2 ms·
Yup, but the real problem here is the chosen re-synchronization strategy of the Rolling code when de-sync occurs (performed by the BCM/vehicle) that is done in
by wallaBBB 4y ago
Yup, but the real problem here is the chosen re-synchronization strategy of the Rolling code when de-sync occurs (performed by the BCM/vehicle) that is done in backward. This is described in the article, but most of the comments here seem not to read the details.
Also Honda does offer bidirectional fobs, that make this attacks a lot harder (still not impossible if the same resync strategy is used)
- amluto 4y agoI would argue that both problems are real. Yes, Honda’s resynchronization system is very weak, and a good system would require the owner to actually repeatedly press the button to resync and/or should only ever resync forward. But one-way protocols are also inherently vulnerable to long-range replay attacks if the owner can be convinced to push the bottom near the attacker even if they’re far from the car, and this is not really excusable for a device costing at least $10 (retail) talking to a car that costs thousands of dollars. A microcontroller with a bidirectional radio is cheap. Heck, an NFC device communicating using backscatter modulation that works with no battery is cheap enough for this application. You can find them in disposable subway tickets! What is a bidirectional fob doing resyncing at all? There is absolutely no need for any sort of state in a bidirectional if any reasonable protocol is used. The fob should not even need writable nonvolatile memory.
- wallaBBB 4y ago1) long range replay attack are what is a real issue, and is solved by bi-dir fobs. Only thing keeping them out of the market as a default is price. Issue described in the article is far less of a concern than what you mentioned, I put it in the category of Intel's Spectra - where if you already have such physical access to the device/CPU, there are easier ways... 2) Price - just the MCU is more than 10+ USD. Those MCUs are basically ASICs with a lot of stuff integrated (plus - automotive rating). Precise and stable OCX doesn't come cheap either... 3)There is no single chip solution in the automotive market that would integrate all functions (LF Rx, RF Tx+RX, transponder Rx+Tx). Additionally, RF bi-dir + passive LF is power hungry, and getting a year out of your standard CR2032 forget about it - so a more expensive power source needs to be used... 4)NFC is basically just only one of the aforementioned functions - similar to transponder Rx+Tx. 5) Oh it needs writable nonvolatile memory for a lot of reasons... - configuration to cover different vehicle/market/protocol variants, DTC, Secret Keys for pairing, unless you want your fob replacement price to skyrocket... Regarding fob price - keep in mind it's not just the electronics, although automotive MCUs have harder requirements to satisfy (op. range of temperature, voltage, very low quiescent current, very low ppm failures). Mechanics are expensive, although deceiving when you look at them. Keep in mind they go through some pretty nasty tests - including (and I kid you not) a washing machine test - basically testing if it will survive a washing machine.