3 ms·
>The essential problem is that static credentials are transmitted and can be copied. If they used a randomly generated code to unlock the cars (needs to be gene
by _iyig 7y ago
>The essential problem is that static credentials are transmitted and can be copied. If they used a randomly generated code to unlock the cars (needs to be generated offline) then that would solve this issue.
Not necessarily. Relay attacks are very hard to defeat, regardless of your crypto scheme:
https://www.wired.com/2017/04/just-pair-11-radio-gadgets-can-steal-car/ https://www.wired.com/2017/04/just-pair-11-radio-gadgets-can...
- chapium 7y agoDoesn't this require the attacker to have the keys?
- tialaramex 7y agoThe relay attack (which is not what this article is about) relies on an erroneous idea in the design of keyless entry and keyless ignition systems. Signals from an RFID device don't travel very far. So, (here's the error) if the keys can receive and respond to a signal from the car they must be very close to the car. But signals can be relayed. Crook A stands next to your car. Crook B walks up to your front door. Crook B is relying on the fact that most people leave their car keys on a key hook, or in a bowl, or maybe even in their outside jacket, which they leave by the door because that's convenient. You have done this. The car is sending radio pulses. "Hey, are you my key?". Crook A has a relay transceiver, it doesn't need to understand this pulse, just relay it to Crook B. Crook B has another transceiver, and when it says "Hey, are you my key?" the key, on the far side of a locked front door, says "Yes! I'm the right key, see! 023483109" and Crook B's transceiver sends that right back to Crook A. "Yes! I'm the right key, see! 023483109" the one-time code from the key matches, the car unlocks. Crook A gets into the car and starts it. Crook B walks over and gets into the passenger seat. In a few seconds the car will discover that the key, which was apparently right there, has somehow vanished. But for safety reasons it is unsafe to suddenly lock everything and shut off. The thieves will ensure that by the time it decides it would be safe to lock itself, it's inside a chop shop and that's too late. So no, the attacker doesn't "have" the key, they just need to be able to stand relatively close to it.
- deleted 7y ago[deleted]
- chapium 7y agoI think what I am unclear about is how the crook gets the signal. Is it as simple as recording it once and using it again later? Does they key change between uses? Otherwise the attack seems arbitrary. If my key keeping bowl at home physical security is compromised I have someone in my house. I generally dont leave my keys out anyway, but a nefarious plumber/home contractor could potentially gain access.
- jeroenhd 7y agoShouldn't relay attacks be preventable by having the car inspect the timing of the response? A signal that needs to be received, reprocessed, transmitted, reprocessed again and then retransmitted should have a noticeable difference in timing, shouldn't it? Is there any reason a challenge/response protocol with proper timing filtering isn't safe against relay attacks?
- yc-kraln 7y agoCurrently working in the Car industry, previously in the access control industry (and have developed active RFID systems which include timing information to prevent relay attacks) Yes, you can do this. I have done this (restricted the negotiation to about 12 meters)--you're essentially racing the speed of light, see DE102012104955A1. Most of the reasonable approaches are patented by NXP.
- jeroenhd 7y agoI see, very interesting! I could've figured someone would patent something like this. Thank you for explaining.