Secure Ranging Codes and Mutual Authentication Against Relay Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication protocols are vulnerable to relay attacks, compromising the security of proximity-based interactions between devices, such as unlocking a smartphone with a wearable device, by allowing attackers to falsely indicate proximity.

Innovation Solution

Implement secure ranging using independently generated pseudorandom ranging codes derived from ranging keys, combined with mutual authentication through secure elements, to ensure devices verify proximity securely and prevent relay attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless communication protocols are used for proximity-based interactions, then ease of operation is improved, but security against relay attacks deteriorates

Engineering Contradiction:
Improveproximity-based interactionVSAvoidsecurity against relay attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary mutual authentication between devices before allowing proximity-based operations. The secure elements in both devices authenticate each other and establish shared secrets in advance, ensuring that even if relay attacks occur during communication, the devices have already verified each other's identity through cryptographic challenges and responses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces secure elements as intermediary components within each device that handle cryptographic operations independently. These secure elements generate and store private keys, perform digital signatures, and manage session secrets, acting as a trusted mediator between the application processor and the wireless communication interface to prevent relay attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure ranging with mutual authentication is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional components: secure elements for cryptographic operations, application processors for user interface and control, and wireless communication interfaces for signal transmission. This segmentation allows each component to specialize in its function, reducing overall system complexity while maintaining high security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each device's secure element performs self-service cryptographic operations including generating private keys, computing digital signatures, and deriving shared secrets without requiring external assistance. The devices independently complete mutual authentication through exchanged cryptographic challenges and responses, eliminating the need for centralized authentication servers.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Ensures secure verification of device proximity, preventing unauthorized access and enhancing security in proximity-based interactions by ensuring devices authenticate and verify range independently and securely.

Implementation Method 1

allow both devices to separately determine the distance or range between the devices based on the time of flight of the received signals

Methodology Applied
Scientific EffectTime of flight: Time of Flight

Data Source

PatentEP3417663B1Methods and architectures for secure ranging
Publication Date: 2025.08.27 APPLE INC
  • EP3417663B1 patent drawingFigure 1~2
  • EP3417663B1 patent drawingFigure 3
  • EP3417663B1 patent drawingFigure 4

AI summary

A secure ranging system can use a secure processing system to deliver one or more ranging keys to a ranging radio on a device, and the ranging radio can derive locally at the system ranging codes based on the ranging keys. A deterministic random number generator can derive the ranging codes using the ranging key and one or more session parameters, and each device (e.g. a cellular telephone and another device) can independently derive the ranging codes and derive them contemporaneously with their use in ranging operations.