Keyless Entry Proximity Verification Against Relay Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote key entry systems are vulnerable to relay and replay attacks, which allow unauthorized access to vehicles, and existing solutions like Distance Bounding require high-spec hardware and Ultra-Wide Bandwidth channels, making them difficult to implement effectively.

Innovation Solution

A method and system using a verifier, prover, and helper components that communicate wirelessly, with the prover generating a hash based on channel observations and a cryptographic key, and the verifier verifying proximity and legitimacy through similarity checks and hash comparisons, without the need for high-time accuracy or specialized hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Distance Bounding techniques are used to prevent relay attacks, then security against relay attacks is improved, but device complexity and hardware requirements increase

Engineering Contradiction:
Improvesecurity against relay attacksVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/time-based measurement system of Distance Bounding with a signal-based channel observation system. Instead of measuring time of flight with high-precision hardware, the system observes characteristics of the wireless communication channel (signal strength, phase, timing) to determine proximity. This substitution maintains security while eliminating complex hardware requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces channel observations as an intermediary mechanism between the verifier and prover. Rather than directly measuring time or distance, the system uses the wireless channel itself as a mediator that carries proximity information through its observed characteristics. This intermediary approach simplifies the verification process while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Distance Bounding techniques are used to prevent relay attacks, then security against relay attacks is improved, but ease of implementation deteriorates

Engineering Contradiction:
Improvesecurity against relay attacksVSAvoidease of implementation
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces the complex time measurement mechanism of Distance Bounding with standard wireless communication observations. By using existing wireless channel characteristics rather than specialized timing hardware, the system becomes much easier to implement in commercial products while maintaining equivalent security properties.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The wireless channel itself provides the proximity verification information through its natural characteristics. The channel observations are obtained as a byproduct of normal communication, eliminating the need for separate verification infrastructure. The system uses the communication medium's inherent properties to perform security verification.

Inventive Principle:
Principle #25Self-service

3Reliability

If Distance Bounding techniques are used to prevent relay attacks, then security against relay attacks is improved, but loss of time increases due to complex timing measurements

Engineering Contradiction:
Improvesecurity against relay attacksVSAvoidtiming measurement complexity
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent substitutes high-precision time measurement with signal characteristic observation. Instead of requiring nanosecond-level timing accuracy, the system uses readily observable channel properties that can be measured with standard wireless hardware, significantly reducing the time and computational overhead while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of manufacture

If standard wireless communication channels are used instead of Ultra-Wide Bandwidth channels, then ease of implementation is improved, but measurement precision may deteriorate

Engineering Contradiction:
Improveease of implementationVSAvoidproximity measurement accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent moves from one-dimensional time-based measurement to multi-dimensional channel observation. By considering multiple channel characteristics simultaneously (signal strength, phase, timing, frequency response), the system achieves accurate proximity determination using standard wireless channels, compensating for the lack of Ultra-Wide Bandwidth through increased observational dimensions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent combines multiple channel observation metrics to create a composite proximity verification mechanism. Rather than relying on a single precise measurement, the system integrates multiple less-precise observations to achieve accurate and reliable proximity determination, similar to how composite materials combine multiple materials to achieve superior properties.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS11926284B2Preventing replay/relay attacks in keyless entry systems
Publication Date: 2024.03.12 KK TOSHIBA
  • US11926284B2 patent drawing
  • US11926284B2 patent drawing
  • US11926284B2 patent drawing

AI summary

A method for controlling access to a resource, the method performed by a system comprising a first component, a second component and a third component, the first component comprising a first cryptographic key; the second component comprising a second cryptographic key. The method comprising: transmitting a signal; generating, by the first component a first channel observation; generating, by the second component, a second channel observation, and a first data value based on the second channel observation and the second cryptographic key; transmitting, by the second component, the second channel observation and the first data value; and verifying the second component based on the second channel observation, the first cryptographic key and the first data value; and allowing access to the resource in response to determining that the second component is: 1) permitted to gain access to the resource; and 2) located proximate to the first component.