7 From Relay Attacks to Distance-Bounding Protocols
125
7.4.2.3 Provably-(in)Secure Protocols
Designing a distance-bounding protocol that is both efficient and provably-secure
has proved a difficult task.
For instance, the Hancke-Kuhn scheme presented in Sect. 7.3 only provides suboptimal mafia-fraud resistance (3/4 per round as opposed to the optimal 1/2);
in addition, it is vulnerable to distance frauds by PRF-programming. Striving for
optimal mafia- and distance-fraud resistance, Avoine and Tchamkerten [45] describe
a scheme in which the proximity-check responses are inter-dependent: this strategy
makes the per-round mafia-fraud security asymptotically approach the optimal
bound of 1/2, but fails to thwart PRF-programming strategies. By combining a
late authentication like Brands-Chaum and two pseudorandom response registers
like Hancke-Kuhn, Kim et al. attempted to achieve optimal mafia- and distancefraud resistance, as well as terrorist-fraud resistance [328]. However, its design
includes a circularity in the use of the key which does not allow provable mafiafraud resistance; in addition, its use of PRFs is problematic with respect to achieving
distance-fraud resistance.
Protocols that provably guarantee the four properties described above are rare in
the literature [40, 114]. The SKI protocols [110] introduced a new countermeasure
to terrorist fraud by using a leakage function. This design is further refined and
made efficient by Boureanu and Vaudenay [111, 325]. A recent protocol called
SPADE [118] circumvents PRF-programming attacks by using one-time keys
during the proximity-checking phase; in that case, terrorist-fraud resistance is
achieved by adding in a backdoor. An extended family of protocols using the same
basic designs was proposed in [42]; it can be instantiated with various primitives,
achieving different degrees of provable security and privacy.
The reader is referred to extensive distance-bounding surveys, such as [40, 114].
7.5 Distance-Bounding Protocols in Practice
7.5.1 NXP’s Mifare Technology
NXP is a world-wide semiconductor supplier especially involved in secure identification, automotive and digital networking industries. Mifare is a series of NXP’s
contactless products that includes four families, namely Classic, Plus, Ultralight,
and DESFire. Mifare Plus (X and EV1) as well as Mifare DESFire (EV2) benefit
from a distance-bounding protocol [445, 446]. Note that the DB protocols are not
activated by default on these cards, and the data sheets do not explain how the system
operator should evaluate the value of the round-trip time upper bound.
Although the protocols have not been publicly released, it is worth noting that
NXP published several patents on distance-bounding protocols. Figure 7.5 depicts
the protocol described in [303, 553]. In contrast to most DB protocols available in
125
7.4.2.3 Provably-(in)Secure Protocols
Designing a distance-bounding protocol that is both efficient and provably-secure
has proved a difficult task.
For instance, the Hancke-Kuhn scheme presented in Sect. 7.3 only provides suboptimal mafia-fraud resistance (3/4 per round as opposed to the optimal 1/2);
in addition, it is vulnerable to distance frauds by PRF-programming. Striving for
optimal mafia- and distance-fraud resistance, Avoine and Tchamkerten [45] describe
a scheme in which the proximity-check responses are inter-dependent: this strategy
makes the per-round mafia-fraud security asymptotically approach the optimal
bound of 1/2, but fails to thwart PRF-programming strategies. By combining a
late authentication like Brands-Chaum and two pseudorandom response registers
like Hancke-Kuhn, Kim et al. attempted to achieve optimal mafia- and distancefraud resistance, as well as terrorist-fraud resistance [328]. However, its design
includes a circularity in the use of the key which does not allow provable mafiafraud resistance; in addition, its use of PRFs is problematic with respect to achieving
distance-fraud resistance.
Protocols that provably guarantee the four properties described above are rare in
the literature [40, 114]. The SKI protocols [110] introduced a new countermeasure
to terrorist fraud by using a leakage function. This design is further refined and
made efficient by Boureanu and Vaudenay [111, 325]. A recent protocol called
SPADE [118] circumvents PRF-programming attacks by using one-time keys
during the proximity-checking phase; in that case, terrorist-fraud resistance is
achieved by adding in a backdoor. An extended family of protocols using the same
basic designs was proposed in [42]; it can be instantiated with various primitives,
achieving different degrees of provable security and privacy.
The reader is referred to extensive distance-bounding surveys, such as [40, 114].
7.5 Distance-Bounding Protocols in Practice
7.5.1 NXP’s Mifare Technology
NXP is a world-wide semiconductor supplier especially involved in secure identification, automotive and digital networking industries. Mifare is a series of NXP’s
contactless products that includes four families, namely Classic, Plus, Ultralight,
and DESFire. Mifare Plus (X and EV1) as well as Mifare DESFire (EV2) benefit
from a distance-bounding protocol [445, 446]. Note that the DB protocols are not
activated by default on these cards, and the data sheets do not explain how the system
operator should evaluate the value of the round-trip time upper bound.
Although the protocols have not been publicly released, it is worth noting that
NXP published several patents on distance-bounding protocols. Figure 7.5 depicts
the protocol described in [303, 553]. In contrast to most DB protocols available in
