Relay attack detection methods

WO2026166624A1PCT designated stage Publication Date: 2026-08-13ASSA ABLOY AB
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2026-08-13

Smart Images

  • Figure EP2025053334_13082026_PF_FP_ABST
    Figure EP2025053334_13082026_PF_FP_ABST
Patent Text Reader

Abstract

An initiator device of an access control system includes protocol layer circuitry and processing circuitry operatively coupled to the protocol layer circuitry. The processing circuitry is configured to initiate transmitting a first command to a responder device; receive a first response to the first command from the responder device; initiate transmitting a second command to the responder device; determine a first time measurement from a beginning of receiving the first response to an end of sending the second command; receive a second time measurement from the responder device, wherein the second time measurement is measured from a beginning of sending the first response by the responder device to an end of receiving the second command from the initiator device; and generate an indication of a relay attack using the first time measurement and the second time measurement.
Need to check novelty before this filing date? Find Prior Art

Description

RELAY ATTACK DETECTION METHODSTECHNICAL FIELD

[0001] Embodiments illustrated and described herein generally relate to access control systems and to preventing security breaches in physical access control systems.BACKGROUND

[0002] Physical access control systems grant physical access to an authorized user through a controlled portal such as a secured door. Seamless access control refers to when physical access is granted to an authorized user through the controlled portal without requiring actions of the user such as swiping an access card at a card reader device or entering a person identification number (PIN) or password. Unfortunately, attempts to defeat systems that provide secure authentication often occur. A relay attack is a type of hacking technique that can lead to a security breach of a physical access control system.BRIEF DESCRIPTION OF THE DRAWINGS

[0003] FIG. 1 is an illustration of an example of a physical access control system structure.

[0004] FIG. 2 is a timing diagram representing an example of a command sent by an initiator device and received by a responder device.

[0005] FIG. 3 is a timing diagram representing an example of a relay attack involving a command sent by an initiator device and received by a responder device.

[0006] FIG. 4 is a flow diagram of an example of a method of inter-device wireless communication.

[0007] FIG. 5 is a timing diagram of an example of detecting a relay attack in interdevice wireless communication.

[0008] FIG. 6 is a diagram of a sequence of the two commands sent by an initiator device to a responder device.

[0009] FIG. 7 is a flow diagram of an example of a method of inter-device wireless communication.

[0010] FIG. 8 is a block diagram schematic of portions of an example of a verifier device.DETAILED DESCRIPTION

[0011] A physical access control system (PACS) provides automatic physical access to an authorized user through a physical access point such as a secured door. Seamless access control systems grant physical access to an authorized user through the controlled portal without requiring actions of the user such as entering or swiping an access card at a card reader or entering a personal identification number (PIN) or password. The architecture of a PACS may vary significantly based on the application (e.g., a hotel, a residence, an office, etc.), the technology (e.g., access interfaces technology, door type, etc.), and the manufacturer.

[0012] FIG. 1 is an illustration of a basic PACS structure useful for an office application. The Access Credential is a data object, a piece of knowledge (e.g., PIN, password, etc.), or a facet of the person’s physical being (e.g., face, fingerprint, etc.) that provides proof of the person’s identity. The Credential Device 104 stores the Access Credential when the Access Credential is a data object. The Credential Device 104 may be a smartcard or smartphone. Other examples of Credential Devices include, but are not limited to, proximity radio frequency identification based (RFID-based) cards, access control cards, credit cards, debit cards, passports, identification cards, key fobs, near field communication (NFC) enabled devices, mobile phones, personal digital assistants (PDAs), tags, or any other device configurable to emulate a virtual credential.

[0013] The Credential Device 104 can be referred to as the Access Credential. The Reader device 102 or other verifier device retrieves and authenticates the Access Credential when a Credential Device is used and sends the Access Credential to the Access Controller 106. The Access Controller 106 compares the Access Credential to an Access Control list and grants or denies access based on the comparison, such as by controlling an automatic lock 108 on a door for example.

[0014] The functionality of an Access Controller 106 may be included in the Reader device 102. These Reader devices can be referred to as offline readers or standalone readers. If the unlocking mechanism is included as well, a device is referred to as smart door lock which is more typically used in residential applications. Devices such as smart door locks are often battery powered, and power consumption and battery lifetime can be key parameters for the devices.

[0015] In a PACS, an access sequence consists of four parts: Proof of Presence, Intent Detection, Authentication, and Authorization. The user approaches the door and presentstheir access credential or credential device. This provides the Proof of Presence and Intent portions of the sequence. The reader device checks the validity of the access credential (the Authentication portion) and sends it to the access controller (e.g., using a local area network or LAN), which grants or denies access (the Authorization portion). As explained above, seamless access is access granted without actions to show Intent (e.g., presenting a card, entering a password etc.), while maintaining the same level of security as a conventional access system.

[0016] Physical access control systems are susceptible to attempts for unauthorized access such as hacking. A relay attack is a type of hacking technique related to man-in-the middle attacks. In a man-in-the-middle attack, communication between the Access Controller 106 (or Reader device 102) and a Credential Device 104 is initiated by the attacking device, and the attacking device merely relays messages between the two legitimate devices. The Credential Device 104 may be remote from the controlled physical portal, but the Access Controller 106 grants access as if the legitimate Credential Device 104 were present. This may allow access to the holder of the attacking device to the controlled portal.

[0017] FIG. 2 is a timing diagram representing a command sent by an initiator device and received by a responder device. The initiator device may be an interface terminal of a physical access control system (e.g., a Reader Device 102 of a PACS or another type of verifier device) and the responder device may be a Credential Device 104. The initiator device and the responder device each include protocol layer circuitry 118 and processing circuitry 116. The protocol layer circuitry 118 can include a medium access control (MAC) layer and a physical (PHY) layer. The initiator device transmits a command 210 to the responder device. The command 210 may be included in an authentication protocol communicated between the initiator device and the responder device. The command 210 may include multiple non-atomic blocks or frames of command data. In the example of FIG. 2, the command includes two blocks of non-atomic command data.

[0018] FIG. 2 shows a time delay or communication gap Tc between the time the start of the command 210 is sent by the initiator device until the command 210 begins to arrive at the responder device. The time of the communication gap Tc depends on the wired or wireless transmission protocol and on the related configuration parameters used by the initiator and responder for communication. A non-limiting example of a way to estimate the communication gap Tc is to calculate it as Tc = s / R, where is the size in bits of the firstatomic block of command data and R is the transmission throughput (e.g., in bits / second) of the transmission protocol.

[0019] When the command data arrives at the responder device, the protocol layer circuitry of the responder device recognizes the command 210 after receiving the first non-atomic block of command data (Block #1), which may include a command identifier for example. The time for the responder device to receive and recognize the first non-atomic block of command data is indicated as TR in the diagram.

[0020] FIG. 2 also shows the initiator response waiting time 214 during which the initiator device waits for a response from the responder device after transmitting the command 210. The timing diagram includes a command processing time 216 of the responder device during which the responder device processes the command received from the initiator device. The command processing time 216 depends on the hardware and firmware of the responder device.

[0021] After the command processing time 216 of the responder device, the responder device begins to transmit a response 212 to the command to the initiator device. In the example of FIG. 2, the response is a multi -block response that includes two non-atomic blocks of response data. There is also a second communication gap Tc between the time that the responder device starts to send the response 212 and the initiator device starts to receive and recognize the response data, assuming the number of bits and transmission throughput is symmetrical between the initiator device and the responder device in the protocol.

[0022] In the timing diagram of FIG. 2, time TA is the total time that the initiator device sees from the beginning of transmitting the command 210 to the end of receiving the response 212. In case the responder only recognizes the receipt of the command 210 once the first non-atomic block of command data has been received, time TB is the total time seen by the responder device from recognizing the command 210 to the end of transmitting the response 212 to the command. Because of the time delays in signaling, the initiator total time TA is greater than the responder total time TB. Without a relay attack the difference between TA and TB will be approximately 2Tc + TR, or TA - TB = 2Tc + TR. If the transmission throughput of the responder device is not the same as the transmission throughput of the initiator device, the communication gap may be different between directions from initiator to responder and responder to initiator. If the communication gaps are different, the time difference may be (Tci + Tc2 + TR), where Tci is the communication gap of the initiator device and Tc2 is the communication gap of the responder device. When there is a relayattack, there will be some non-zero time for the command and response to pass through the attacking device or devices. The additional devices will add communication gaps Tc to the transmitting and receiving of the command and response.

[0023] FIG. 3 is a timing diagram representing a relay attack on the device communication in the example of FIG. 2. The command 210 is sent by an initiator device, relayed by two attacking devices (ATTACKER 1, ATTACKER 2) in a relay attack, and then received by a responder device. The attacking devices add a communication gap Tc to the sending of the command 210 by the initiator device and the receiving of the command 210 by the responder device. There is also a communication gap TCA between the attacking devices. The communication gap TCA between the attacking devices may be less than the communication Tc. In a perfect relay attack, the attacking device or devices will be as efficient as possible. The communication between the attacking devices can be very efficient because the attacking devices can use any proprietary communication protocol. The communication gap TCA from the attacking devices is added to time of sending of the command 210 by the initiator device and to the time of receiving of the command 210 by the responder device.

[0024] The attacking devices also add the Tc and TCA communication gaps to the sending of the response 212 by the responder device and the receiving of the response 212 by the initiator device. The total time from when the initiator device starts to send the command to when the initiator device recognizes receiving the response 212 to the command isTA= TB + TR + 4(Tc) + 2(TCA). (1)

[0025] The difference in time between the normal communication and the relay attack communication is 2(Tc) + 2(TCA). If the communication time gaps are different between directions from initiator to responder and responder to initiator, the time difference may be (Tci + Tc?) + (TCAI + TCA2). If all the communication time gaps are all the same, the time difference is 4(Tc). The difference in communication times measured by the initiator device and the responder device can be used by one or both of the initiator device and the responder device to detect the relay attack. If the measured difference in time TA - TB is greater than a predetermined relay attack detection threshold, then there may be a relay attack. For example, the initiator or responder device may produce an indication of a relay attack when the measured difference between the initiator total time TA and the responder total time TB is greater than two times the communication gap Tc plus the TR time, or TA - TB > 2Tc + TR +AT, where AT is a specified tolerance time. The value of AT may depend on the values of Tc and TCA.

[0026] FIG. 4 is a flow diagram of an example of a method 400 of inter-device wireless communication to detect a relay attack. The example uses inter-device wireless communication between an initiator device and a responder device, but the method can be applied to any inter-device communication susceptible to a relay attack. The initiator device measures the time it takes to send a command and receive the response to the command. The responder device measures the time it takes to receive a command, process the command, and send the response to the initiator device. At block 405, the initiator device transmits a command to the responder device. The command may include one or more command blocks or command frames containing command data.

[0027] At block 410, the initiator device determines a first time duration, e.g., the initiator total time duration TA. The initiator device may measure the time duration TA from the beginning of sending the command to the responder device to the end of receiving a response to the command from the responder device and includes the response waiting time of the initiator device. For instance, the initiator device may start a timer at the beginning of sending the command 210 in FIG. 3 and stop the timer when it recognizes the end of the response 212. The command may be a multi-block command as in FIG. 3, and the response may be a multi-block response, and the initiator device stops the timer once the last response block is received and recognized by the initiator device. In variations, the initiator device may stop the timer when the first non-atomic block of response data is recognized by the initiator device.

[0028] At block 415, the responder device determines a second time duration, e.g., the responder total time duration TB. The responder device may measure the time duration TB from the detection of receipt of the command to the end of sending the response to the command. For instance, the responder device may start a timer at the end of receiving the first block of the command 210 in FIG. 3 and stop the timer at the end of sending the response 212. In variations, the responder device may stop its timer at the end of the first non-atomic block of response data (or another point in the response) to match the measuring of the response by the initiator device. The time measurement of the responder device may exclude the time used to receive the first non-atomic command block (e.g., TR). The responder device may only be able to recognize the type of command and begin its time measurement once the first block of command data is received. For instance, the responderdevice may need to receive and decode a whole data link layer exchange block in order to start a time measurement. The responder device recognizes when the transmission of the response 212 ends and stops its timer.

[0029] At block 420, an indication of a relay attack is generated when the difference between the first time duration and the second time duration (e.g., TA-TB) is greater than a specified relay attack detection time threshold (e.g., TA - TB > 2Tc + TR + AT). The indication of relay attack may be a signal sent to alarm circuitry of the initiator device or alarm circuitry of a separate device (e.g., an access controller 106 in FIG. 1). In variations, the indication may be a predetermined message transmitted from the detecting device to the separate device.

[0030] Either device may determine the difference between the time durations and use the difference to detect a relay attack. In some examples, the initiator device detects the relay attack. The initiator device sends a second command to the responder device for the responder device to send its time measurement to the initiator device. In variations, the responder device sends its time measurement back to the initiator device without the initiator device having to send the command. The initiator device computes the difference between its time measurement and the responder device’s time measurement and generates the indication of the relay attack when the computed time difference is greater than the specified relay attack detection time threshold.

[0031] In some examples, the responder device detects the relay attack. After receiving the response to the command, the initiator device sends its time measurement to the responder device. The responder device computes the difference between its time measurement and the initiator device’s time measurement and generates the indication of the relay attack when the computed time difference is greater than the specified relay attack detection time threshold.

[0032] FIG. 5 is a timing diagram of another example of detecting a relay attack on the communication between an initiator device and a responder device. In the approach of FIG. 5, the responder device measures the time taken to transmit a response 512 to a first command and receive a subsequent second command 520 from the initiator device. The total responder time TB in FIG. 5 includes the response transmission time, the command waiting time 522, and the command receiving time. The initiator device measures the time from receiving the response 512 to the first command to the end of sending the second command 520. The total initiator time TA in FIG. 5 includes the response receiving time, the responseprocessing time 524, and the transmission time of the second command 520 by the initiator device. In the example of FIG. 5, the total responder time TB is greater than the total initiator time TA (or TB > TA). FIG. 6 is a diagram of the sequence of the two commands (510, 520) sent by the initiator device to the responder device, and the total initiator time TA from the response 512 to the second command 520.

[0033] The attacking devices add the Tc and TCA communication gaps to the sending of the response 512 by the responder device and the receiving of the response 512 by the initiator device. The attacking devices also add the Tc and TCA communication gaps to the sending of the second command 520 by the initiator device and the receiving of the second command 520 by the responder device.

[0034] The total time from when the responder device starts to send the response 512 to the initiator device to when the responder device recognizes receiving the second command isTB = TA+ 4(TC) + 2(TCA). (2)

[0035] The difference in time between the normal communication and the relay attack communication is 2(Tc) + 2(TCA). AS in the example of FIG. 3, if the communication time gaps are different between directions from initiator to responder and responder to initiator, the time difference may be (Tci + Tc?) + (TCAI + TCA?), and if all the communication time gaps are all the same, the time difference is 4(Tc).

[0036] The difference in communication times measured by the initiator device and the responder device can be used by one or both of the initiator device and the responder device to detect the relay attack. If the measured difference in time TB - TA is greater than a predetermined relay attack detection threshold, then there may be a relay attack. For example, the initiator or responder device may produce an indication of a relay attack when the measured difference between the responder total time TB and the initiator total time TA is greater than two times the communication gap Tc, or TB - TA > 2Tc + AT, where AT is a specified tolerance time. An advantage over the detection method of FIG. 3 is that the responder device is able to recognize the end of the receipt of the second command time 520 even if the responder device is only able to recognize the receipt of the second command once a whole non-atomic block of command data has been received. Thus, the estimate of the time TR taken to receive the first non-atomic block of command data is not needed.

[0037] FIG. 7 is a flow diagram of an example of a method 700 of inter-device wireless communication to detect a relay attack. As in the example of FIG. 4, the example ofFIG. 7 uses inter-device wireless communication between an initiator device and a responder device, but the method can be applied to any inter-device communication susceptible to a relay attack. The initiator device and the responder device measure the time it takes the responder device to transmit a response to a command from the initiator device, and the initiator device to process the response and transmit the next command.

[0038] At block 705, a first command is transmitted from the initiator device to the responder device (e.g., command 510 in FIG. 6). The first command may include one or more command blocks containing command data. At block 710, the responder device transmits a response to the command (e.g., response 512 in FIG. 6). The response to the first command may include one or more blocks of response data. The responder device begins measuring a time duration from the start of sending the response 512. Because the responder device knows when it begins sending the response, beginning the timing measurement by the responder device does not depend on a time of the responder device recognizing a block of non-atomic data of the first command. The initiator device is waiting for the response to the first command and begins measuring a time duration starting at receiving the response to the first command.

[0039] At block 715, the initiator device transmits a second command to the responder device. At block 720, the initiator device measures the time duration from the beginning of receiving the response to the end of transmitting the second command. This time duration is the total initiator time TA that includes the response receiving time, the response processing time of the initiator device, and the transmission time of the subsequent second command.

[0040] At block 725, the responder device measures the time duration from the beginning of sending the response to the end of receiving the second command. This time duration is the total responder time TB that includes the time to transmit the response 512, the waiting time 522 of waiting for the second command, and the time to receive the second command 520. The responder device stops measuring the time duration TB when the responder device recognizes the end of the second command 520. The responder device will recognize the end of the receipt of the command even if the responder device needs to recognize the receipt of a whole non-atomic block of command data to recognize the receipt of a command. The protocol layer circuitry and processing circuitry of the responder device will continue the in-process timing measurement for TB while waiting for the second command and does not time out to another mode (e.g., a sleep mode) while waiting. In someexamples, the processing circuitry of the responder device continues to measure the time duration TB even if a timing measurement overflow occurs in the responder device during the measurement. For instance, the processing circuitry of the responder device securely handles an interrupt raised by an underlying platform in the event of a timing measurement overflow of the time used to measure TB.

[0041] At block 730, an indication of a relay attack is generated using the measured time durations. Either the initiator device or the responder device can generate the indication of the relay attack. For instance, the responder device may send the measured time duration TB to the initiator device. The responder device may include the measured time duration TB in a response to the second command or send the measured time duration TB in response to a third command from the initiator device. The processing circuitry of the initiator device computes the time difference between the measured time duration TB and the measured time duration TA, and compares the computed time difference to a specified relay attack detection time threshold. The initiator device generates the indication of the relay attack when the computed time difference is greater than the relay attack detection time gap (e.g., greater than 2TC+ AT).

[0042] Alternatively, the initiator device may send the measured time duration TA to the responder device. The initiator device may send the measured time duration TA in a third message or third command. The processing circuitry of the responder device computes the time difference TB - TA and compares the computed time difference to the specified relay attack detection time threshold. The responder device generates the indication of the relay attack when the computed time difference is greater than the relay attack detection time gap.

[0043] The systems, devices, and methods described herein may provide a reliable way to detect a relay attack between two devices. Timing measurements for the attack detection are determined and may be shared between the initiator device and the responder device. Either of the device or both devices may produce an alert of a relay attack.

[0044] FIG. 8 is a block diagram schematic of various example components of a device 800 (e.g., an embedded device) for supporting the device architectures described and illustrated herein. The device 800 of FIG. 8 could be, for example, a verifier or reader device that authenticates credential information of authority, status, rights, and / or entitlement to privileges for the holder of a credential device. At a basic level, a reader device can include an interface (e.g., one or more antennas and Integrated Circuit (IC) chip(s)), which permit the reader device to exchange data with another device, such as a credential device or anotherverifier device. One example of credential device is an RFID smartcard that has data stored thereon allowing a holder of the credential device to access a secure area or asset protected by the reader device.

[0045] With reference specifically to FIG. 8, additional examples of a device 800 for supporting the device architecture described and illustrated herein may generally include one or more of a memory 802, a processor 804, one or more antennas 806, a communication port or communication module 808, a network interface device 810, a user interface 812, and a power source 814 or power supply.

[0046] Memory 802 can be used in connection with the execution of application programming or instructions by processing circuitry, and for the temporary or long-term storage of program instructions or instruction sets 816 and / or authorization data 818, such as credential data, credential authorization data, or access control data or instructions, as well as any data, data structures, and / or computer-executable instructions needed or desired to support the above-described device architecture. For example, memory 802 can contain executable instructions 816 that are used by a processor 804 of the processing circuitry to run other components of device 800, to make access determinations based on credential or authorization data 818, and / or to perform any of the functions or operations described herein, such as the method of FIG. 4 for example. Memory 802 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with device 800. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer-readable media.

[0047] Processor 804 can correspond to one or more computer processing devices or resources. For instance, processor 804 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type ofIntegrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 804 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory 820 and / or memory 802. Device 800 may include a timer component 828 to perform timing measurements. The timer component 828 may be integral to the processor 804 or separate from the processor 804.

[0048] Antenna 806 can correspond to one or multiple antennas and can be configured to provide for wireless communications between device 800 and another device. Antenna(s) 806 can be coupled to one or more physical (PHY) layers 824 to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. Processor 804 may implement a MAC layer that forms a protocol layer with a physical layer 824. In an example, antenna 806 may include one or more antennas coupled to one or more physical layers 824 to operate using ultra-wide band (UWB) for in band activity / communi cation and Bluetooth (e.g., BLE) for out-of-band (OOB) activity / communi cation. However, any RFID or personal area network (PAN) technologies, such as the IEEE 502.15.1, near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, etc., may alternatively or additionally be used for the OOB activity / communi cation described herein.

[0049] Device 800 may additionally include a communication module 808 and / or network interface device 810. Communication module 808 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to device 800. Network interface device 810 includes hardware to facilitate communications with other devices over a communication network utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 802.11 family of standards known as Wi-Fi, IEEE 802.16 family of standards known as WiMax, IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others). In some examples, network interface device 810 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), acellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 810 can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques. In some example embodiments, one or more of the antennas 806, communication module 808, and / or network interface device 810 or subcomponents thereof, may be integrated as a single module or device, function or operate as if they were a single module or device, or may comprise of elements that are shared between them.

[0050] User interface 812 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in user interface 812 include, without limitation, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, etc. Examples of suitable user output devices that can be included in user interface 812 include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, etc. It should be appreciated that user interface 812 can also include a combined user input and user output device, such as a touch-sensitive display or the like. The user interface 812 may include a separate alarm circuit 826 to indicate an alarm condition such as a relay attack or other security breach. Alarm circuit 826 may provide an audio signal to a speaker or may activate a light or present an alarm condition using a display device.

[0051] Power source 814 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., and / or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally supplied AC power into DC power) for components of the device 800.

[0052] Device 800 can also include one or more interlinks or buses 822 operable to transmit communications between the various hardware components of the device. A system bus 822 can be any of several types of commercially available bus structures or bus architectures.ADDITIONAL DISCLOSURE AND EXAMPLES

[0053] Example 1 includes subject matter (such as a method of inter-device wireless communication) comprising transmitting a first command from an initiator device to a responder device; transmitting a response from the responder device to the initiator device;transmitting a second command from the initiator device to the responder device; determining, using the initiator device, a first time duration from a beginning of receiving the response to an end of sending the second command; determining, using the responder device, a second time duration from a beginning of sending the response to an end of receiving the second command; and generating an indication of a relay attack using the first time duration and the second time duration.

[0054] In Example 2, the subject matter of Example 1 optionally includes sending, by the initiator device, the first time duration to the responder device; computing, by the responder device, a time difference between the first time duration and the second time duration; comparing the computed time difference to a specified relay attack detection time threshold; and generating, by the responder device, the indication of the relay attack when the computed time difference is greater than the specified relay attack detection time threshold.

[0055] In Example 3, the subject matter of Example 2, optionally includes the initiator device sending the first time duration to the responder device in a third command.

[0056] In Example 4, the subject matter of one or any combination of Examples 1-3 optionally includes sending, by the responder device, the second time duration to the initiator device; computing, by the initiator device, a time difference between the first time duration and the second time duration; comparing the computed time difference to a specified relay attack detection time threshold; and generating, by the initiator device, the indication of the relay attack when the computed time difference is greater than the specified relay attack detection time threshold.

[0057] In Example 5, the subject matter of Example 4 optionally includes the responder device sending the second time duration to the initiator device in response to the second command.

[0058] In Example 6, the subject matter of one or any combination of Examples 1-5 optionally includes determining the second duration time to include a response transmitting time, a second command receiving time, and a command waiting time from after the sending of the response to the beginning of receiving the second command.

[0059] In Example 7, the subject matter of one or any combination of Examples 1-6 optionally includes the initiator device being a reader device of an access control system and the responder device is a smart card.

[0060] In Example 8, the subject matter of one or any combination of Examples 1-7 optionally includes the initiator device being a verifier device of an access control system and the responder device is a smart phone.

[0061] Example 9 includes subject matter (such as an initiator device) or can optionally be combined with one or any combination of Examples 1-8 to include such subject matter, comprising protocol layer circuitry configured to communicate information wirelessly with a responder device, and processing circuitry operatively coupled to the protocol layer circuitry. The processing circuitry is configured to initiate transmitting a first command to a responder device; receive a first response to the first command from the responder device; initiate transmitting a second command to the responder device; determine a first time measurement from a beginning of receiving the first response to an end of sending the second command; receive a second time measurement from the responder device, wherein the second time measurement is measured from a beginning of sending the first response by the responder device to an end of receiving the second command from the initiator device; and generate an indication of a relay attack using the first time measurement and the second time measurement.

[0062] In Example 10, the subject matter of Example 9 optionally includes processing circuitry configured to compute a time difference between the second time measurement and the first time measurement; compare the computed time difference to a specified relay attack detection time threshold; and generate the indication when the computed time difference is greater than the specified relay attack detection time threshold.

[0063] In Example 11, the subject matter of one or both of Examples 9 and 10 optionally includes processing circuitry configured to compute the first time measurement to include a time of receiving the first response, a time of processing the first response by the initiator device, and a time of transmitting the second command.

[0064] In Example 12, the subject matter of one or any combination of Examples 9- 11 optionally includes the initiator device being a verifier device of access control system and the processing circuitry is configured to authenticate credential information received from the responder device.

[0065] Example 13 includes subject matter (such as a method of inter-device wireless communication) or can optionally be combined with one or any combination of Examples 1- 12 to include such subject matter, comprising transmitting a command from an initiator device to a responder device, wherein the command includes one or more command blocks ofdata; determining, using the initiator device, a first time duration from a beginning of sending the command to the responder device to an end of receiving a response to the command from the responder device; determining, using the responder device, a second time duration from an end of receiving a first command block of the command by the responder to an end of sending the response to the command; and generating an indication of a relay attack when a difference between the first time duration and the second time duration is greater than a specified relay attack detection time threshold.

[0066] In Example 14, the subject matter of Example 13 optionally includes the specified relay attack detection time threshold including a time for the responder device to receive the first command block of the command.

[0067] In Example 15, the subject matter of one or both of Examples 13 and 14 optionally includes sending, by the initiator device, the first time duration to the responder device; computing, by the responder device, the time difference between the first time duration and the second time duration; and generating, by the responder device, the indication of the relay attack when the computed time difference is greater than the specified relay attack detection time threshold.

[0068] In Example 16, the subject matter of one or any combination of Examples 13-15 optionally includes sending, by the responder device, the second time duration to the initiator device; computing, by the initiator device, the time difference between the first time duration and the second time duration; and generating, by the initiator device, the indication of the relay attack when the computed time difference is greater than the specified relay attack detection time threshold.

[0069] In Example 17, the subject matter of Example 16 optionally includes sending, by the responder device, the second duration time in a response to a second command received from the initiator device.

[0070] In Example 18, the subject matter of one or nay combination of Examples 13- 17 optionally includes determining the second duration time to include a time to receive the command excluding a time to receive the first command block, a command processing time of the responder device, and a time to send a response to the command.

[0071] In Example 19, the subject matter of one or nay combination of Examples 13- 18 optionally includes determining the first duration time to include a transmitting time of all command blocks of the command by the initiator device, a response waiting time of the initiator device, and a receiving time of the response by the initiator device.

[0072] In Example 20, the subject matter of one or any combination of Examples 13- 19 optionally includes the initiator device being a reader device and the responder device being a smart card.

[0073] In Example 21, the subject matter of one or any combination of Examples 13- 20 optionally includes the initiator device being a verifier device of an access control system and the responder device being a smart phone.

[0074] These non-limiting Examples can be combined in any permutation or combination. The above detailed description includes references to the accompanying drawings, which form a part of the detailed description. The drawings show, by way of illustration, specific embodiments in which the invention can be practiced. The above description is intended to be illustrative, and not restrictive. For example, the abovedescribed examples (or one or more aspects thereof) may be used in combination with each other. Other embodiments can be used, such as by one of ordinary skill in the art upon reviewing the above description. The Abstract is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In the above Detailed Description, various features may be grouped together to streamline the disclosure. This should not be interpreted as intending that an unclaimed disclosed feature is essential to any claim. Rather, the subject matter may lie in less than all features of a particular disclosed embodiment. Thus, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate embodiment, and it is contemplated that such embodiments can be combined with each other in various combinations or permutations. The scope should be determined with reference to the appended claims, along with the full scope of equivalents to which such claims are entitled.

Claims

WHAT IS CLAIMED IS:

1. A method of inter-device wireless communication, the method comprising:transmitting a first command from an initiator device to a responder device; transmitting a response from the responder device to the initiator device; transmitting a second command from the initiator device to the responder device; determining, using the initiator device, a first time duration from a beginning of receiving the response to an end of sending the second command;determining, using the responder device, a second time duration from a beginning of sending the response to an end of receiving the second command; andgenerating an indication of a relay attack using the first time duration and the second time duration.

2. The method of claim 1, wherein the generating the indication of the relay attack includes:sending, by the initiator device, the first time duration to the responder device; computing, by the responder device, a time difference between the first time duration and the second time duration;comparing the computed time difference to a specified relay attack detection time threshold; andgenerating, by the responder device, the indication of the relay attack when the computed time difference is greater than the specified relay attack detection time threshold.

3. The method of claim 2, including the initiator device sending the first time duration to the responder device in a third command.

4. The method of claim 1, wherein the generating the indication of the relay attack includes:sending, by the responder device, the second time duration to the initiator device; computing, by the initiator device, a time difference between the first time duration and the second time duration;comparing the computed time difference to a specified relay attack detection time threshold; andgenerating, by the initiator device, the indication of the relay attack when the computed time difference is greater than the specified relay attack detection time threshold.

5. The method of claim 4, including the responder device sending the second time duration to the initiator device in response to the second command.

6. The method of claim 1, wherein the determining the second duration time includes determining the second duration time to include a response transmitting time, a second command receiving time, and a command waiting time from after the sending of the response to the beginning of receiving the second command.

7. The method of claim 1, wherein the initiator device is a reader device of an access control system and the responder device is a smart card.

8. The method of claim 1, wherein the initiator device is a verifier device of an access control system and the responder device is a smart phone.

9. An initiator device comprising:protocol layer circuitry configured to communicate information wirelessly with a responder device; andprocessing circuitry operatively coupled to the protocol layer circuitry and configured to:initiate transmitting a first command to a responder device;receive a first response to the first command from the responder device;initiate transmitting a second command to the responder device;determine a first time measurement from a beginning of receiving the first response to an end of sending the second command;receive a second time measurement from the responder device, wherein the second time measurement is measured from a beginning of sending the first response by the responder device to an end of receiving the second command from the initiator device; and generate an indication of a relay attack using the first time measurement and the second time measurement.

10. The initiator device of claim 9, wherein the processing circuitry is configured to: compute a time difference between the second time measurement and the first time measurement;compare the computed time difference to a specified relay attack detection time threshold; andgenerate the indication when the computed time difference is greater than the specified relay attack detection time threshold.

11. The initiator device of claim 9, wherein the processing circuitry is configured to compute the first time measurement to include a time of receiving the first response, a time of processing the first response by the initiator device, and a time of transmitting the second command.

12. The initiator device of claim 9, wherein the initiator device is a verifier device of access control system and the processing circuitry is configured to authenticate credential information received from the responder device.

13. A method of inter-device wireless communication, the method comprising:transmitting a command from an initiator device to a responder device, wherein the command includes one or more command blocks of data;determining, using the initiator device, a first time duration from a beginning of sending the command to the responder device to an end of receiving a response to the command from the responder device;determining, using the responder device, a second time duration from an end of receiving a first command block of the command by the responder to an end of sending the response to the command; andgenerating an indication of a relay attack when a difference between the first time duration and the second time duration is greater than a specified relay attack detection time threshold.

14. The method of claim 13, wherein the specified relay attack detection time threshold includes a time for the responder device to receive the first command block of the command.

15. The method of claim 13, wherein the generating the indication of the relay attack includes:sending, by the initiator device, the first time duration to the responder device; computing, by the responder device, the time difference between the first time duration and the second time duration; andgenerating, by the responder device, the indication of the relay attack when the computed time difference is greater than the specified relay attack detection time threshold.

16. The method of claim 13, wherein the generating the indication of the relay attack includes:sending, by the responder device, the second time duration to the initiator device; computing, by the initiator device, the time difference between the first time duration and the second time duration; andgenerating, by the initiator device, the indication of the relay attack when the computed time difference is greater than the specified relay attack detection time threshold.

17. The method of claim 16, including:sending, by the responder device, the second duration time in a response to a second command received from the initiator device.

18. The method of claim 13, wherein the determining the second time duration includes determining the second duration time to include a time to receive the command excluding a time to receive the first command block, a command processing time of the responder device, and a time to send a response to the command.

19. The method of claim 13, wherein the determining the first time duration includes determining the first duration time to include a transmitting time of all command blocks of the command by the initiator device, a response waiting time of the initiator device, and a receiving time of the response by the initiator device.

20. The method of claim 13, wherein the initiator device is a reader device and the responder device is a smart card.2121. The method of claim 13, wherein the initiator device is a verifier device of an access control system and the responder device is a smart phone.22