Analog Physical-Layer Relay Attacks with Application to Bluetooth and Phase-Based Ranging

8Citations
Citations of this article
19Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Today, we use smartphones as multi-purpose devices that communicate with their environment to implement context-aware services, including asset tracking, indoor localization, contact tracing, or access control. As a de-facto standard, Bluetooth is available in virtually every smartphone to provide short-range wireless communication. Importantly, many Bluetooth-driven applications such as Phone as a Key (PaaK) for vehicles and buildings require proximity of legitimate devices, which must be protected against unauthorized access. In earlier access control systems, attackers were able to violate proximity-verification through relay station attacks. However, the vulnerability of Bluetooth against such attacks was yet unclear as existing relay attack strategies are not applicable or can be defeated through wireless distance measurement. In this paper, we design and implement an analog physical-layer relay attack based on low-cost off-the-shelf radio hardware to simultaneously increase the wireless communication range and manipulate distance measurements. Using our setup, we successfully demonstrate relay attacks against Bluetooth-based access control of a car (Tesla Model 3) and a smart lock (Nuki Smart Lock 2.0). Further, we show that our attack can arbitrarily manipulate Multi-Carrier Phase-based Ranging (MCPR) while relaying signals over 90 m.

Cite

CITATION STYLE

APA

Staat, P., Jansen, K., Zenger, C., Elders-Boll, H., & Paar, C. (2022). Analog Physical-Layer Relay Attacks with Application to Bluetooth and Phase-Based Ranging. In WiSec 2022 - Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks (pp. 60–72). Association for Computing Machinery, Inc. https://doi.org/10.1145/3507657.3528536

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free