Round-Trip Timing Estimation With BLE Spoofing Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
RTT-based ranging techniques in Bluetooth Low Energy (BLE) networks are susceptible to spoofing attacks, such as early commit late detect (ECLD) and early detect late commit (EDLC), compromising the security of keyless entry systems.
Innovation Solution
A wireless device compares the frequency and in-phase quadrature (IQ) samples of a transmitted signal to a reference frequency sample to detect potential intrusions during round-trip timing estimation, using a receiver logic to analyze frame synchronization patterns and send notifications if an intrusion is detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If RTT-based ranging techniques are used for keyless entry, then convenience and communication range are improved, but security becomes vulnerable to spoofing attacks
Solution Approach 1:
The system continuously monitors frequency samples during RTT estimation and compares them against expected frequency patterns. When deviations indicating spoofing attempts are detected, the system provides feedback by blocking the access request, thereby maintaining security while preserving the convenience of RTT-based ranging
Solution Approach 2:
Frequency analysis serves as an intermediary detection mechanism between the transmitted signal and the expected legitimate signal. By introducing frequency sample comparison as an intermediate verification step, the system can detect spoofing attempts without altering the fundamental RTT-based ranging operation
2Reliability
If frequency analysis is performed on received signals, then attack detection capability is improved, but processing complexity increases
Solution Approach 1:
Instead of performing complete signal analysis, the system applies partial action by focusing frequency sampling and comparison only on specific portions of the received signal during RTT estimation. This selective approach provides adequate attack detection capability while minimizing processing complexity
Solution Approach 2:
The system changes the parameter of analysis from raw signal processing to frequency domain analysis. By transforming the signal into frequency samples and comparing against expected patterns, the system achieves effective attack detection with simpler processing requirements compared to full signal analysis
Data Source
AI summary
A wireless device includes a receiver adapted with Bluetooth® low energy (BLE) capability and logic at least one of coupled to or integrated within the receiver. The logic determines frequency samples of bits of a predetermined pattern of a packet during a round-trip timing estimation of the packet, wherein the packet is received during a keyless access attempt of an enclosure having a transmitter and the receiver. The logic compares, to a reference frequency sample, the frequency samples of bits of the predetermined pattern. In response to determining a difference between the reference frequency sample and the frequency samples of bits of the predetermined pattern, the logic detects an intrusion associated with the predetermined pattern.


