BLE Round-Trip Timing Attack Detection Using Frequency Samples
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
RTT-based ranging techniques in Bluetooth Low Energy (BLE) networks are susceptible to spoofing attacks, such as early commit late detect (ECLD) and early detect late commit (EDLC), compromising security in keyless entry systems.
Innovation Solution
A method involving a wireless device that compares the frequency and/or in-phase quadrature (IQ) samples of a transmitted signal to a reference frequency sample to detect intrusions during round-trip timing estimation, using logic to determine frequency distortions indicative of potential attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If RTT-based ranging techniques are used in BLE networks, then distance estimation and keyless entry functionality is achieved, but the system becomes susceptible to spoofing attacks (ECLD, EDLC)
Solution Approach 1:
The patent implements feedback mechanisms where the receiving device sends acknowledgment packets with frequency information back to the transmitting device. The transmitting device uses this feedback to detect frequency distortions that indicate spoofing attempts, allowing real-time security monitoring during the RTT-based keyless entry operation
Solution Approach 2:
The patent introduces frequency samples and IQ data as intermediary elements that carry additional security information during the RTT exchange. These intermediaries enable the detection of attacks without disrupting the underlying distance estimation functionality, allowing security verification alongside the normal keyless entry operation
2Reliability
If frequency comparison methods are added to detect intrusions, then security against spoofing is improved, but device complexity increases
Solution Approach 1:
The patent makes the existing receiver components multi-functional by enabling them to perform both distance estimation and attack detection. The same receiver that estimates RTT for keyless entry also analyzes frequency samples and IQ data to detect spoofing attempts, eliminating the need for separate dedicated security hardware
Solution Approach 2:
The patent changes the analysis parameters from simple RTT timing to include frequency deviations and IQ sample patterns. By transforming the detection approach to analyze frequency variations within the existing signal structure, the system achieves enhanced security without requiring fundamentally new hardware components
3Measurement precision
If frequency analysis is performed on transmitted signals, then spoofing detection accuracy is improved, but processing time increases
Solution Approach 1:
The patent performs preliminary frequency sampling and IQ data collection during the normal RTT exchange process, so that when attack detection is needed, the data is already captured and ready for analysis. This preliminary action during the legitimate operation phase reduces the additional time required for security verification
Data Source
AI summary
A wireless device includes a receiver adapted with Bluetooth® low energy (BLE) capability and logic at least one of coupled to or integrated within the receiver. The logic determines frequency samples of bits of a predetermined pattern of a packet during a round-trip timing estimation of the packet, wherein the packet is received during a keyless access attempt of an enclosure having a transmitter and the receiver. The logic compares, to a reference frequency sample, the frequency samples of bits of the predetermined pattern. In response to determining a difference between the reference frequency sample and the frequency samples of bits of the predetermined pattern, the logic detects an intrusion associated with the predetermined pattern.


