7 From Relay Attacks to Distance-Bounding Protocols
121
verifier. This allows the adversary to establish two sessions (one with the prover,
the other, with the verifier) which share the same response strings R 0 and R 1 . This
adversary can now use its session with the prover to extract data: before it receives
the honest verifier’s challenge, the adversary can query the prover with any kind of
request. If the protocol were to rely on only one response string, the adversary could
obtain the entire response and forward it to the attacker.
7.3.3 The Brands-Chaum Protocol
The public-key counterpart of the Hancke-Kuhn protocol was proposed by Brands
and Chaum [113] and relies on commitment schemes and digital signatures.
Commitment schemes allow users to temporarily hide a value; the commitment will
also only open to that hidden value, and not to any other. Signature schemes are
public-key primitives allowing a signer to generate signatures for a given message
and a secret key; the signature can be verified for that message with the public key.
Figure 7.4 depicts an execution of the Brands-Chaum protocol. The session setup and verification consist of one-message rounds each. During set-up, the prover
chooses and commits (in a message C) to a number of responses to be used at
proximity checking. Note that C hides the contents of the message, from both an
attacker and the verifier. In each round of the proximity-checking phase the verifier
picks a one-bit random challenge c i and sends it to P. The latter’s response is
c i ⊕ r i , where r i is the response bit to which the prover committed for this round.
The values R i and the measured RTT values are stored by the verifier. Finally, during
verification, P sends to V the opening of the commitment C and a signature on the
concatenated challenge and response values exchanged at proximity-checking. The
Fig. 7.4 The Brands–Chaum protocol for a prover P and a verifier V
121
verifier. This allows the adversary to establish two sessions (one with the prover,
the other, with the verifier) which share the same response strings R 0 and R 1 . This
adversary can now use its session with the prover to extract data: before it receives
the honest verifier’s challenge, the adversary can query the prover with any kind of
request. If the protocol were to rely on only one response string, the adversary could
obtain the entire response and forward it to the attacker.
7.3.3 The Brands-Chaum Protocol
The public-key counterpart of the Hancke-Kuhn protocol was proposed by Brands
and Chaum [113] and relies on commitment schemes and digital signatures.
Commitment schemes allow users to temporarily hide a value; the commitment will
also only open to that hidden value, and not to any other. Signature schemes are
public-key primitives allowing a signer to generate signatures for a given message
and a secret key; the signature can be verified for that message with the public key.
Figure 7.4 depicts an execution of the Brands-Chaum protocol. The session setup and verification consist of one-message rounds each. During set-up, the prover
chooses and commits (in a message C) to a number of responses to be used at
proximity checking. Note that C hides the contents of the message, from both an
attacker and the verifier. In each round of the proximity-checking phase the verifier
picks a one-bit random challenge c i and sends it to P. The latter’s response is
c i ⊕ r i , where r i is the response bit to which the prover committed for this round.
The values R i and the measured RTT values are stored by the verifier. Finally, during
verification, P sends to V the opening of the commitment C and a signature on the
concatenated challenge and response values exchanged at proximity-checking. The
Fig. 7.4 The Brands–Chaum protocol for a prover P and a verifier V
