Interlocking Tx Rx Roles for Relay-Attack Resistant Wireless Entry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication systems, such as PEPS systems in modern vehicles, are vulnerable to relay-attacks where thieves deceive the system into thinking the keyfob is nearby, allowing unauthorized access and potential theft.
Innovation Solution
The solution involves interlocking the switching between transmit (Tx) and receive (Rx) roles of the communicating devices (keyfob and vehicle's digital radio device) to create a time-bound communication protocol, reducing time uncertainty and limiting the range of a successful relay-attack to about 20-30 meters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the vehicle allows RF communication with keyfobs within a certain range to enable passive entry, then ease of operation is improved, but vulnerability to relay-attacks increases
Solution Approach 1:
The system performs preliminary actions by establishing a challenge-response authentication mechanism before granting access. The vehicle sends a challenge signal to the keyfob, and the keyfob must respond with the correct authentication code within a specific time window. This preliminary verification ensures that the keyfob is not only nearby but also authentic, preventing relay-attacks where a malicious device might otherwise intercept and relay signals.
Solution Approach 2:
The system uses feedback mechanisms where the vehicle monitors the timing and validity of responses from the keyfob. If the response time exceeds the expected window or the authentication fails, the vehicle immediately terminates the access attempt. This feedback loop allows the system to detect and respond to relay-attack attempts in real-time, maintaining security while preserving legitimate access.
2Ease of manufacture
If the system uses traditional RF communication protocols for keyless entry, then ease of manufacture is improved, but susceptibility to relay-attacks increases
Solution Approach 1:
The system modifies critical parameters of the RF communication protocol, specifically the time window for authentication responses and the challenge-response mechanism. By changing these temporal and procedural parameters, the system maintains compatibility with existing RF hardware while adding security features that prevent relay-attacks. The modified protocol requires precise timing control and authentication verification, which can be implemented with standard microcontrollers and radio modules.
3Device complexity
If the vehicle accepts keyfob signals without strict timing control, then device complexity is reduced, but effectiveness against relay-attacks decreases
Solution Approach 1:
The system performs preliminary timing setup by defining a specific authentication time window before the actual communication begins. The vehicle waits for the keyfob's response within this pre-established window, which is calculated based on the expected propagation time of RF signals. This preliminary timing configuration allows the system to detect timing anomalies indicative of relay-attacks without requiring complex real-time analysis, thus balancing simplicity with security.
Data Source
AI summary
A method of relay-attack resistant communications in a wireless communications system that includes a master wireless device (Master) sending a synchronization signal to a slave wireless device (Slave). The synchronization signal includes timing information including a common time reference and a timeslot duration for interlocking Master communication timeslots for Master and Slave communication timeslots so that an alternating TX and RX role pattern is provided. The Master analyzes Slave packet data received from the Slave to identify overlaps of a transmission from the Master and the slave packet data, and in a case of detecting overlap, suspends communications from Master to Slave to prevent a relay-attack.


