7 From Relay Attacks to Distance-Bounding Protocols
127
7.5.2 3DB Technology
3DB Access AG is a Swiss company founded in 2013, by Boris Danev and David
Barras. 3DB developed an integrated circuit that contains a distance-bounding
protocol based on Ultra-Wide Band (UWB) pulses compliant to IEEE 802.15.4f.
The technology allows a reader to estimate the distance to reach a given contactless
receiver. It aims to avoid mafia-fraud attacks, but it does not consider the other frauds
presented in Sect. 7.4 (e.g., it does not consider distance fraud). The distance range
is 120 meters (line of sight) and the accuracy of the distance-bounding protocol is
10 cm according to the product’s datasheet. 2 The 3DB technology specifically (but
not only) targets the market of keyless entry and start systems (PKES), given that
such systems are particularly vulnerable to relay attacks [221]. It is likely that most
vehicles will be equipped with such a DB-friendly PKES in the future.
The protocol implemented in the 3DB technology, described in [531], is based on
the Brands-Chaum protocol [113]. However, it takes the channel characteristics into
account and includes countermeasures to thwart physical-layer attacks, in particular
the “early detect and late commit” attack described in Sect. 7.2 that is mitigated
since the basic symbol pulses have a very short period. These countermeasures rely
on the reordering and blinding of the pulses. The reordering consists in applying
a permutation to the pulse positions associated with each bit. The number of bits
considered in the pulse reordering is actually an adjustable security parameter. The
blinding consists in XORing the stream of pulses with a mask. The cryptographic
primitives used to generate the permutation and the mask are not described. No
attack has been suggested so far on these reordering and blinding techniques. Apart
from security properties, UWB channels can also provide very accurate time-ofarrival measurement as the timing resolution achievable with a signal of bandwidth
B, is 1/2B.
7.5.3 Relay-Resistance in EMV
Relay attacks are particularly relevant in contactless-payment systems. Indeed,
no PIN code or other payee-originating input is requested with such payments.
Moreover, most contactless payment cards rely on ISO 14443, which is a standard
available in most of today’s smartphones. Consequently, performing a relay attack
between a payment terminal and a payment card is as simple as uploading an app
on a smartphone [567].
Indeed, using off-the-shelf smartphones and some in-house Android software,
this relay threat was exhibited in practice by Chothia et al. [141] against the EMV
(Europay, Mastercard and Visa) contactless-payment protocol; this is the most wide2 Available at the 3DB Access AG Website, https://www.3db-access.com/, May 2018.
Précédent

- 138/268

Suivant