Time of Flight Security for Vehicle Key Fob Relay Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Passive Entry and Passive Start (PEPS) key systems are vulnerable to relay attacks, where a device mimics a valid key fob's signal, making it appear near or inside a vehicle, which existing solutions do not adequately address, especially when multiple key fobs are present, leading to potential unauthorized access and delays in unlocking.
Innovation Solution
Implementing a Time-of-Flight (ToF) security system that assigns time slots to key fobs within operative distance, using a Body Control Module (BCM) to select a key fob based on Received Signal Strength Indication (RSSI) and historical usage patterns, and performing ToF determinations to authenticate and unlock the vehicle, thereby mitigating relay attacks while maintaining low response times.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If signal strength is used to determine distance between key fob and vehicle, then passive entry function is enabled, but relay attack vulnerability increases
Solution Approach 1:
The patent changes the parameter used for distance determination from signal strength (RSSI) to time of flight (ToF). By measuring the actual time it takes for a signal to travel between the key fob and vehicle, the system obtains a more reliable distance metric that cannot be easily spoofed by relay attacks, while maintaining the convenience of passive entry functionality
Solution Approach 2:
The patent replaces the electromagnetic signal strength-based distance estimation with a time-based measurement system. Using precise timing measurements of signal round-trip time, the system substitutes the vulnerable RSSI method with a more secure ToF measurement that is difficult to manipulate through relay attacks
2Adaptability or versatility
If multiple key fobs are simultaneously present near the vehicle, then access flexibility is improved, but cumulative delays occur in unlocking
Solution Approach 1:
The system performs preliminary actions by pre-assigning time slots to each key fob before the actual authentication process. When multiple key fobs are present, their ToF measurements are conducted in predetermined time slots rather than sequentially, which eliminates cumulative delays while maintaining the ability to support multiple users
Solution Approach 2:
The patent implements periodic action by using time-division multiplexing where each key fob is assigned a specific time slot for communication. This periodic structure allows the system to handle multiple key fobs simultaneously without interference or cumulative delays, as each fob communicates at its designated time interval
3Reliability
If time of flight determination is performed for each key fob sequentially, then relay attack resistance is improved, but response time increases
Solution Approach 1:
The system performs preliminary assignment of time slots to each key fob before authentication. This preliminary structuring allows parallel ToF measurements to be conducted without interference, maintaining relay attack resistance while eliminating the need for sequential processing that would increase response time
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
The ToF security system effectively reduces the threat of relay attacks, ensures secure vehicle access, and maintains tolerable delay limits by authenticating key fobs and selecting the appropriate one for unlocking, even in scenarios with multiple key fobs present.
Implementation Method 1
performing ToF determinations to authenticate and unlock the vehicle
Data Source
AI summary
A system for passive locking and unlocking a vehicle is described that includes a memory for storing executable instructions and a processor configured to execute the instructions to unlock the vehicle using a time of flight to transmit the trigger request between the vehicle and the first key fob. The processor receives, from a first key fob, a trigger request to unlock the vehicle, and determines, based key fob identifiers that identify the first key fob and a second key fob that is also near the vehicle, that the first and second key fobs are associated with a vehicle. The processor selects the first key fob based on a key fob characteristic. The processor evaluates the time of flight using the first key fob, and unlocks the vehicle based on the time of flight satisfying a threshold for signal transmission flight time.


