Secure Ranging Method for Spoofing-Resistant Device Unlocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security protocols for devices are vulnerable to attackers who can spoof the proximity of a trusted device by capturing and amplifying wireless signals, allowing unauthorized access without breaking encryption, particularly in wireless communication systems.

Innovation Solution

Implementing secure ranging methods that use shared secrets and timestamp-based distance measurements to verify the proximity of trusted devices, including multiple frequency bands and cryptographic key exchanges, to ensure secure communication and prevent spoofing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless protocols (Bluetooth, Wi-Fi) are used for device communication, then convenience and ease of operation are improved, but security is worsened due to vulnerability to signal capture and spoofing attacks

Engineering Contradiction:
Improveconvenience of device unlockingVSAvoidsecurity against spoofing attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces traditional wireless signal strength-based proximity detection (RSSI) with a cryptographic timestamp-based ranging system. Instead of relying on physical signal propagation characteristics that can be manipulated, the system uses cryptographic key exchanges and timestamp verification to mathematically prove proximity, substituting a vulnerable physical layer mechanism with a secure computational one.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent fundamentally changes the parameter used for proximity detection from signal strength (RSSI) to timestamp-based distance measurement. By measuring the time of flight of cryptographic messages between devices and comparing it against a threshold, the system transforms the proximity verification problem from a signal analysis task into a time-based cryptographic verification task that cannot be spoofed through signal amplification.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If RSSI-based proximity detection is used, then ease of operation is improved, but measurement precision is worsened due to susceptibility to signal amplification attacks

Engineering Contradiction:
Improveautomatic device unlockingVSAvoidaccuracy of proximity detection
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent replaces the physical signal propagation measurement (RSSI) with a cryptographic time-of-flight measurement system. The proximity determination is no longer based on signal strength attenuation through space, but on the precise timing of cryptographic message exchanges, making the measurement immune to signal amplification while maintaining automatic operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces cryptographic timestamps and shared secrets as intermediaries between the transmitting and receiving devices. These cryptographic elements mediate the proximity verification process, allowing the devices to accurately determine proximity through verified message timing without directly relying on vulnerable wireless signal characteristics.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cryptographic key exchanges and timestamp-based ranging are implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improvesecurity against spoofingVSAvoidcomplexity of ranging protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary cryptographic key exchange and shared secret establishment between devices before the actual proximity verification is needed. By pre-configuring cryptographic credentials and thresholds, the system reduces the computational and protocol complexity during the actual unlocking operation, as the heavy cryptographic work has already been completed in advance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11250118B2Remote interaction with a device using secure range detection
Publication Date: 2022.02.15 APPLE INC
  • US11250118B2 patent drawing
  • US11250118B2 patent drawing
  • US11250118B2 patent drawing

AI summary

In some embodiments, a first device performs ranging operations to allow a user to perform one or more operations on the first device without providing device-access credentials. For example, when a second device is within a first distance of the first device, the first device determines that the second device is associated with a first user account that is authorized to perform operations on the first device. In response to the determination, the first device enables at least one substitute interaction (e.g., a password-less UI interaction) to allow the operations to be performed on the first device to be accessed without receiving access credentials through a user interface. In response to detecting an occurrence of the substitute interaction, the operation is authorized on the first device.