122
G. Avoine et al.
verifier retrieves the randomly-chosen r i values from C and uses them to ascertain
the validity of the prover’s time-critical responses and the signature σ and R i values.
If these values verify and the measured RTTs are below the t max bound, then the
verifier authenticates the prover.
Design Intuition The commitment serves a dual purpose: it hides the values of
r i until they become useless to the attacker (i.e., until after the proximity-checking
rounds); and the commitment compensates for the fact that the response values are
chosen entirely by the prover. Finally, the commitment allows the verifier to retrieve
the r i values without exchanging or sharing any further keys with the prover. The
commitment, however, does not authenticate P; that is achieved by the signature
σ . The signature also effectively prevents pre-ask strategies during the proximitychecking phase.
7.4 Distance-Bounding Threat Model and Its Formal
Treatments
In this section, we present the main threats in distance bounding, and the state
of formal security analysis in this field. We also review more recent protocols,
comparing their advantages and disadvantages.
7.4.1 Main Threat-Model
Distance-bounding schemes are vulnerable to attacks other than relaying, issued out
of the proximity-checking measure. For instance, any attack that makes the prover
appear closer than it actually is defeats the purpose of a distance-bounding protocol,
which is to compute a correct upper bound on this distance. The threats we present
can be classified as attacks by outsiders and attacks by insiders. In the first category
lies mafia fraud, where an unauthorized adversary attempts to be accepted by the
verifier. In the second, comprising distance fraud, distance hijacking and terrorist
fraud, a faraway dishonest prover attempts to be accepted by the verifier despite his
distance.
7.4.1.1 Mafia Fraud (MF) [178]
In mafia fraud, an adversary A authenticates in the presence of a far-away honest
prover. A mafia fraud typically involves a faraway prover, and two collaborating
adversaries: one near the prover, and one near the verifier. The fraud succeeds if
the authentication of the adversary located close to the verifier is accepted by the
verifier.
G. Avoine et al.
verifier retrieves the randomly-chosen r i values from C and uses them to ascertain
the validity of the prover’s time-critical responses and the signature σ and R i values.
If these values verify and the measured RTTs are below the t max bound, then the
verifier authenticates the prover.
Design Intuition The commitment serves a dual purpose: it hides the values of
r i until they become useless to the attacker (i.e., until after the proximity-checking
rounds); and the commitment compensates for the fact that the response values are
chosen entirely by the prover. Finally, the commitment allows the verifier to retrieve
the r i values without exchanging or sharing any further keys with the prover. The
commitment, however, does not authenticate P; that is achieved by the signature
σ . The signature also effectively prevents pre-ask strategies during the proximitychecking phase.
7.4 Distance-Bounding Threat Model and Its Formal
Treatments
In this section, we present the main threats in distance bounding, and the state
of formal security analysis in this field. We also review more recent protocols,
comparing their advantages and disadvantages.
7.4.1 Main Threat-Model
Distance-bounding schemes are vulnerable to attacks other than relaying, issued out
of the proximity-checking measure. For instance, any attack that makes the prover
appear closer than it actually is defeats the purpose of a distance-bounding protocol,
which is to compute a correct upper bound on this distance. The threats we present
can be classified as attacks by outsiders and attacks by insiders. In the first category
lies mafia fraud, where an unauthorized adversary attempts to be accepted by the
verifier. In the second, comprising distance fraud, distance hijacking and terrorist
fraud, a faraway dishonest prover attempts to be accepted by the verifier despite his
distance.
7.4.1.1 Mafia Fraud (MF) [178]
In mafia fraud, an adversary A authenticates in the presence of a far-away honest
prover. A mafia fraud typically involves a faraway prover, and two collaborating
adversaries: one near the prover, and one near the verifier. The fraud succeeds if
the authentication of the adversary located close to the verifier is accepted by the
verifier.
