7 From Relay Attacks to Distance-Bounding Protocols
115
7.1.3 Other Relay-Countermeasures
Approaches to relay-counteraction other than distance bounding have been proposed. In his seminal paper [178], Desmedt proposed that a prover computed his
exact location on earth, signed it, and sent it to the verifier. The inconvenience in
this approach is that it requires one to trust the prover not to cheat. In addition,
it requires a safe localization system, which is not trivial to realize. In particular,
using the GPS technology does not seem to be a robust solution [242] due to the
fact that the GPS signal is sensitive to obstacles and not accurate enough. In [133],
position-based cryptography is further studied and proven to be impossible.
Another option against relay attacks is to measure the strength of the signal
received by the verifier [347]: since it decreases as the distance increases, it gives
indications about the distance from the prover. However, an attacker can amplify the
signal to make the prover appear closer to the verifier, and defeat this approach.
Similarly, a solution based on sensing the local environment (for instance the air
temperature) was proposed, with the idea that if the prover was actually close to
the verifier, then it would sense similar values [561]. This approach however fails
if the adversary is able to manipulate the value that is being sensed, which can be
relatively easy to do.
To prevent relay attacks, one can also isolate the prover inside a Faraday cage [74]
during the protocol, to make sure that it cannot communicate with external entities.
While efficient, this solution is not very user friendly, and severely limits the
usability of the system.
Finally, radio frequency fingerprinting [496] can be used. It identifies the devices
based on variations in the signal features due to imperfections in the manufacturing
process. However, such fingerprinting can be counterfeited [168].
Comparing all the aforementioned relay-countermeasures, distance bounding
appears the most promising option to defeat relay attacks.
7.2 Relay Attacks in Practice
Relay attacks have been implemented against contact-based smart cards [189],
contactless smart cards [256], and keyless car entry systems [221]. First, in
Sect. 7.2.1, we discuss attacks against “unprotected systems”. Then, in Sect. 7.2.2,
taking into consideration the fact that distance-bounding type countermeasures are
starting to be implemented, we consider more advanced practical relay strategies
against systems thus “protected”.
115
7.1.3 Other Relay-Countermeasures
Approaches to relay-counteraction other than distance bounding have been proposed. In his seminal paper [178], Desmedt proposed that a prover computed his
exact location on earth, signed it, and sent it to the verifier. The inconvenience in
this approach is that it requires one to trust the prover not to cheat. In addition,
it requires a safe localization system, which is not trivial to realize. In particular,
using the GPS technology does not seem to be a robust solution [242] due to the
fact that the GPS signal is sensitive to obstacles and not accurate enough. In [133],
position-based cryptography is further studied and proven to be impossible.
Another option against relay attacks is to measure the strength of the signal
received by the verifier [347]: since it decreases as the distance increases, it gives
indications about the distance from the prover. However, an attacker can amplify the
signal to make the prover appear closer to the verifier, and defeat this approach.
Similarly, a solution based on sensing the local environment (for instance the air
temperature) was proposed, with the idea that if the prover was actually close to
the verifier, then it would sense similar values [561]. This approach however fails
if the adversary is able to manipulate the value that is being sensed, which can be
relatively easy to do.
To prevent relay attacks, one can also isolate the prover inside a Faraday cage [74]
during the protocol, to make sure that it cannot communicate with external entities.
While efficient, this solution is not very user friendly, and severely limits the
usability of the system.
Finally, radio frequency fingerprinting [496] can be used. It identifies the devices
based on variations in the signal features due to imperfections in the manufacturing
process. However, such fingerprinting can be counterfeited [168].
Comparing all the aforementioned relay-countermeasures, distance bounding
appears the most promising option to defeat relay attacks.
7.2 Relay Attacks in Practice
Relay attacks have been implemented against contact-based smart cards [189],
contactless smart cards [256], and keyless car entry systems [221]. First, in
Sect. 7.2.1, we discuss attacks against “unprotected systems”. Then, in Sect. 7.2.2,
taking into consideration the fact that distance-bounding type countermeasures are
starting to be implemented, we consider more advanced practical relay strategies
against systems thus “protected”.
