Key Derivation for UWB Ranging in Keyless Entry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern keyless entry systems in vehicles face security challenges, particularly in ultra-wide band (UWB) RF ranging systems, where attacks like relay and preamble injection can manipulate distance measurements, and existing solutions have high overhead and do not adequately protect the confidentiality, integrity, and authenticity of data frames, especially in limited RF budgets.

Innovation Solution

A key derivation scheme is introduced for UWB RF communication that uses Type 1 and Type 2 data frames, employing ECB or CBC encryption for Type 1 frames and authenticated encryption for Type 2 frames, with a Generic Scrambled Timestamp Sequence (GSTS) index to ensure confidentiality, integrity, and authenticity, minimizing data transmission while protecting against attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption schemes are used for data frame transmission in UWB ranging systems, then security against relay and preamble injection attacks is improved, but data overhead increases and RF budget is consumed

Engineering Contradiction:
ImprovesecurityVSAvoiddata overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and removes unnecessary encryption overhead from data frame transmission. Instead of encrypting entire data frames, the invention applies encryption only to critical security elements (preamble and specific fields), thereby maintaining security while significantly reducing data overhead and preserving RF budget for ranging measurements

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different encryption strategies to different parts of the data frame based on their security requirements. The preamble receives full encryption protection, while other fields use selective encryption or authentication mechanisms, optimizing the balance between security and efficiency for each specific component

Inventive Principle:
Principle #3Local quality

2Reliability

If full encryption of data frames is applied to protect confidentiality and integrity, then security is improved, but transmission efficiency decreases and energy consumption increases

Engineering Contradiction:
Improvedata integrityVSAvoidtransmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial encryption action by encrypting only the essential security-critical portions of data frames (particularly the preamble containing synchronization and security information) rather than the entire frame. This partial approach maintains data integrity and confidentiality for critical elements while preserving transmission efficiency and reducing energy consumption

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If authentication mechanisms are added to verify data frame authenticity, then protection against attacks is improved, but device complexity increases

Engineering Contradiction:
ImproveauthenticityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges authentication functionality with the existing encryption framework by integrating authentication tags and verification mechanisms directly into the encrypted data frame structure. This consolidation allows authenticity verification to be performed as part of the normal decryption process, reducing the need for separate authentication hardware or protocols and thereby managing device complexity

Inventive Principle:
Principle #5Merging (Combining)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The scheme effectively reduces data overhead, enhances security by protecting user privacy and data integrity, and prevents attacks like relay and preamble injection, while maintaining efficient energy use in UWB RF communication.

Implementation Method 1

An UWB RF ranging system typically employs the Time-of-Flight principle to determine the distance between the tag and the structure to be opened or markers on the structure. Usually, a transceiver's transmitter sends out a waveform, commonly a chirp or a pulse, which is either reflected by an object or retransmitted by a second transceiver. Based on the amount of time it takes for the reflection or retransmission to reach the originating transceiver's receiver, the distance between the objects can be calculated.

Methodology Applied
Scientific EffectTime of flight: Time of Flight

Data Source

PatentEP3681046B1Key derivation scheme for data frame transmission in ultra-wide band ranging in keyless entry systems
Publication Date: 2022.07.20 NXP BV
  • EP3681046B1 patent drawingFigure 1
  • EP3681046B1 patent drawingFigure 2~5
  • EP3681046B1 patent drawingFigure 3

AI summary

Disclosed are methods and devices for deriving keys for coding the contents of data frames, which are to be transmitted in a keyless entry system during an ultra-wide band ranging session between a transceiver device coupled to a base structure to be opened and closed and/or to be locked and unlocked, and a mobile transceiver device associated with the structure-coupled transceiver device.