10
M. Kutyłowski et al.
Device cannot access the communication channel without help from the Watchdog.
Consequently, it does not know Enc z (z).
For the adversary, the situation is just the opposite: it has access to Enc z (z), but
it does not know z and cannot learn it from the colluding Device, as there is no
communication channel between them.
1.2.3.5 Distance Bounding Protocols
A distance bounding protocol [112] is executed when the physical presence of the
Device in a close proximity of the Reader needs to be verified. This is particularly
important in scenarios concerning access control in the presence of hardware tokens.
By utilizing the timing delays between sending out a challenge bit and receiving a
response, the Reader can calculate an upper bound on the distance to the verified
device, and, if the Device is outside the intended perimeter, abandon the protocol.
The main and most problematic part in distance bounding protocols is the Rapid
Bit Exchange (RBE) phase that is key to calculating the distance based on the
response time. Typically, it is executed by a Device and a Reader as follows:
1. the Device and the Reader share m-bit strings r 0 and r 1 (computed from a shared
secret and a nonce transmitted in clear),
2. for i = 1, . . . , m, the following steps are executed:
(a) the Reader sends a pseudorandom bit c[i],
(b) the Device responds immediately with r c[i] [i].
3. The Reader aborts the protocol if the answers of the Device have not been
obtained within (strict) time limits or not all of them are correct.
The RBE phase is potentially a source of problems:
• The Device can send bits different from r c[i] [i] just to create a covert channel.
Incorrect responses might be interpreted not as malicious activity of the Device,
but as an attempt by an adversary standing between the Device and the Reader to
cheat about the distance.
• Convincing the Watchdog about the correctness of the responses is a challenge:
during the RBE phase there is no time for exchange of messages between the
Device and the Watchdog and for nontrivial computations.
The solution presented below is based on blinding the responses with a one-time
pad, where the random key is transported via the Device to the Watchdog in a secure
way. It consists of the three phases described below:
PREPARATION: During this phase a blinding string is prepared. Namely, a
session key z shared between the Watchdog and the Reader
is established, as described in Sect. 1.2.3.4. However, instead
of using it for encapsulation of messages it is used as a seed
for creating a pseudorandom bit string B(z).
Précédent

- 25/268

Suivant