PEPS Relay Attack Prevention via Time-of-Flight Ranging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Passive entry passive start (PEPS) systems are vulnerable to relay attacks, where thieves deceive the system by relaying short-range communication over long distances without the vehicle user's permission, allowing unauthorized access or starting of the vehicle.

Innovation Solution

The method involves communicating authorization signals and time-of-flight (ToF) ranging signals concurrently between a portable controller and a base station to confirm authorization and proximity, preventing the target function from being controlled if the controller is not within range, using low-frequency (LF) and ultra-high frequency (UHF) communications for authorization and ultra-wide-band (UWB) communications for ToF measurements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If short-range PEPS communication is relayed over long distances, then unauthorized access is enabled, but system security is compromised

Engineering Contradiction:
Improveremote control accessVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary ranging measurement mechanism that acts as a mediator between the authorization signal and the target function execution. The ranging signal measures the physical distance between the controller and base station, serving as an intermediary verification layer that prevents relay attacks by confirming the controller is within the required proximity range before allowing target function activation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary ranging measurement and verification before executing the target function. By measuring the distance between the controller and base station in advance and comparing it against a predetermined threshold, the system proactively prevents unauthorized access attempts rather than reacting after detection.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If concurrent authorization and ranging signals are communicated, then relay attack prevention is achieved, but communication complexity increases

Engineering Contradiction:
Improverelay attack preventionVSAvoidcommunication protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authorization signal communication and ranging signal communication into a single concurrent process. Both types of signals are transmitted and received simultaneously between the controller and base station, combining two verification functions into one integrated communication exchange rather than separate sequential processes.

Inventive Principle:
Principle #5Merging (Combining)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach effectively prevents relay attacks by ensuring that the vehicle function is only enabled when the controller is authorized and within range, enhancing security by reducing the risk of unauthorized access or starting.

Implementation Method 1

communicating authorization signals and time-of-flight (ToF) ranging signals concurrently between a portable controller and a base station

Methodology Applied
Scientific EffectTime of Flight: Time of Flight

Data Source

PatentUS9566945B2Passive entry passive start (PEPS) system with relay attack prevention
Publication Date: 2017.02.14 LEAR CORP
  • US9566945B2 patent drawing
  • US9566945B2 patent drawing
  • US9566945B2 patent drawing

AI summary

A system includes a remote control unit, such as a fob, and a base station at a target, such as a vehicle. The control unit and the base station are configured to communicate authorization signals and time-of-flight (ToF) ranging signals concurrently between one another. The base station is further configured to confirm from the authorization signals whether the control unit is authorized for controlling a target function and to confirm from the ToF ranging signals whether the control unit is within range of the target. The base station is further configured to prevent the target function from being controlled by the control unit when the control unit is not within range of the target.