Passive Keyless Entry Relay Attack Detection Using RSSI
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Passive keyless entry systems are vulnerable to relay attacks, allowing unauthorized access and control of vehicles by mimicking communication between the key fob and the vehicle using relay stations, which existing systems fail to detect effectively.
Innovation Solution
Implementing a system that uses Bluetooth Low Energy (BLE) transceivers in both the base and portable units to measure and compare Received Signal Strength Indicator (RSSI) values, terminating communication if significant discrepancies are detected, and adjusting transmission power to verify direct communication, thereby preventing relay attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If relay attack stations are used to extend communication range, then accessibility and convenience are improved, but security against unauthorized access deteriorates
Solution Approach 1:
The system continuously monitors RSSI values from both the portable unit and base unit, comparing them in real-time to detect discrepancies that indicate relay attacks. This feedback mechanism allows the system to maintain convenience while actively detecting security threats.
Solution Approach 2:
The patent introduces RSSI comparison as an intermediary verification layer between the portable unit and base unit. By measuring and comparing signal strength indicators, the system creates an additional security checkpoint that prevents relay attacks without affecting normal keyless entry operation.
2Reliability
If RSSI measurement and comparison mechanisms are added to detect relay attacks, then security is improved, but device complexity increases
Solution Approach 1:
The patent leverages the existing Bluetooth Low Energy transceivers in both portable units and base units to perform dual functions: normal communication and security verification through RSSI measurement. This multi-functionality approach avoids adding dedicated hardware while enhancing security.
Solution Approach 2:
The system uses its own communication infrastructure (Bluetooth transceivers) to perform security verification. The existing transceivers that handle normal communication also measure RSSI values, eliminating the need for separate measurement hardware and reducing overall system complexity.
3Reliability
If transmission power adjustment is implemented to verify direct communication, then security is improved, but energy consumption increases
Solution Approach 1:
The system performs transmission power adjustment and RSSI verification at specific intervals during the communication establishment process, rather than continuously. This periodic verification approach maintains security while minimizing energy consumption by activating power-intensive operations only when needed.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Effectively defends against relay attacks by ensuring direct communication between the base and portable units, enhancing security and preventing unauthorized access to vehicles.
Implementation Method 1
For each message received at the portable unit, a second RSSI value is measured
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A system includes a first unit associated with an object and a second unit. The first unit includes a first transceiver coupled with first processing circuitry. The second unit includes a second transceiver coupled with second processing circuitry. Methodology includes establishing a bidirectional wireless communication link between the first and second units. Following establishment of the communication link, the first and second units exchange messages. The first processing circuitry measures a first received signal strength indicator (RSSI) value for each of the messages received at the first unit and sends the first RSSI value in a subsequent message to the second unit. The second processing circuitry measures a second RSSI value for each of the messages received at the second unit and sends the second RSSI value in another subsequent message to the first unit. A relay attack is determined in response to the first and second RSSI values.