Interlocking Tx Rx Roles for Relay-Attack Resistant Wireless Entry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication systems, such as PEPS systems in modern vehicles, are vulnerable to relay-attacks where thieves deceive the system into thinking the keyfob is nearby, allowing unauthorized access and potential theft.

Innovation Solution

The solution involves interlocking the switching between transmit (Tx) and receive (Rx) roles of the communicating devices (keyfob and vehicle's digital radio device) to create a time-bound communication protocol, reducing time uncertainty and limiting the range of a successful relay-attack to about 20-30 meters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the vehicle allows RF communication with keyfobs within a certain range to enable passive entry, then ease of operation is improved, but vulnerability to relay-attacks increases

Engineering Contradiction:
Improvepassive entry convenienceVSAvoidsecurity against relay-attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing a challenge-response authentication mechanism before granting access. The vehicle sends a challenge signal to the keyfob, and the keyfob must respond with the correct authentication code within a specific time window. This preliminary verification ensures that the keyfob is not only nearby but also authentic, preventing relay-attacks where a malicious device might otherwise intercept and relay signals.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback mechanisms where the vehicle monitors the timing and validity of responses from the keyfob. If the response time exceeds the expected window or the authentication fails, the vehicle immediately terminates the access attempt. This feedback loop allows the system to detect and respond to relay-attack attempts in real-time, maintaining security while preserving legitimate access.

Inventive Principle:
Principle #23Feedback

2Ease of manufacture

If the system uses traditional RF communication protocols for keyless entry, then ease of manufacture is improved, but susceptibility to relay-attacks increases

Engineering Contradiction:
Improveimplementation simplicityVSAvoidresistance to relay-attacks
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system modifies critical parameters of the RF communication protocol, specifically the time window for authentication responses and the challenge-response mechanism. By changing these temporal and procedural parameters, the system maintains compatibility with existing RF hardware while adding security features that prevent relay-attacks. The modified protocol requires precise timing control and authentication verification, which can be implemented with standard microcontrollers and radio modules.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If the vehicle accepts keyfob signals without strict timing control, then device complexity is reduced, but effectiveness against relay-attacks decreases

Engineering Contradiction:
Improvetiming control requirementsVSAvoidrelay-attack prevention capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system performs preliminary timing setup by defining a specific authentication time window before the actual communication begins. The vehicle waits for the keyfob's response within this pre-established window, which is calculated based on the expected propagation time of RF signals. This preliminary timing configuration allows the system to detect timing anomalies indicative of relay-attacks without requiring complex real-time analysis, thus balancing simplicity with security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250030726A1Relay-attack resistant communications
Publication Date: 2025.01.23 TEXAS INSTRUMENTS INC
  • US20250030726A1 patent drawing
  • US20250030726A1 patent drawing
  • US20250030726A1 patent drawing

AI summary

A method of relay-attack resistant communications in a wireless communications system that includes a master wireless device (Master) sending a synchronization signal to a slave wireless device (Slave). The synchronization signal includes timing information including a common time reference and a timeslot duration for interlocking Master communication timeslots for Master and Slave communication timeslots so that an alternating TX and RX role pattern is provided. The Master analyzes Slave packet data received from the Slave to identify overlaps of a transmission from the Master and the slave packet data, and in a case of detecting overlap, suspends communications from Master to Slave to prevent a relay-attack.