message can be interleaved using the interleaver generated in step 1203.

[0237] The content of the connection instruction message sent in step 1201 may be encrypted and indicate a host transmission time relating to a timing of the transmission of the connection instruction message by the host device.

[0238] The establishment of secure communications with the peripheral device may further comprise a challenge-response procedure. In this case, the connection instruction message sent in step 1201 can comprise a challenge, and the peripheral device can determine a challenge response to the challenge. The message received in step 1205 can comprise the determined challenge response.

[0239] For the challenge-response procedure, the host device and the peripheral device may have a shared stored codebook that comprises a plurality of challenges and a corresponding plurality of challenge responses. In this case, the host device can check the validity of the received challenge response can be determined by looking up the challenge response in the codebook corresponding to the challenge.

[0240] As an alternative to having a stored codebook, the peripheral device may have determined the challenge response by generating the challenge response from the received challenge. The host device checks the validity of the challenge response.

[0241] The method in Fig. 12 may be initiated by the host device receiving a connection request message from the peripheral device. The connection request message may be the ConReq message 409 in Fig. 4, of the ConReq message 809 in Fig. 8. The connection request message may comprise an identifier for the peripheral device. The connection request message may also or alternatively comprise a classification index related to a processing capability of the peripheral device. The connection request message may have been interleaved using the mother interleaver known to the peripheral device and the host device.

[0242] Fig. 13 is a simplified block diagram of an apparatus 1300 that can be used to implement, or implement part of, one or more of the host device and peripheral device described herein. The apparatus 1300 may be, or be a part of, a host device, such as a vehicle; a peripheral device, such as a key, key fob, smartphone, etc. In particular embodiments, the apparatus 1300 can be configured or adapted to perform the method shown in any of Figs. 9-12.

[0243] The apparatus 1300 comprises processing circuitry (or logic) 1301. It will be appreciated that the apparatus 1300 may comprise one or more virtual machines running different software and / or processes. The apparatus 1300 may therefore comprise, or be implemented in or as one or more servers, switches and / or storage devices and / or may comprise cloud computing infrastructure that runs the software and / or processes.

[0244] The processing circuitry 1301 controls the operation of the apparatus 1300 to implement any of the methods described herein. The processing circuitry 1301 can comprise one or more processors, processing units, multi-core processors or modules that are configured or programmed to control the apparatus 1300 in the manner described herein. In particular implementations, the processing circuitry 1301 can comprise a plurality of software and / or hardware modules that are each configured to perform, or are for performing, individual or multiple steps of the method described herein in relation to the apparatus 1300.

[0245] The apparatus 1300 also comprises a communications interface 1302. The communications interface 1302 is for use in enabling communications with other devices (i.e. a host device in the case where the apparatus 1300 is a peripheral device, or a peripheral device in the case where the apparatus 1300 is a host device). For example, the communications interface 1302 can be configured to transmit to and / or receive from other devices, requests, messages, acknowledgements, information, data, signals, or similar. The communications interface 1302 can use any suitable communication technology.

[0246] The processing circuitry 1301 may be configured to control the communications interface

[0247] 1302 to transmit to and / or receive from other devices requests, messages, acknowledgements, information, data, signals, or similar, according to the methods described herein.

[0248] The apparatus 1300 may comprise a memory 1303. In some embodiments, the memory

[0249] 1303 can be configured to store program code that can be executed by the processing circuitry 1301 to perform the methods described herein in relation to the apparatus 1300. Alternatively or in addition, the memory 1303 can be configured to store any requests, messages, acknowledgements, information, data, signals, or similar that are described herein. The processing circuitry 1301 may be configured to control the memory 1303 to store such information therein.

[0250] Although the computing devices described herein (e.g. host devices, peripheral devices) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in a device, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0251] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device- readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole.

[0252] The foregoing merely illustrates the principles of the disclosure. Various modifications and alterations to the described embodiments will be apparent to those skilled in the art in view of the teachings herein. It will thus be appreciated that those skilled in the art will be able to devise numerous systems, arrangements, and procedures that, although not explicitly shown or described herein, embody the principles of the disclosure and can be thus within the scope of the disclosure. Various exemplary embodiments can be used together with one another, as well as interchangeably therewith, as should be understood by those having ordinary skill in the art.

Claims

Claim1 . A method performed by a peripheral device for establishing secure communications with a host device, the method comprising: receiving (1101) a connection instruction message from the host device, wherein the connection instruction message comprises a data element; generating (1103) an interleaver using the data element; using (1105) the generated interleaver to encode a response message for transmission to the host device; and transmitting the encoded response message to the host device.

2. The method as claimed in claim 1 , wherein the step of generating (1103) comprises generating the interleaver using an Interleaver Division Multiple Access, I DMA, technique.

3. The method as claimed in claim 1 or 2, wherein the step of generating (1103) comprises generating the interleaver from a mother interleaver known to the peripheral device and host device.

4. The method as claimed in claim 3, wherein the method further comprises deinterleaving the received connection instruction message using the mother interleaver.

5. The method as claimed in any of claims 1-4, wherein the data element is a cryptographic key or a random seed.

6. The method as claimed in any of claims 1-5, wherein the content of the connection instruction message comprises a peripheral response time relating to a timing of the transmission of the response message by the peripheral device.

7. The method as claimed in claim 6, wherein the encoded response message is transmitted to the host device according to the peripheral response time.

8. The method as claimed in any of claims 1-7, wherein the content of the connection instruction message is encrypted and indicates a host transmission time relating to a timing of the transmission of the connection instruction message by the host device.

9. The method as claimed in claim 8, wherein the method further comprises: comparing (903) the host transmission time to a time at which the connection instruction message was received by the peripheral device; if the time elapsed since the host transmission time satisfies an attack criterion, the response message is an attack report to the host device indicating that communications with the peripheral device are not secure; and if the time elapsed since the host transmission time does not satisfy the attack criterion, the response message indicates to the host device to continue the establishment of secure communications with the peripheral device.

10. The method as claimed in claim 9, wherein the attack criterion is based on an expected propagation time between the host device and the peripheral device.

11. The method as claimed in claim 9 or 10, wherein if the attack report is transmitted to the host device, stopping communications with the host device.

12. The method as claimed in any of claims 1-11 , wherein the received connection instruction message further comprises a challenge, the method further comprises determining a challenge response to the challenge, and the response message comprises the determined challenge response.

13. The method as claimed in claim 12, wherein the peripheral device has a stored codebook that comprises a plurality of challenges and a corresponding plurality of challenge responses.

14. The method as claimed in claim 13, wherein the step of determining the challenge response comprises looking up the challenge response in the codebook corresponding to the challenge in the received connection instruction message.

15. The method as claimed in any of claims 12-14, wherein the step of determining the challenge response comprises generating the challenge response from the received challenge.

16. The method as claimed in any of claims 12-14, wherein the step of determining the challenge response comprises one of: signing the challenge using a cryptographic key, generating the challenge response using a hash function, generating the challenge response from a physically unclonable function, PUF.

17. The method as claimed in any of claims 1-16, wherein the content of the response message is encrypted.

18. The method as claimed in any of claims 1-17, wherein the method further comprises receiving a further message from the host device, wherein the further message indicates whether or not the communications between the host device and the peripheral device are secure.

19. The method as claimed in claim 18, wherein if the further message indicates that communications between the host device and the peripheral device are not secure, stopping communications with the host device.

20. The method as claimed in claim 18 or 19, wherein the method further comprises deinterleaving the received further message using the generated interleaver.21 . The method as claimed in any of claims 1-20, wherein the method further comprises: transmitting a connection request message to the host device to initiate the establishment of secure communications between the host device and the peripheral device.

22. The method as claimed in claim 21 , wherein the connection request message comprises an identifier for the peripheral device.

23. The method as claimed in claim 21 or 22, wherein the connection request message comprises a classification index related to a processing capability of the peripheral device.

24. The method as claimed in any of claims 1-23, wherein the peripheral device is a key or key fob, and the host device is a vehicle.

25. A method performed by a host device for establishing secure communications with a peripheral device, the method comprising: sending (1201) a connection instruction message to the peripheral device, wherein the connection instruction message comprises a data element; generating (1203) an interleaver using the data element; receiving (1205) a response message from the peripheral device; and using (1207) the generated interleaver to decode the response message.

26. The method as claimed in claim 25, wherein the step of generating (1203) comprises generating the interleaver using an Interleaver Division Multiple Access, I DMA, technique.

27. The method as claimed in claim 25 or 26, wherein the step of generating (1203) comprises generating the interleaver from a mother interleaver known to the peripheral device and host device.

28. The method as claimed in claim 27, wherein the method further comprises interleaving the connection instruction message using the mother interleaver.

29. The method as claimed in any of claims 25-28, wherein the data element is a cryptographic key or a random seed.

30. The method as claimed in any of claims 25-29, wherein if response message is successfully decoded using the generated interleaver, continuing the establishment of secure communications with the peripheral device; and if the response message is not successfully decoded using the generated interleaver, determining that communications with the peripheral device are not secure.

31. The method as claimed in any of claims 25-30, wherein the response message is one of: an attack report indicating that communications with the peripheral device are not secure, and a message indicating to the host device to continue the establishment of secure communications with the peripheral device.

32. The method as claimed in claim 31 , wherein if the response message is an attack report, stopping communications with the peripheral device.

33. The method as claimed in any of claims 25-32, wherein the content of the connection instruction message comprises a peripheral response time relating to a timing of the transmission of the response message by the peripheral device.

34. The method as claimed in claim 33, wherein the method further comprises: determining (1005) if a time at which the host device received the response message from the peripheral device satisfies an attack criterion based on the peripheral response time; andsending (1007; 1009) a further message to the peripheral device based on whether the time satisfies the attack criterion.

35. The method as claimed in claim 34, wherein: if the attack criterion is not satisfied, the further message is an acknowledgement message indicating the host device is to continue the establishment of secure communications with the peripheral device; and if the attack criterion is satisfied, the further message is a rejection message indicating that communications with the peripheral device are not secure.

36. The method as claimed in claim 34 or 35, wherein the method further comprises interleaving the further message using the generated interleaver.

37. The method as claimed in any of claims 25-36, wherein the content of the connection instruction message is encrypted and indicates a host transmission time relating to a timing of the transmission of the connection instruction message by the host device.

38. The method as claimed in claim 37, wherein the received response message indicates whether the connection instruction message was received by the peripheral device according to the host transmission time.

39. The method as claimed in any of claims 25-38, wherein the connection instruction message further comprises a challenge, and the received response message comprises a challenge response; and wherein the method further comprises: determining if the challenge response is valid.

40. The method as claimed in any of claims 25-39, wherein the content of the response message is encrypted.41 . The method as claimed in any of claims 25-40, wherein the connection instruction message is sent to the peripheral device in response to receiving a connection request message from the peripheral device that requests the establishment of secure communications between the host device and the peripheral device.

42. The method as claimed in claim 41 , wherein the connection request message comprises an identifier for the peripheral device.

43. The method as claimed in claim 41 or 42, wherein the connection request message comprises a classification index related to a processing capability of the peripheral device.

44. The method as claimed in any of claims 25-43, wherein the peripheral device is a key or key fob, and the host device is a vehicle.

45. A computer program product comprising a computer readable medium having computer readable code embodied therein, the computer readable code being configured such that, on execution by a suitable computer or processor, the computer or processor is caused to perform the method of any of claims 1-44.

46. A peripheral device configured to perform the method of any of claims 1-24.

47. A peripheral device, comprising a processor and a memory, said memory containing instructions executable by said processor whereby said peripheral device is operative to perform the method of any of claims 1-24.

48. A host device configured to perform the method of any of claims 25-44.

49. A host device comprising a processor and a memory, said memory containing instructions executable by said processor whereby said host device is operative to perform the method of any of claims 25-44.

Citation Information

Patent Citations

  • Protection against a relay attack

    US11023600B2

  • Passive keyless entry system

    US10486648B1

  • Electronic device and method for interleave division multiple access communication

    US11128393B2

  • Apparatus and method for in multiple access in wireless communication

    US20210297300A1

  • Storage device authenticating host credential and utilizing physically unclonable function (PUF) for data encryption / decryption

    WO2022259012A1