7 From Relay Attacks to Distance-Bounding Protocols
117
7.2.2 Advanced Relay Strategies
The relay attacks above were executed on systems that implemented no proximity checks. As systems start to implement such checks over conventional lowbandwidth communication channels there are practical strategies for gaining time
that can hide the relay delay. Even if the attacker can gain part of a bit period,
e.g., a few microseconds, it could leave enough time to mount one of the attacks in
Sect. 7.2.1.
7.2.2.1 Early Send and Late Commit
If the attacker can send a challenge or response late but still get the prover or verifier
to accept it as a valid message then that could also hide the relay delay. Receivers
do not evaluate the bit value right at the beginning of the bit period T B . To make
the channel more reliable this evaluation is done later, in the middle or at the end of
the bit period, which could be exploited to gain the attacker some time [149, 255].
For example, for NRZ (non-return to zero) coding the signal is high for the entire
bit period for ‘1’ and low for the entire bit period for ‘0’, and the receiver samples
only once in the middle of the bit period to determine the bit value, as shown in
Fig. 7.1a. This means the attacker could start his response bit up to T A = T B /2 late,
and still have the bit sampled correctly. Several receiver architectures, to be resistant
to noise, integrate the signal across the entire bit period and evaluate the bit value at
the end. In this case, the attack could ‘late commit’ by transmitting a larger, shorter
signal later in the bit period and still achieve the same integration output at the time
of bit value evaluation. If combined with early send, where the attacker guesses the
value based on the observation of the first part of the bit period, the attack in Fig. 7.2
becomes possible. The attacker will guess the value of challenge C i from the verifier
early, and send it to the prover late. It will repeat this approach for the response R i
Fig. 7.1 Gaining attack time by exploiting channel characteristics. (a) Late commit for non-return
to zero (NRZ) coding. (b) Speeding up Manchester code data clock [255]: Sampling clock is 8×
time data clock (trigger and synchronization counter for sampling signal transition shown)
Précédent

- 128/268

Suivant