114
G. Avoine et al.
7.1.1 Relay Attacks
A relay attack against two legitimate parties A and B is one whereby a man-in-themiddle C forwards A’s messages to B and/or B’s messages to A, unbeknown to
them. In doing so, C wishes to obtain a facility meant for A and granted by B or
vice-versa. For instance, C could get to fraudulently spend the funds associated with
A’s bank-card at a payment terminal embodied by B.
Relay attacks are hard to detect and deter, as they subvert all conventional
cryptographic mechanisms potentially employed in the protocols: C only forwards
the messages, and does not need to break the cryptography that is used. This is even
more acute in the case of contactless applications: user A simply brings a token (e.g.,
a card or phone) within range of a reader B, and the protocol starts automatically,
with no consent or input by the person who is getting the privilege. Thus, a relay
attack can be mounted without hindrance.
7.1.2 Distance Bounding
The further A is from B, the longer the messages relayed by C from A take to arrive
at B. Hence, imposing an upper-bound on the round-trip times (RTTs) of messageexchanges was proposed as a countermeasure in [83]. This lowers the probability of
successful relay attacks. This mechanism is often referred to as distance bounding
(DB).
The idea of distance-bounding protocols is as follows: a verifier (e.g., an RFID
reader) is equipped in the physical layer with a reliable clock that measures the
RTTs of certain communication exchanges to check that a prover (e.g., a card) is no
further than some allowed distance. So, at some point in the protocol, the verifier
starts its clock, sends a challenge, and stops the clock when it receives the response.
The measured time Δ t corresponds to twice the time it takes for a message to travel
from the prover to the verifier, plus the time taken by the prover to reply. Since no
information can travel faster than the speed of light c, d =
Δ t ·c
2 is an upper bound
on the distance between the prover and the verifier. If the prover was any further
than d, then it would mean that the messages traveled faster than light, which is
impossible. Consequently, if d is short enough, then the verifier can deduce that the
prover is within range. In other words, a time bound B can be a priori fixed such
that, if Δ t > B, then the verifier rejects the prover.
As described above, distance bounding would be just a proximity-checking
mechanism. However, most distance-bounding protocols do not stop at proximitychecking. Instead, they also encompass a unilateral authentication dimension: the
prover authenticates itself to the verifier. Authentication is generally achieved
cryptographically: by using well-established primitives, such as signature schemes,
HMAC, encryption, and others.
G. Avoine et al.
7.1.1 Relay Attacks
A relay attack against two legitimate parties A and B is one whereby a man-in-themiddle C forwards A’s messages to B and/or B’s messages to A, unbeknown to
them. In doing so, C wishes to obtain a facility meant for A and granted by B or
vice-versa. For instance, C could get to fraudulently spend the funds associated with
A’s bank-card at a payment terminal embodied by B.
Relay attacks are hard to detect and deter, as they subvert all conventional
cryptographic mechanisms potentially employed in the protocols: C only forwards
the messages, and does not need to break the cryptography that is used. This is even
more acute in the case of contactless applications: user A simply brings a token (e.g.,
a card or phone) within range of a reader B, and the protocol starts automatically,
with no consent or input by the person who is getting the privilege. Thus, a relay
attack can be mounted without hindrance.
7.1.2 Distance Bounding
The further A is from B, the longer the messages relayed by C from A take to arrive
at B. Hence, imposing an upper-bound on the round-trip times (RTTs) of messageexchanges was proposed as a countermeasure in [83]. This lowers the probability of
successful relay attacks. This mechanism is often referred to as distance bounding
(DB).
The idea of distance-bounding protocols is as follows: a verifier (e.g., an RFID
reader) is equipped in the physical layer with a reliable clock that measures the
RTTs of certain communication exchanges to check that a prover (e.g., a card) is no
further than some allowed distance. So, at some point in the protocol, the verifier
starts its clock, sends a challenge, and stops the clock when it receives the response.
The measured time Δ t corresponds to twice the time it takes for a message to travel
from the prover to the verifier, plus the time taken by the prover to reply. Since no
information can travel faster than the speed of light c, d =
Δ t ·c
2 is an upper bound
on the distance between the prover and the verifier. If the prover was any further
than d, then it would mean that the messages traveled faster than light, which is
impossible. Consequently, if d is short enough, then the verifier can deduce that the
prover is within range. In other words, a time bound B can be a priori fixed such
that, if Δ t > B, then the verifier rejects the prover.
As described above, distance bounding would be just a proximity-checking
mechanism. However, most distance-bounding protocols do not stop at proximitychecking. Instead, they also encompass a unilateral authentication dimension: the
prover authenticates itself to the verifier. Authentication is generally achieved
cryptographically: by using well-established primitives, such as signature schemes,
HMAC, encryption, and others.
