Vehicle Smart Key Authentication via Time-of-Flight Relay Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart key systems for vehicles are vulnerable to hacking due to the limitations of Low Frequency (LF) signal transmission range, which can be exploited by relays to facilitate unauthorized authentication processes.

Innovation Solution

A vehicle and method that utilize a communication unit to transmit a test value via LF signals and receive a verification value via RF signals, with a timer determining the passage time to authenticate the external device, preventing relay attacks by setting thresholds for the transmission and reception times.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Length of stationary object

If LF signal transmission range is extended using a relay, then the smart key can be authenticated from a distant location, but the system becomes vulnerable to relay attacks and hacking

Engineering Contradiction:
ImproveLF signal transmission rangeVSAvoidauthentication security
Core Design Contradiction:
Length of stationary objectVSReliability

Solution Approach 1:

The system performs preliminary actions by measuring and recording the time of flight (ToF) of LF signals during normal authentication. This baseline ToF data is stored and used later to detect anomalies, allowing the system to identify relay attacks before they can compromise security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring the ToF of LF signals and comparing it against the stored baseline. When the ToF exceeds the threshold, the system provides feedback by rejecting the authentication request, thereby preventing relay attacks while allowing legitimate distant authentication.

Inventive Principle:
Principle #23Feedback

2Reliability

If the vehicle authenticates smart keys only within limited LF range, then relay attacks are prevented, but legitimate users cannot authenticate from distant locations

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication distance flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system changes the parameter of ToF threshold dynamically. Instead of using a fixed distance limit, the system calculates an acceptable ToF range based on the baseline measurement and adds a margin. This allows legitimate users at various distances to authenticate while still blocking relay attacks that introduce excessive delay.

Inventive Principle:
Principle #35Parameter changes

3Length of stationary object

If the system uses only RF communication for authentication, then transmission range is increased, but the ability to detect relay attacks is reduced

Engineering Contradiction:
Improvecommunication rangeVSAvoidrelay attack detection capability
Core Design Contradiction:
Length of stationary objectVSDifficulty of detecting and measuring

Solution Approach 1:

The system introduces LF signal ToF measurement as an intermediary verification layer. The LF signal acts as a mediator that provides timing information about the physical proximity of the smart key, complementing the RF authentication process and enabling relay attack detection without replacing RF communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10202101B2Vehicle and method for controlling the vehicle
Publication Date: 2019.02.12 HYUNDAI MOTOR CO LTD
  • US10202101B2 patent drawing
  • US10202101B2 patent drawing
  • US10202101B2 patent drawing

AI summary

A vehicle includes a communication unit for transmitting a Low Frequency (LF) signal including a test value to an external device, and for receiving a Radio Frequency (RF) signal including a verification value from the external device, a timer for determining a passage time from a point of time of transmission of the test value to a point of time of reception of the verification value, and a controller for authenticating the external device based on the passage time and whether the test value and the verification value correspond to each other.