Round-Trip Timing Estimation With BLE Spoofing Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RTT-based ranging techniques in Bluetooth Low Energy (BLE) networks are susceptible to spoofing attacks, such as early commit late detect (ECLD) and early detect late commit (EDLC), compromising the security of keyless entry systems.

Innovation Solution

A wireless device compares the frequency and in-phase quadrature (IQ) samples of a transmitted signal to a reference frequency sample to detect potential intrusions during round-trip timing estimation, using a receiver logic to analyze frame synchronization patterns and send notifications if an intrusion is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If RTT-based ranging techniques are used for keyless entry, then convenience and communication range are improved, but security becomes vulnerable to spoofing attacks

Engineering Contradiction:
Improveconvenience of keyless entryVSAvoidsecurity against spoofing attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system continuously monitors frequency samples during RTT estimation and compares them against expected frequency patterns. When deviations indicating spoofing attempts are detected, the system provides feedback by blocking the access request, thereby maintaining security while preserving the convenience of RTT-based ranging

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Frequency analysis serves as an intermediary detection mechanism between the transmitted signal and the expected legitimate signal. By introducing frequency sample comparison as an intermediate verification step, the system can detect spoofing attempts without altering the fundamental RTT-based ranging operation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If frequency analysis is performed on received signals, then attack detection capability is improved, but processing complexity increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of performing complete signal analysis, the system applies partial action by focusing frequency sampling and comparison only on specific portions of the received signal during RTT estimation. This selective approach provides adequate attack detection capability while minimizing processing complexity

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes the parameter of analysis from raw signal processing to frequency domain analysis. By transforming the signal into frequency samples and comparing against expected patterns, the system achieves effective attack detection with simpler processing requirements compared to full signal analysis

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12425862B2Attack detection in round-trip timing estimation
Publication Date: 2025.09.23 INFINEON TECHNOLOGIES AMERICAS CORP
  • US12425862B2 patent drawing
  • US12425862B2 patent drawing
  • US12425862B2 patent drawing

AI summary

A wireless device includes a receiver adapted with Bluetooth® low energy (BLE) capability and logic at least one of coupled to or integrated within the receiver. The logic determines frequency samples of bits of a predetermined pattern of a packet during a round-trip timing estimation of the packet, wherein the packet is received during a keyless access attempt of an enclosure having a transmitter and the receiver. The logic compares, to a reference frequency sample, the frequency samples of bits of the predetermined pattern. In response to determining a difference between the reference frequency sample and the frequency samples of bits of the predetermined pattern, the logic detects an intrusion associated with the predetermined pattern.