Lohan, Alén-Savikko, Chen, Järvinen, Leppäkoski, Kuusniemi, and Korpisaari
302
Because signals cannot travel faster than light, the distance between P and V is at
most d = tc/2, where t = max(t i ) and c is the speed of light. In the end, P opens the commitment by sending a, b and m to V (signed with P’s secret key using a secure digital
signature scheme to ensure integrity and authenticity). V accepts d as the maximum
distance if m matches the commitment and the signature is valid. The fact that b i
depends on a i prevents P from sending b i before it has received a i , the commitment to
m prevents P from fabricating an appropriate m’ afterwards, and the signature prevents an imposter P’ from acting as P. The above distance‐bounding protocol is
depicted in Figure 13.7.
The distance‐bounding is very sensitive to processing delays. The delay t = t s + t p ,
where t s is the time that the signal travels from V to P and back and t p is the time spent
in processing (e.g. computing the xor and delays in radio transceivers). The distance‐
bounding protocol gives meaningful results only if t s > > t p . The signal travels at about
30 cm in one nanosecond, so a very small t p is needed in order to ensure the accuracy
required by 5G. This forms major challenges for implementing accurate distance‐
bounding protocols and requires specific hardware solutions [5].
Distance‐bounding provides only the distance between two entities, but triangulation
allows several (mutually trusted) verifiers to derive the exact position of P (see, for
example [102]). Distance‐bounding can be also integrated into cryptographic user
authentication protocols and it is a central part also in securing cooperative positioning
systems where peers locate each other without trusted parties [102]. Cryptographic
distance‐bounding could complement the techniques discussed in Section 13.2 by preventing, for example, various man‐in‐the‐middle attacks.
Verifier V
Prover P
Repeat for i = l, ..., k
Physical distance d p
Select k random bits a i
Transmit the bit a i
Measure time t
i
Receive the bit b i
Commit to m i
Select k random bits m i
Receive the bit a i
Compute b i = a i xor m i
Transmit the bit b i
Open commitment
Compute sign(a,b,m)
Verify commitment
Verify sign(a,b,m)
d p < max(t i ) c/2
Figure 13.7 Brands and Chaum’s distance‐bounding protocol [101].
Précédent

- 344/483

Suivant