Secure Wireless Ranging Using Transient Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless ranging techniques are vulnerable to relay attacks due to the lack of encryption in signals exchanged between devices, allowing dishonest devices to intercept and manipulate communications, leading to unauthorized access.

Innovation Solution

Implementing secure wireless ranging by using a transient key derived from shared random identifiers and a pre-shared key to encrypt measurement signals, ensuring only authorized devices can determine the separation distance and communicate securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional wireless ranging techniques are used, then device communication and distance measurement are enabled, but the system becomes vulnerable to relay attacks due to lack of encryption

Engineering Contradiction:
Improvesecurity against relay attacksVSAvoidencryption mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing key derivation and encryption setup before the actual distance measurement process. A transient key is derived in advance from shared random identifiers and a pre-shared key, then used to encrypt measurement signals. This preliminary cryptographic preparation ensures security is established before vulnerable communications occur, preventing relay attacks without complicating the core ranging function.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption is added to wireless ranging signals, then security against relay attacks is improved, but the complexity of the communication protocol increases

Engineering Contradiction:
Improvesignal encryption securityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary element - a transient key - that mediates between the pre-shared key and the encrypted measurement signals. This transient key is derived from random identifiers exchanged during the protocol and serves as a session-specific encryption key. By using this intermediary, the system achieves strong security without requiring complex cryptographic operations in the main measurement path, thus limiting protocol complexity increase.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If distance bounding protocols are implemented without encryption, then wireless ranging functionality is achieved, but unauthorized access can occur through signal interception and manipulation

Engineering Contradiction:
Improveauthorization securityVSAvoidencryption implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming the cryptographic parameters used in distance bounding protocols. Instead of using unencrypted signals, the measurement signals are encrypted using a transient key derived from pre-shared keys and random identifiers. This parameter change from plaintext to encrypted signals ensures that even if signals are intercepted, they cannot be manipulated without the cryptographic keys, thus securing authorization while maintaining protocol functionality.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3460503B1Secure wireless ranging
Publication Date: 2023.08.16 APPLE INC
  • EP3460503B1 patent drawingFigure 1
  • EP3460503B1 patent drawingFigure 2
  • EP3460503B1 patent drawingFigure 3

AI summary

Embodiments for securely determining a separation distance between wireless communication devices is provided. These embodiments include receiving a measurement request and a first random identifier from a first wireless communication device at a second wireless communication device. The embodiments also includes deriving a transient key using the first random identifier, a second random identifier (generated by the second device), and a pre-shared key. The first and second random identifiers, the pre-shared key, and the transient key derived therefrom are shared between the first and second devices, but are not known to any other devices. The embodiments further include encrypting measurement data exchanged between the two devices using the transient key, and using the encrypted measurement data to calculate and verify a separation distance between the devices. The embodiments thus prevent dishonest wireless communication devices from intercepting communications and spoofing a location of one of the two honest devices.