Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

50 results about "Relay attack" patented technology

A relay attack in computer security is a type of hacking technique related to man-in-the-middle and replay attacks. In a classic man-in-the-middle attack, an attacker intercepts and manipulates communications between two parties initiated by one of the parties. In a classic relay attack, communication with both parties is initiated by the attacker who then merely relays messages between the two parties without manipulating them or even necessarily reading them.

Vehicle door unlocking method and system and vehicle

The invention discloses a vehicle door unlocking method and system and a vehicle, which are characterized in that on the basis of a Bluetooth digital key or an NFC (Near Field Communication) digital key, selectable enhanced safety function verification is added. When safety function enhancement verification is selected, potential safety hazards such as relay attacks and replay attacks can be resisted, and the safety of vehicle door unlocking can be improved; and when the safety function enhancement verification is not selected, the vehicle door can be unlocked as long as the preliminary unlocking authentication is successful, so that the vehicle door unlocking convenience can be improved. The user can decide whether to start the enhanced security function verification according to the actual demand and the application scene, so that the unlocking security and the unlocking convenience are better balanced, and the application scene is expanded.
Owner:CHINA CHANGAN AUTOMOBILE GROUP CO LTD SHANGHAI CHIDU INTELLIGENT CONTROL TECHNOLOGY BRANCH +2

System and method for securing vehicles from relay attacks using map database

An approach is provided for securing vehicles from relay attacks using map database. The approach, for example, involves determining a first location of a vehicle and a first location of a user associated with the vehicle. The approach further involves determining, using a map database, at least one signal dead zone within a first pre-determined distance from the first location of the vehicle. A distance between the first location of the user associated with the vehicle and the first location of the vehicle exceeds the first pre-determined distance. The approach further involves generating a validation output in response to the first location of the user associated with the vehicle exceeding the first pre-determined distance from the first location of the vehicle.
Owner:HERE GLOBAL BV

System and the like

To provide a system and the like which can reduce risks of theft or the like by relay attack in a vehicle or the like which already mounts a smart entry system or the like.SOLUTION: A vehicle system which is provided with a function to perform smart operation to be at least operation of either unlock or engine start of a vehicle on the basis of a response signal from a smart key with respect to a request signal transmitted to the smart key from the vehicle, a system is retrofitted. The system is provided with at least either a function to prohibit the smart operation in the vehicle system or a function to notify when a part of the smart operation is performed.SELECTED DRAWING: Figure 1
Owner:YUPITERU CORP

A bluetooth channel sounding high-precision ranging soc method, chip and device

PendingCN122661684AFrequency counterTerm memory
The application discloses a Bluetooth channel sounding high-precision ranging SOC method, a chip and equipment. The method comprises the following steps: controlling a radio frequency transceiver front end to output a data frame and a received signal strength quantization value, a direct memory access controller carries the data frame to a memory of a channel sounding coprocessor, the coprocessor compares the quantization value with a multipath deep fading threshold value, and when the quantization value is lower than the threshold value, corresponding data is overwritten as a digital zero, a polar coordinate system conversion forms a frequency domain channel response array, an inverse fast Fourier transform is performed to extract a line-of-sight path main peak and calculate a first distance value, a high-frequency counter records a physical round trip time and converts a second distance value, a hardware interlocking comparator calculates a difference value, and when the difference value exceeds a safety tolerance window, a blocking instruction is sent to the direct memory access controller. The application can solve the data distortion problem in a multipath environment and eliminate the delay vulnerability of the anti-relay attack of the physical layer.
Owner:ZITAI MICROELECTRONICS (SHANGHAI) CO LTD

Mobile device relay attack detection and power management for vehicles

The present disclosure provides "Mobile device relay attack detection and power management for vehicles." A method and apparatus for mobile device relay attack detection and power management for vehicles is disclosed. An example vehicle includes a first module for first protocol communication, a second module for second protocol communication, and a controller. The controller is to determine a first distance to a mobile device using a signal strength of the first protocol communication, and upon receiving an entry request, determine a second distance to the mobile device using a time of flight of the second protocol communication. The controller is also to prevent entry when the second distance does not match the first distance.
Owner:FORD GLOBAL TECH LLC

Methods, systems, and computer-readable media for mitigating unauthorized message relay attacks

The present invention relates to methods, systems, and computer readable media for mitigating unauthorized message relay attacks. According to one method, the method is performed at a network node configured to relay network message information or derivative information to avoid resource contention between user equipments (UEs). The method includes receiving a first temporary UE identifier (TUEI) associated with a first UE for requesting radio resources within a serving cell; allocating the radio resources to the first UE using the first TUEI; generating a second value based on the first TUEI using at least a conversion algorithm, wherein the second value has a higher entropy characteristic than the first TUEI, thereby reducing a likelihood that the second value includes an encoded message that can be decoded by a second UE when relayed by the network node; and broadcasting a message including the second value to a plurality of UEs including the second UE.
Owner:KEYSIGHT TECHNOLOGIES INC

Anti-theft devices for automobiles

The article to which this design relates is a device to prevent automobile theft by relay attacks, etc., and is carried along with an electronic key. This article uses UWB (ultra-wideband) radio waves to perform ranging communication with the electronic control system installed in the automobile. If the results of the ranging communication are normal, the electronic control system will allow the door locks to operate.
Owner:KK TOKAI RIKA DENKI SEISAKUSHO +1

Systems and methods for secure RFID / NFC communications

Systems and methods for enabling secure RFID / NFC communications and thwarting relay attacks are described. A device that includes an RFID or NFC tag (such as a credit card with an NFC tag or a key fob with an RFID tag) includes a sensor system configured to detect, in response to the device receiving a request for information from a tag reader, one or more physical inputs. For example, the sensor system may include a photoresistor that detects light around the device, the presence of which indicates that the device is probably not in the user's wallet or pocket (and therefore probably is not experiencing a relay attack). When the device determines that the sensor output satisfies one or more criteria (such as when sensor system detects light around the device), the device transmits the information to the tag reader; otherwise the device does not transmit the information.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC

Relay attack mitigation techniques

Methods and systems for communicating with an access control system are provided. The methods and systems receive, by a first device, a request to establish a connection with a second device to obtain access to a resource protected by the first device, the connection being secured at an application layer by a first set of encryption keys. The methods and systems determine whether a physical link layer (LL) pairing between the first device and the second device is successful, the LL pairing being based on a second set of encryption keys that are separate from the first set of encryption keys. The methods and systems selectively process access control information in response to determining whether the physical LL pairing between the first device and the second device is successful.
Owner:ASSA ABLOY AB

Anti-theft devices for automobiles

The article of this design is a device for preventing automobile theft by relay attacks, etc., and is installed on the column cover of an automobile. If a user installs an electronic control system using UWB (ultra-wideband) radio waves in their automobile, and the battery of the ranging communication mobile device that communicates with the electronic control system runs out, ranging authentication is not established, and the doors and engine are not allowed to operate. In this case, the user unlocks the doors using a physical key. Then, by holding the ranging communication mobile device over the article, ranging authentication is established and the engine is allowed to operate. Furthermore, when the automobile's anti-theft system is activated, the indicator of the article flashes to indicate that the anti-theft system is activated. The article consists of a case, an indicator, and a lid. As shown in Reference Figure 1, which shows the usage state, the case is installed inside the mounting surface (column cover, etc.), and the tip of the indicator and the lid are exposed outside the mounting surface. Reference Figures 2 and 3, which show the usage state, respectively show examples of the installation state when the thickness of the installation surface is thicker and thinner than that of Reference Figure 1, which shows the usage state, and the positional relationship between the lid part and the indicator part is adjusted according to the thickness of the installation surface.
Owner:KK TOKAI RIKA DENKI SEISAKUSHO +1

Intelligent reflecting surface assisted identity channel binding authentication method

The application provides an intelligent reflecting surface assisted identity channel binding authentication method, mainly including three stages, in the first stage, a pilot sequence is sent by a to-be-verified party, the intelligent reflecting surface performs phase flipping between each pair of pilot symbols, and a verification party analyzes channel characteristics; in the second stage, an authentication message containing a digital signature is sent by the to-be-verified party, the intelligent reflecting surface is phase-locked to the state at the end of the previous stage, the verification party demodulates and verifies the signature of the authentication message; in the third stage, the verification party randomly adjusts the reflection coefficient matrix of the intelligent reflecting surface, and sends a challenge signal to the to-be-verified party, the to-be-verified party measures the power of the challenge signal reflected by the intelligent reflecting surface and feeds back a signed accumulated power value, the verification party receives the response of the to-be-verified party, performs consistency checking on the feedback power value and a locally calculated theoretical power value, and completes security authentication based on the checking result. The application can effectively resist pilot pollution attacks and malicious relay attacks.
Owner:ZHENGZHOU UNIVERSITY OF LIGHT INDUSTRY

Ultra-lightweight Hardware Control System and Method Based on Stateless Spatiotemporal Coordinate Mapping and Quantum-Resistant Zero-Knowledge Proof in Offline Environments

PendingKR1020260112927AConfidentialityAttack
The present invention relates to a stateless security system capable of perfectly verifying access and control authority for physical hardware, such as front doors, automobiles, and drones, even in an offline environment where the communication network connection with a central server is disconnected. Conventional hardware locks are vulnerable to offline hacking (physical hijacking) and relay attacks because they verify authority by comparing it with a user database (DB) stored on the device or through communication with a cloud server. The present invention incorporates a virtual quantum processing unit (vQPU) with O(1) constant complexity that completely eliminates memory storage (DB) into the hardware, and verifies the access rights of entrants by topologically computing them using only 'Multi-Node Zero-Knowledge Proof (ZKP) tokens' delegated from the master node and 'Quantum Helper Data'. Through this, it provides a technical effect that guarantees fundamental confidentiality even against physical destruction of the hardware or computational attacks on the quantum computer.
Owner:정민호

System and method for managing data relay attacks

The invention provides a system and a method for managing data relay attacks. A method includes causing a first roadside unit to broadcast one or more messages to one or more vehicles; determining, by an infrastructure-side algorithm, whether the one or more messages received by the second roadside unit match the one or more messages broadcast by the first roadside unit; and causing the one or more vehicles to initiate one or more remedial actions in response to determining that the one or more messages received by the second roadside unit do not match the one or more messages broadcast by the first roadside unit within the predefined time range.
Owner:FORD GLOBAL TECH LLC

Dual relay prevention digital key system based on geographic location and environmental fingerprint

PendingCN122637505AIn vehicleTrunking
The present application relates to the technical field of vehicle digital key, and provides a double relay prevention digital key system based on geographical position and environment fingerprint, which comprises a user mobile phone terminal, a vehicle terminal and a cloud server.The user mobile phone terminal collects the current mobile phone terminal environment fingerprint and uploads it to the cloud server.The vehicle terminal acquires the vehicle position and collects the vehicle terminal environment fingerprint, uploads the vehicle position and the vehicle terminal environment fingerprint to the cloud server through the vehicle-mounted communication module, and executes relevant operations according to the instruction of the cloud server.The cloud server receives and compares the position information and the environment fingerprint of the mobile phone terminal and the vehicle terminal, judges whether to allow unlocking, limited unlocking or refuse unlocking according to the position consistency, the comprehensive similarity of the environment fingerprint and the credential state, and sends the corresponding instruction to the vehicle terminal.The present application improves the defense capability against relay attacks through the geographical position verification mechanism and the environment fingerprint checking mechanism, does not need to add UWB hardware, has cost advantage, and supports complex scenes such as underground garage.
Owner:ZHEJIANG RUNXIN MICRO TECHNOLOGY CO LTD

A bluetooth identity-oriented end-to-end secure communication method and system

The application discloses a kind of end-to-end security communication methods and systems for bluetooth identity identification, method includes the following steps: S1, initialization stage, using LE Secure Connections protocol establishes trusted key negotiation channel, and core key is derived;S2, daily identification stage, through dynamic resolvable private address RPA and encryption verification, prevent replay attack and relay attack;S3, storage stage, utilize hardware encryption engine and partition protection, ensure the physical security of key.The application uses the above-mentioned end-to-end security communication method and system for bluetooth identity identification, realizes end-to-end security coverage, from the initial pairing of mobile phone and equipment, to the dynamic verification of daily communication, to the hardware level protection of core key, forms whole-link closed-loop security system, effectively resists various malicious attacks, adapts high-risk scene such as finance, security, improves the security and reliability of bluetooth identity identification.
Owner:GUIZHOU HUOYANSHAN ELECTRICAL CORP

Bank card swiping prevention and transaction verification system and method

The invention discloses an anti-theft bank card and a transaction verification system and method.The chip layer of the anti-theft bank card is internally provided with a quantum voiceprint sensor, dynamic verification is carried out by collecting voiceprint features and quantum disturbance features and combining the voiceprint features and the quantum disturbance features to the transaction verification system, and the transaction verification system comprises the anti-theft bank card, a transaction terminal and a back-end server. A transaction terminal is used as a communication transfer station, an anti-theft bank card is used as a biological signal acquisition end, a back-end server is used as a verification and transaction execution end, and through encryption communication real-time interaction among the transaction terminal, the biological signal acquisition end and the verification and transaction execution end and in combination with real-time verification of data such as quantum disturbance characteristics, voiceprint characteristics and communication data, composite security requirements such as relay attacks are effectively met. And the transaction security is improved.
Owner:金邦达有限公司

A method of unlocking and related system

An unlocking method and a related system, the unlocking method is applied to a first device, comprising: obtaining an RSSI value of a signal sent by a second device, the RSSI value being used to calculate a distance between the first device and the second device; in a case that the distance is less than a preset distance, obtaining first information of the first device and second information of the second device; in a case that the first information and the second information satisfy a preset condition, performing unlocking. The application can improve the unlocking security of a device to be unlocked, thereby improving the reliability of a non-inductive intelligent entering system and reducing the risk of the device to be unlocked encountering a broadcast relay attack.
Owner:BYD CO LTD

Systems and methods of managing data relay attacks

A method including the causation of a first road-side unit to broadcast one or more messages to one or more vehicles, the determination by an infrastructure-side algorithm of whether one or more messages received by a second road-side unit matches the one or more messages broadcasted by the first road-side unit, and the causation of the one or more vehicles to initiate one or more remedial actions in response to determining that the one or more messages received by the second road-side unit do not match the one or more messages broadcasted by the first road-side unit within a predefined timeframe.
Owner:FORD GLOBAL TECH LLC

NFC anti-relay protection

Systems and methods for detecting and preventing a relay attack in a channel on which a near field communication (NFC) action between a key holder device and a reader is attempted are disclosed. A time limit is established for polling communications between the key holder device and the reader. Each of the reader and the key holder device generates a reader random value and a device random value respectively. The reader sends to the key holder device the reader random value, which includes the time limit for a response from the key holder device, the response including the device random value and the reader random value. The reader receives the response from the key holder device and can then determine whether the response from the key holder device is received within the time limit, to detect whether a relay attack can be made on the channel for the NFC action.
Owner:APPLE INC

Mobile device, a vehicle having the same, and a control method thereof

A vehicle may receive channel hopping information and a time stamp of a data area of a packet from a communicator; broadcast the packet as information of an advertising signal through any one of a plurality of preset channels; in response to the information of the advertising signal being identical to information of a response signal of a mobile device received through the communicator, determine as a relay attack detection and control deactivation of a digital key; in response to the information of the advertising signal being different from the information of the response signal of the mobile device, confirm a channel through which the information of the response signal is received; and in response to the confirmed channel being identical to the any one channel, control activation of the digital key.
Owner:HYUNDAI MOTOR CO LTD +1

Low-power-consumption Bluetooth link layer relay attack blocking method, system, device, medium, program product and application

The invention belongs to the technical field of wireless communication security, and particularly relates to a low-power-consumption Bluetooth link layer relay attack blocking method, system, equipment, medium and program product and application, and the method comprises the following steps: initializing BLE channel selection parameters, synchronously calling CSA2, generating channel identification parameters and a channel remapping table based on a BLE access address and a channel mapping table, the method comprises the following steps: acquiring cryptographic disturbance input parameters for combination, performing hash operation by using a secure hash function, taking a result as a dynamic disturbance factor, generating a variable connection event count based on the dynamic disturbance factor, replacing a CSA2 native connection event count, and generating an unpredictable pseudo-random number in combination with a channel identification parameter; and finally, determining a next connection event communication channel which cannot be predicted by the attacker in combination with a channel mapping table (Channel Map) and a channel remapping table (Remapping Table). A BLE5. X for the use of CSA2; the system, the equipment and the medium are used for implementing the method. The program product comprises a computer program for implementing the method; and an attacker is prevented from implementing a relay attack.
Owner:XIDIAN UNIV

Positioning method and device combining BLE and UWB, and electronic equipment

The invention provides a positioning method and device combining BLE and UWB and electronic equipment, and relates to the technical field of vehicles. According to the method, the BLE module and the UWB module are combined with the neural network model to position the vehicle key, the advantages of different technologies can be effectively fused, and the positioning precision and the anti-interference capability are improved. In addition, the BLE module in the scheme can adopt a BLE Channel sounding technology to realize positioning, the technology can realize decimeter-level precision distance measurement and has certain relay attack prevention capability, and the scheme adopts one UWB module, so that low-cost positioning can be realized on the basis of further relay attack prevention, namely, the scheme not only ensures the safety of a vehicle key, but also ensures the safety of the vehicle key. And the economical efficiency and the positioning precision are also considered.
Owner:FENG LEI ARTIFICIAL INTELLIGENCE TECHNOLOGY (SHANGHAI) CO LTD

Automatic attack generation and analysis method for low-power-consumption Bluetooth keyless entry system

The invention discloses an automatic attack generation and analysis method for a low-power-consumption Bluetooth keyless entry system, and the method comprises the steps: enabling a target vehicle control application to run in a sandbox environment which is constructed through the modification of a Bluetooth library file of an Android system, and enabling the target vehicle control application to run in the sandbox environment under the condition of no need of reverse engineering, capturing a complete BLE protocol interaction log at a system level; a specific defense mechanism adopted by the target system is automatically identified through protocol analysis and attack simulation; generating a structured attack strategy configuration file according to the identified defense mechanism, wherein the configuration file defines accurate conditions required to be met for successfully implementing the attack; and executing a relay attack according to the attack strategy configuration file to realize anomaly detection so as to generate a customized defense strategy for the BLE keyless entry system. The method is mainly used for carrying out rapid and extensible automatic safety evaluation and verification on BLE keyless entry systems of vehicles of different brands, does not need to depend on manual reverse engineering, and improves the efficiency.
Owner:ZHEJIANG UNIV +1

Relay attack prevention off-line vehicle control method and device, vehicle, medium and program product

The invention relates to the technical field of vehicle control, and discloses an anti-relay attack off-line vehicle control method, an anti-relay attack off-line vehicle control device, a vehicle, a medium and a program product, which can ensure that the vehicle is controlled in a network-free or weak network environment by establishing Bluetooth connection and executing communication interaction and a vehicle control process between vehicle control equipment and the vehicle in a network-free state. Moreover, the distance information between the vehicle and the vehicle control equipment is calculated by sending a distance measurement signal to the vehicle control equipment and receiving a response signal fed back by the vehicle control equipment, and an encryption authentication request of the vehicle control equipment is received after the distance information passes verification, so that a remote illegal request is preliminarily avoided. Then, the encrypted authentication request is decrypted, validity verification is carried out on a first session key of the vehicle control equipment and a second session key of the vehicle control equipment, and the time difference between a first timestamp when the encrypted authentication request is received and a second timestamp when the vehicle control equipment generates a response signal is verified, so that relay attack is blocked; and the vehicle is prevented from being illegally controlled or stolen.
Owner:CHONGQING CHANGAN AUTOMOBILE CO LTD

SYSTEMS AND METHODS FOR MANAGING DATA RELAY ATTACKS

A method including causing a first roadside unit to transmit one or more messages to one or more vehicles, determining, by an infrastructure-side algorithm, whether one or more messages received by a second roadside unit match the one or more messages transmitted by the first roadside unit; and causing the one or more vehicles to initiate one or more remedial actions in response to determining that the one or more messages received by the second roadside unit do not match the one or more messages transmitted by the first roadside unit within a predefined timeframe.
Owner:FORD GLOBAL TECH LLC

Payment method, POS machine and computer storage medium

The invention relates to a payment method, a POS machine and a computer storage medium, and the method comprises the steps: the payment information of a relay end is read in a non-contact card reading mode, and the time for reading the payment information does not exceed the card reading operation time set by a timer circuit and a preset card reading time upper limit; and if the payment information is successfully read within the card reading operation time and a preset card reading time upper limit, payment is completed based on the payment information. According to the method provided by the invention, the non-contact card reading time of the POS machine is shortened, so that the possibility of relay attack is effectively reduced.
Owner:BEIJING HAIKE RONGTONG PAYMENT SERVICE CO LTD

Systems and methods for verifying remote device proximity in RFID systems

Systems and methods for verifying remote device proximity in RFID systems are described. To reduce the risk of relay attacks, a terminal may determine a distance of a remote device from the terminal. The terminal may send a computational challenge to the remote device and determine whether a latency of the response is within a maximum acceptable latency, indicating that the remote device is within a maximum acceptable distance. The maximum acceptable latency may be dynamically determined based on context information, such as a time of day, that may be correlated with a likelihood of attempted unauthorized accesses. The terminal may determine whether to perform an action associated with the remote device based on whether the response was received within the maximum acceptable latency.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC

Methods and related equipment for verifying the identity of electronic devices

This application provides a method and related equipment for verifying the identity of an electronic device, comprising: a first electronic device sending N challenge data packets to a second electronic device; the first electronic device receiving N response data packets from the second electronic device, wherein each of the N response data packets corresponds one-to-one with the N challenge data packets; the first electronic device determining first verification information based on the N response data packets, wherein the first verification information indicates the received signal strength (RSS) information of the N response data packets; the first electronic device acquiring second verification information from the second electronic device, wherein the second verification information indicates the RSS information of the N challenge data packets; and verifying the identity of the second electronic device based on the first verification information and the second verification information. The above technical solution utilizes the properties of RSS to provide an efficient identity authentication process. Therefore, this technical solution can ensure the execution of authenticated ranging and proximity estimation, and avoid relay attacks, replay attacks, and active attacks against digital key schemes.
Owner:YINWANG INTELLIGENT TECHNOLOGIES CO LTD

Systems and methods for preventing relay attacks

Systems, methods, and apparatus for preventing relay attacks are disclosed. A user device can receive device identification data for a first access device from an intervention device (e.g., when approaching the first access device). Messages can be received from a second access device via the intervention device. The messages may include a digital signature generated at least in part based on the second access device identification data. The user device can verify the message using the digital signature and a public key. If the message is invalid, the user device can discard the message. If the message is valid (e.g., unchanged), the user device can determine that the user has not confirmed their intention to interact with the second access device and therefore can terminate further interaction with the second access device.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Contactless payment relay attack protection

A method for contactless payment relay attack protection includes receiving an online authorization request including a cryptogram, a measured processing time, and a reference processing time from a terminal. The cryptogram is verified, and a determination is performed as to whether the measured processing time exceeds the reference processing time. An online authorization response authorizing or declining a monetary transaction is transmitted, based on the determination. An artificial intelligence transaction analysis can be performed based on past and current conditions (e.g., battery level, operating system, open applications) of a payment device such as a mobile phone, past and current conditions of a terminal, and / or a monetary amount. The online authorization response can be based on the artificial intelligence transaction analysis.
Owner:MASTERCARD INT INC