Relay Attack Detection Using Challenge-Response Timing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mass-produced smart devices are vulnerable to relay attacks due to the impracticality of precise Time of Flight and distance bounding methods, which require hardware not available in these devices.

Innovation Solution

A method involving two communication platforms that use encrypted signals over multiple channels, including Bluetooth or WiFi, and ultra-wideband frequencies, where a start clock signal and challenge are transmitted, and a response is sent, allowing the second platform to determine if a relay attack has occurred by measuring the time elapsed, ignoring responses if the time exceeds a predetermined threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Time of Flight or distance bounding methods are used to prevent relay attacks, then security against relay attacks is improved, but the requirement for highly precise hardware (nanosecond precision, specialized distance bounding hardware) makes the solution unrealistic for mass-produced smart devices

Engineering Contradiction:
Improvesecurity against relay attacksVSAvoidhardware precision requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a challenge-response mechanism as an intermediary verification step. Instead of directly measuring time of flight with high-precision hardware, the system uses cryptographic challenges exchanged between devices to indirectly verify proximity. The challenge is sent through the communication channel, and the response timing is measured with standard device clocks, avoiding the need for specialized nanosecond-precision hardware while still detecting relay attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/physical approach of direct time-of-flight measurement with specialized hardware with a cryptographic challenge-response system using standard device clocks and processors. This substitution allows the system to achieve relay attack detection using components already present in mass-produced smart devices, eliminating the need for additional precise hardware.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If standard communication channels are used without additional verification, then ease of operation is improved, but vulnerability to relay attacks increases

Engineering Contradiction:
Improvesimplicity of communicationVSAvoidrelay attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary verification actions before completing the authentication process. A challenge is sent through the communication channel before the final authentication decision is made. This preliminary challenge-response exchange allows the system to verify that the communication path is direct and not being relayed, while still using standard communication channels and maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11483320B2System and method for detecting active relay station attacks between two multimedia communication platforms
Publication Date: 2022.10.25 VOXX INT CORP
  • US11483320B2 patent drawing
  • US11483320B2 patent drawing
  • US11483320B2 patent drawing

AI summary

A method for detecting relay attacks between two communication platforms, the method including: receiving, at a first communication platform, a first signal sent via a first communication channel from a second communication platform, the first signal including information about a challenge; receiving, at the first communication platform, a second signal sent via a second communication channel from the second communication platform, the second signal being a start clock; receiving, at the first communication platform, a third signal sent via the second communication channel from the second communication platform, the third signal including the challenge; outputting, from the first communication platform, a response to the challenge via the first communication channel to the second communication platform; and determining, at the second communication platform, whether a relay attack has occurred based on a time elapsed from when the start clock began to when the response is received at the second communication platform.