Relay Station Attack Mitigation via RSSI and Transmit Power Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication systems, such as Bluetooth Low Energy (BLE), are vulnerable to relay station attacks, where unauthorized devices intercept and retransmit validation signals to gain control over vehicle systems, highlighting a need for improved security measures.

Innovation Solution

A system and method that includes a first and second wireless communication node, where the second node decrypts an encrypted transmit power value and compares it to a received signal strength indication, controlling communication based on the comparison to prevent unauthorized access, utilizing Bluetooth Low Energy nodes and sensors to monitor vehicle conditions and status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless communication protocols are used to access and operate vehicle systems, then ease of operation is improved, but vulnerability to relay station attacks increases

Engineering Contradiction:
Improveease of operationVSAvoidvulnerability to relay station attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification by comparing the received signal strength indication (RSSI) with the encrypted transmit power value before allowing communication. This preliminary action detects potential relay station attacks in advance by verifying that the signal strength matches the expected transmit power, preventing unauthorized devices from establishing communication with vehicle systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism that acts as a mediator between the wireless communication protocol and vehicle system access. The RSSI-to-transmit-power comparison serves as an intermediary security check that validates whether the communication path is direct or relayed, adding a security layer without disrupting the ease of wireless operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If relay station attack mitigation measures are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs self-service security verification where the receiving device uses its own received signal strength indication (RSSI) measurement to verify the authenticity of the transmitting device. By comparing the measured RSSI with the encrypted transmit power value, the system performs self-validation without requiring external security infrastructure, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the verification parameter from traditional authentication methods to a physical layer parameter comparison (RSSI vs. transmit power). This parameter change simplifies the security mechanism by using inherent radio frequency characteristics rather than complex cryptographic protocols, reducing device complexity while improving reliability against relay attacks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10192379B2System and method for mitigating relay station attack
Publication Date: 2019.01.29 HUF NORTH AMERICA AUTOMOTIVE PARTS MANUFACTURING CORP
  • US10192379B2 patent drawing
  • US10192379B2 patent drawing
  • US10192379B2 patent drawing

AI summary

A system for mitigating relay station attack in a wireless communication system is provided. The system may include a first wireless communication node and a second wireless communication node. The first wireless communication node is operable to transmit data including an encrypted transmit power value. The second wireless communication node is operable to receive the data, decrypt the encrypted transmit power value, and determine a received signal strength indication value of the data. The second wireless communication node may also be operable to compare the received signal strength indication value to the decrypted transmit power value and prevent communication between the first wireless communication node and the second wireless communication node based on the comparison between the received signal strength indication value and the decrypted transmit power value.