Analog Physical-Layer Relay Attacks with Application to Bluetooth and Phase-Based Ranging

02/14/2022
by   Paul Staat, et al.
0

Today, we use smartphones as multi-purpose devices that communicate with their environment to implement context-aware services, including asset tracking, indoor localization, contact tracing, or access control. As a de-facto standard, Bluetooth is available in virtually every smartphone to provide short-range wireless communication. Importantly, many Bluetooth-driven applications such as Phone as a Key (PaaK) for vehicles and buildings require proximity of legitimate devices, which must be protected against unauthorized access. In earlier access control systems, attackers were able to violate proximity-verification through relay station attacks. However, the vulnerability of Bluetooth against such attacks was yet unclear as existing relay attack strategies are not applicable or can be defeated through wireless distance measurement. In this paper, we design and implement an analog physical-layer relay attack based on low-cost off-the-shelf radio hardware to simultaneously increase the wireless communication range and manipulate distance measurements. Using our setup, we successfully demonstrate relay attacks against Bluetooth-based access control of a car and a smart lock. Further, we show that our attack can arbitrarily manipulate Multi-Carrier Phase-based Ranging (MCPR) while relaying signals over 90 m.

READ FULL TEXT
research
02/22/2022

DEMO: Relay/Replay Attacks on GNSS signals

Global Navigation Satellite Systems (GNSS) are ubiquitously relied upon ...
research
04/24/2019

Security Analysis of Near-Field Communication (NFC) Payments

Near-Field Communication (NFC) is a modern technology for short range co...
research
10/06/2022

EvilScreen Attack: Smart TV Hijacking via Multi-channel Remote Control Mimicry

Modern smart TVs often communicate with their remote controls (including...
research
11/15/2019

Novel Relay Selection Protocol for Cooperative Networks

Extensive research has been done to achieve better throughput and reliab...
research
11/09/2021

Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB Ranging

We present the first over-the-air attack on IEEE 802.15.4z High-Rate Pul...
research
03/25/2020

Analog MIMO RoC Passive Relay for Indoor Deployments of Wireless Networks

Most of the indoor coverage issues arise from network deployments that a...
research
08/10/2020

NFCGate: Opening the Door for NFC Security Research with a Smartphone-Based Toolkit

Near-Field Communication (NFC) is being used in a variety of security-cr...

Please sign up or login with your details

Forgot password? Click here to reset