Relay Attack Detection via Signal Strength and Content Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Short-range wireless communication systems are vulnerable to relay attacks, where a transceiver amplifies and retransmits signals to bypass security features, potentially allowing unauthorized access, and existing systems lack effective methods to detect and counter such attacks.
Innovation Solution
Implementing a system that compares the strength and content of received signals to a transmitted signal, identifying relay attacks by determining if the received signal is stronger than expected and initiating security actions such as notifications, alarms, or denying access when a relay attack is detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If short-range wireless communication systems operate without relay attack detection, then system simplicity is maintained, but security vulnerability increases allowing unauthorized access
Solution Approach 1:
The system performs preliminary actions by buffering the transmitted signal before it is sent and preparing to compare it with the received signal. This advance preparation enables the system to detect relay attacks by comparing the buffered signal characteristics with the actual received signal, allowing security verification to occur before unauthorized access can be completed.
Solution Approach 2:
The system implements feedback by comparing the received signal against the buffered transmitted signal and using this comparison to detect relay attacks. The signal strength measurement and content comparison provide feedback that determines whether a relay attack is occurring, enabling the system to respond appropriately by denying access or alerting the user.
2Difficulty of detecting and measuring
If signal strength threshold detection is implemented, then relay attack detection capability is improved, but false positive rate increases due to signal variations
Solution Approach 1:
The system changes parameters by comparing multiple characteristics of the signal including signal strength and content, rather than relying on a single fixed threshold. The signal strength threshold is adjusted based on the specific transmission conditions, and the content comparison uses code sequence values that change with each transmission, making the detection more robust against false positives while maintaining relay attack detection capability.
Solution Approach 2:
The detection mechanism uses a composite approach by combining signal strength measurement with content comparison. Instead of using a single detection method, the system integrates multiple detection parameters (signal strength threshold and code sequence matching) to create a more reliable relay attack detection system that reduces false positives while maintaining security.
3Measurement precision
If the system buffers and compares signal content, then relay attack detection precision is improved, but processing time increases
Solution Approach 1:
The system performs preliminary action by buffering the transmitted signal immediately after transmission and preparing it for comparison. This advance buffering eliminates the need for complex real-time signal capture and storage, reducing processing time while maintaining the ability to perform precise content comparison between the transmitted and received signals.
Solution Approach 2:
The system rushes through the comparison process by directly comparing the buffered signal content with the received signal content without extensive intermediate processing. The code sequence value comparison is performed efficiently by skipping unnecessary processing steps, allowing precise detection while minimizing the time loss associated with signal analysis.
Data Source
AI summary
The disclosed computer-implemented method for defeating relay attacks may include (1) buffering, in a memory buffer, an encoded signal that has been sent to a remote device, (2) detecting, within a time interval of the encoded signal being sent, a second signal that corresponds to the encoded signal, (3) determining that a strength of the second signal is above a predetermined threshold, (4) determining, based on the strength of the second signal being above the predetermined threshold, that the second signal represents a relay attack, and (5) initiating a security action to defeat the relay attack. Various other methods, systems, and computer-readable media are also disclosed.


