EP3430764A1 - Verfahren zum erzeugen einer authentifizierungsnachricht, verfahren zum authentifizieren, authentifizierungsgerät und authentifizierungsbasisgerät - Google Patents
Verfahren zum erzeugen einer authentifizierungsnachricht, verfahren zum authentifizieren, authentifizierungsgerät und authentifizierungsbasisgerätInfo
- Publication number
- EP3430764A1 EP3430764A1 EP17703363.6A EP17703363A EP3430764A1 EP 3430764 A1 EP3430764 A1 EP 3430764A1 EP 17703363 A EP17703363 A EP 17703363A EP 3430764 A1 EP3430764 A1 EP 3430764A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- message
- authentication
- key sequence
- initialization
- initialization message
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3234—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B60—VEHICLES IN GENERAL
- B60R—VEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
- B60R25/00—Fittings or systems for preventing or indicating unauthorised use or theft of vehicles
- B60R25/20—Means to switch the anti-theft system on or off
- B60R25/24—Means to switch the anti-theft system on or off using electronic identifiers containing a code not memorised by the user
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07C—TIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
- G07C9/00—Individual registration on entry or exit
- G07C9/00174—Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys
- G07C9/00309—Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0478—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload applying multiple layers of encryption, e.g. nested tunnels or encrypting the content with a first key and then with at least a second key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
- H04L9/065—Encryption by serially and continuously modifying data stream elements, e.g. stream cipher systems, RC4, SEAL or A5/3
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3271—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B60—VEHICLES IN GENERAL
- B60R—VEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
- B60R2325/00—Indexing scheme relating to vehicle anti-theft devices
- B60R2325/10—Communication protocols, communication systems of vehicle anti-theft devices
- B60R2325/108—Encryption
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07C—TIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
- G07C9/00—Individual registration on entry or exit
- G07C9/00174—Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys
- G07C9/00309—Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks
- G07C2009/00412—Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks the transmitted data signal being encrypted
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/84—Vehicles
Definitions
- Embodiments are concerned with methods for generating an authentication message and methods of authentication used, for example, to check whether a user of an authentication device is authorized to use an item or service.
- the so-called cryptographic locating serves the localized authentication of a person or an object. This can be done by means of a person attached to the object or mobile radio transceiver or an authentication device that responds to a radio query of (fixed) radio technology or from an authentication base device or even initiates a radio query with this wireless infrastructure. For authentication, the authentication device encrypts a message, which it then transmits to the base authentication device. In the more specific case of cryptographic distance measurement, there is an additional limitation of the spatial communication range.
- the encryption can, among other things, ensure the privacy of the authenticated as well as the unauthenticated user. Furthermore, encryption may effectively restrict the access rights or rights to use an item or service to potential attackers.
- Such systems are used for example in car keys to open the doors of the vehicle only for an authorized user with corresponding authentication device or to start the vehicle engine.
- One possibility for attacking such systems is the so-called relay attack, in which the attacker amplifies and forwards the signals between the infrastructure and the mobile transceiver. Distance restriction may attempt to exclude such an attacker.
- so-called “Time of Flighf” measurements can be used (also called Two Way Ranging or Round Trip Time), which evaluate the signal propagation times between the basic authentication device and the authentication device.
- Another possibility of an attack is to crack the encryption of the authentication device and thus be able to answer a radio request of the authentication base device or an initialization message contained therein instead of the authentication device and thus have authorization to use the authentication device pretend secured infrastructure.
- Such an attack could only be prevented to a limited extent by "time of flight.”
- the length of the key sequence used is limited due to limited hardware or power supply, such as in the car keys already mentioned, such attacks can be realized Need to improve existing authentication methods.
- Embodiments of a method for generating an authentication message include receiving a sent initialization message and encrypting the sent initialization message using a first cryptographic method to generate an intermediate message.
- This intermediate message is encrypted by means of a second cryptographic method in order to obtain the authentication message which is used to check in an authentication base device which has generated the sent initialization message whether the authentication message is regarded as authenticating and thus a sender of the authentication.
- authorization message is authorized.
- the two-time encryption with different cryptographic methods significantly hampers or even obscures the communication and spying out the encryption algorithm used to generate the authentication message and the encryption sequence used impossible.
- Embodiments of a method for authentication include sending an initialization message, which for example is processed by an authentication device will be used to create an authentication message. This authentication message is received and the authentication message decrypted using the second cryptographic method also used in the generation thereof to obtain a received intermediate message. Decrypting the received intermediate message using a first cryptographic method generates a received initialization message. A comparison of the received initialization message and the sent initialization message is made to determine if the authentication message is considered authenticating. As with the generation of the authentication message, the successive application of the two cryptographic methods used to evaluate the authentication message takes place in order to ensure the high security of the method.
- Embodiments of an authentication device include a receiver configured to receive an initialization message and a first encryption module configured to encrypt the received initialization message using a first cryptographic method to obtain an intermediate message.
- a second encryption module is configured to encrypt the intermediate message using a second cryptographic method to obtain the authentication message.
- a sender serves to send the authentication message.
- An embodiment of an authentication base device for communicating with the authentication device comprises a transmitter that is configured to send an initialization message and a receiver that is configured to receive an authentication message.
- a first decryption module is configured to decrypt the authentication message using a second cryptographic method to obtain a received intermediate message.
- a second decryption module is configured to decrypt the received intermediate message using a first cryptographic method to obtain a received initialization message.
- a decision module configured to compare the received initialization message and the sent initialization message to determine whether the authentication device is considered authenticated.
- 1 is a flow chart of an embodiment of a method for generating an authentication message
- FIG. 2 shows a flow diagram of an embodiment of a method for authenticating
- 3 is a block diagram of one embodiment of an authentication device for use with analog waveforms
- 4 is a block diagram of another embodiment of an authentication device for use with analog waveforms
- Fig. 5 is a block diagram of one embodiment of an authentication device for use with digital signals
- Fig. 6 is a block diagram of another embodiment of an authentication device for use with digital signals
- Fig. 7 is a block diagram of an embodiment of an authentication base device.
- Fig. 8 shows an implementation of an embodiment for opening a motor vehicle.
- an infrastructure can include, for example, any devices which are protected against unauthorized use by means of the authentication base device, for example motor vehicles, construction machines, tools or the like.
- a service may be, for example, the free or paid service of a third party or may include authentication to a computer system or special software.
- the method for generating an authentication message comprises receiving a sent initialization message 102. Encrypting the received initialization message 104 using a first cryptographic method generates an intermediate message.
- This intermediate message is encrypted by a second cryptographic method to obtain the authentication message used to check in an authentication base device that generated the sent initialization message 104 whether the authentication message is considered authenticating and thus a sender the authentication message is authorized.
- a second cryptographic method to obtain the authentication message used to check in an authentication base device that generated the sent initialization message 104 whether the authentication message is considered authenticating and thus a sender the authentication message is authorized.
- a cryptographic method is defined in particular by the algorithm which is used to encrypt the sent initialization message by means of a key sequence. Depending on whether the encryption is digital or analog, this can be implemented by a different calculation rule or by different hardware components that combine the sent initialization message and the key sequence. Examples of analog and digital implementations are shown in Figs. 3-6. In these implementations, as used cryptographic methods, adding the key sequence to the message to be encrypted and multiplying the key sequence by the message to be encrypted are combined, as will be explained with reference to the figures.
- FIG. 2 shows a flow diagram of an embodiment of a method for authenticating, comprising sending an initialization message 202, which is processed, for example, by an authentication device in order to generate an authentication message.
- the authentication message is received in method step 204.
- the authentication message is decrypted using the second cryptographic method also used in the generation thereof to obtain a received intermediate message.
- the received intermediate message is decrypted using a first cryptographic method to obtain a received initialization message.
- the received initialization message and the sent initialization message (the original, originally generated, and additionally reserved initialization message) are compared to determine whether the authentication message is considered authenticating.
- the authentication is judged to be successful if the received initialization message and the sent initialization message correspond to each other, which in some embodiments is particularly the case if both messages differ by less than an allowable number of bits. This correspondence or agreement may be be be evaluated by means of another arbitrarily set threshold value.
- the key sequences used in the method of authentication and the method of generating an authentication message may be identical if symmetric encryption is used, or may be mutually corresponding public and private key sequences if asymmetric encryption is used.
- a signal delay is determined between the transmission of the initialization message and the receipt of the authentication message.
- the authentication is evaluated as successful only if the signal propagation time is less than a predetermined threshold so as to better detect, for example, remote relay attacks.
- FIG. 3 schematically shows an exemplary embodiment of an authentication device 300.
- the cryptographic methods used are implemented analogously; an analog to digital conversion of the received initialization message can thus be omitted. Nonetheless, possible digital generation of the key sequences cl (t) and c2 (t) including a digital-to-analogue conversion as well as digital signal detection, synchronization and power estimation are outside the direct signal chain implementing both cryptographic methods.
- the sent initialization message 303 is received.
- a signal analyzer 304 a signal & power detection as well as the synchronization to the received signal, in particular to the sent Initialmaschinesnachricht 303, which is further processed as an analog waveform.
- a signal & power detection can be based, for example, on a signal preceding the transmitted initialization message 303, for example on a signal form which serves to estimate the distance between the authentication base device and the authentication device (ranging request).
- the power detection may generally be based on the received power and the synchronization may also be based on partial correlation on an imaginary and a priori known preamble portion of the received signal.
- a preamble can also be dispensed with if sufficient synchronization in time and sufficient power equalization have already been achieved by the previous communication.
- a frame synchronization and - possibly with an interpolation - a symbol synchronization can be achieved, that is, it can be determined which period corresponds in the received waveform to which logical information.
- a symbol synchronization is helpful, in particular, in the receiver postprocessing, because then the modulation of the authentication advisory and the authentication base device can be superimposed in phase.
- the carrier and symbol clock frequencies are also matched to those of the infrastructure transmitter (carrier and clock synchronization). For the following considerations, it is assumed that a synchronization has taken place successfully and therefore it is known which period in the received signal form corresponds to which logical information, so that the key sequences can be processed synchronously with the sent initialization message.
- the transmitted initialization message and the key sequences are synchronous and the analog key sequences are digitally generated and converted into an analog signal with a digital-to-analog converter.
- the sent initialization message is that part of the received signal which is encrypted in the method for generating an authentication message.
- the first cryptographic method uses a first key sequence 306 and the second cryptographic method uses a second key sequence 308.
- both key sequences are extended in time approximately as long as the sent initialization message 303.
- a first length of the first key sequence 306 differs and a second length of the second key sequence 308 less than 20% of a length of the sent initialization message 303. In some other embodiments, this deviation is less than 10% or less than 5%.
- the key sequences 306, 308 are in some embodiments after the signal detection (or possibly after the previous communication) from a on the mobile
- the authentication device calculates 300 stored keys (or multiple keys).
- a key sequence for the encryption of both sequences can be generated, for example, from three components: a separate key of the authentication device 300, a key specific to the authentication base device and a time-dependent share. In this case, the time-dependent share and the key of the authentication base device can be dispensed with in some implementations. The latter already enters the initialization signal received and originally sent by the authentication base device.
- the first cryptographic method is based in the embodiment shown on the multiplication of the first key sequence 306 with the message to be encrypted.
- a mixer or multiplier 310 is used that multiplies the transmitted analog initialization message 303 by the first key sequence 306, which is also an analog waveform, to obtain an intermediate message 312.
- the rate of the first key sequence 306 does not have to match the rate of the second key sequence 308.
- the rate of the first key sequence 306 is less than the rate of the sent initialization message 303, but ideally the rate is then given by an integer divisor.
- the second cryptographic method comprises adding the second key sequence 308 to the intermediate message 312.
- an adder 314 is added which adds the second key sequence 308 to the intermediate message 312 to obtain the authentication message 316.
- the second, additive encryption stage should use a key sequence whose waveform resembles that of the multiplicatively modulated intermediate message 312 in its waveform so that the additive portion in the authentication message 316 can not be separated and thus identified. This can affect both the amplitude and the bandwidth.
- a bandwidth of the first key sequence 306 and / or the second key sequence 308 differs by less than 20% from a bandwidth of the sent initialization message 303 and / or the intermediate message 312. In some other embodiments, this deviation is less than 10% or less than 5%.
- an amplitude of the first key sequence 306 and / or the second key sequence 308 deviates by less than 20% from an amplitude of the sent initialization message 303 and / or the intermediate message 312.
- the received power determined by the power estimator 318 is adjusted by means of the variable gain block 320 such that both the additive portions, the intermediate message 312 and the second key sequence 308 have the (approximately) equal power and amplitude, respectively so that they are difficult or impossible to distinguish in the resulting sum signal (in the example of FIG. 3, this is the authentication message 316).
- the latter results from the observability, or the impossible conclusion on N similar estimates based on M ⁇ N observations.
- the optional additional mixing of the signal with a local oscillation frequency 322 (LO) shown in FIG. 3 for converting the signal spectrum to a spectral range other than the received signal serves to decouple the received signal and the transmitted signal in order to prevent signal feedback loops.
- LO local oscillation frequency
- the multiplicative combination of a message with the bandwidth ⁇ and key sequence with bandwidth Bschüssei creates a spread of the signal bandwidth on ( ⁇ + Bschidorfi).
- the local oscillation frequency 322 is therefore greater than the total bandwidth ( ⁇ ⁇ + Bschidorfi) according to some embodiments.
- the additive linking of intermediate message 312 and second key sequence 308 occurs e.g. via an active or passive combiner circuit.
- Signal transmission of the frequency division multiplexed (FDM) authentication message 316 improves signal detection by preventing or greatly suppressing crosstalk.
- FDM frequency division multiplexed
- a time division multiplex (TDM) is also possible.
- TDM requires a long delay line with high bandwidth, which covers the entire signal frame length, but which can also be realized digitally.
- Both the TDM and FDM implementations are effective against the simple form of the attack with reinforcing relays: the defined, fixed delay time can be stored for TDM in the authentication base device, for example, so that an attacking relay that does not have the crypto sequence knows, has to look into the future in order to achieve a shorter duration and to carry out a successful attack.
- the signal propagation times within the authentication device are kept as short as possible. This makes some stronger cryptographic attack methods, such as the "Guessing Attack” and the “Early Bit Detection", more difficult. Therefore, according to some embodiments, the processing steps are kept as short as possible.
- cryptographic methods that perform block-by-block processing of the data to be encrypted are eliminated to avoid the associated latency.
- methods are used in which short sequences of the data to be encrypted are combined directly with short sequences of the key sequences 306 and 308. In the case of digital processing, this can mean, for example, that data to be encrypted is billed bit by bit with the key sequences.
- An alternative implementation of the mobile authentication device as an analog relay may use a load modulation for the multiplicative component instead of a mixer to switch between two (or more phasing) modes.
- the encryption sequence can be used directly digitally in this embodiment and a digital-to-analog conversion of the same can be dispensed with.
- the first cryptographic method comprises adding the first key sequence 306 to the initialization message 303, wherein the second cryptographic method comprises multiplying the second key sequence 308 by the intermediate message 312.
- embodiments make it possible to improve existing encryptions by adding an additive term to a multiplicative modulation, as used, for example, in backscatter methods such as passive RFID.
- the received codeword is additionally added multiplicatively modulated to its own coded codeword.
- Prior to the start of the actual method for generating an authentication message there may be a previous communication with an activation of the authentication device, in which case further encrypted information may also be exchanged.
- a basic synchronization in time and frequency can already be performed.
- the combined part of the cryptographic part of the TOF method is set up via an encrypted communication channel or preceded or readjusted to the cryptographic part. Often, sequences are transmitted bit by bit and retransmitted according to encryption with XOR or NAND operations.
- cryptographic communication offers a broad field of application. It is technically mostly based on one or more keys per communication partner.
- symmetric encryption methods and non-symmetric encryption methods, which use an identical key for encryption and decryption or a public key for encryption and a private key for decryption.
- Encryption methods are often attacked using methods of complete search (Brute force), even if this problem is NP-complete and thus a success can only be solved with exponential effort (based on the length of the key).
- knowing a sequence of the unencrypted source word may also make it possible to decrypt faster.
- the system-technical observability of the approach can be excluded.
- the embodiments of the invention can be used by the embodiments of the invention, if necessary, on shorter encryptions with the same security.
- FIGS. 3 and 4 show analogous implementations
- exemplary digital embodiments are depicted in FIGS. 5 and 6. Otherwise, the mode of operation of the embodiment shown in FIG. 5 corresponds to that of FIG. 4 and that of FIG. 6 corresponds to that of FIG. 3. Therefore, the functionally identical function blocks are provided with identical reference symbols, and subsequently only brief reference is made to the digital processing owed differences.
- the received signal is first sampled after filtering by means of a bandpass filter 502 and amplification with an amplifier 504 (LNA), subsequent mixing to baseband with a mixer 506, and bandlimiting of the baseband signal by means of a low pass 508 in an analog to digital converter 510 (ADC). Thereafter (after signal detection, synchronization and power estimation) the transmitted initialization message is detected in an analyzer 512, resulting in a sequence of logical ones and zeros. This then becomes additive and multiplicative with the key sequences 306 and 308, which in turn are generated from the keys used. Due to the digital symbol and frame synchronization, which are needed to determine the initialization message 303, the synchronicity of the received sequence and the two key sequences 306 and 308 is ensured.
- the bits of the authentication message are generated based on the Galois Field logic GF (2). According to this, the ® is to be regarded as logical exclusive "or" (XOR) as follows:
- the ® is interpreted as a logical "AND” (AND) according to this logic:
- a different assignment can also be made, for example the logical "AND” can be replaced by the logical "OR” (OR) or a negation of one of the two (NOR or NAND).
- OR logical "OR”
- NOR negative-n-AND
- the signals remain in the same field and amplitude gradations can not occur through this additive key sequence, which efficient transmission structures can be used and what makes the separation of the two encryption words even more difficult.
- the digital authentication message Prior to transmission, the digital authentication message is converted by means of a digital-to-analog converter 520 and, after optional filtering by means of another low-pass filter 522, mixed by means of a further mixer 524 to the carrier frequency, if necessary filtered again with another bandpass filter 526 and with a further amplifier 528 amplified and then sent.
- a digital-to-analog converter 520 Prior to transmission, the digital authentication message is converted by means of a digital-to-analog converter 520 and, after optional filtering by means of another low-pass filter 522, mixed by means of a further mixer 524 to the carrier frequency, if necessary filtered again with another bandpass filter 526 and with a further amplifier 528 amplified and then sent.
- FDM FDM
- TDM TDM
- FIG. 7 shows a block diagram of one embodiment of an authentication base 700.
- This includes a transmitter 702 configured to send an initialization message 703 and a receiver 704 configured to receive the authentication message 701.
- the signal received from the receiver antenna first filtered in the analog front-end 740, amplified, and mixed into baseband or a suitable intermediate frequency, where it is scanned by means of an ADC 742.
- the authentication base device 700 includes a first decryption module 706 configured to decrypt the authentication message by a second cryptographic method to obtain a received intermediate message 707; and a second decryption module 708 configured to decrypt the received intermediate message 707 using a second cryptographic method to obtain a received initialization message 709.
- the first decryption module 706 and the second decryption module 708 are presently located within a cryptography module 712, which also receives the initialization message 703.
- a decision module 710 in the cryptography module 712 is further configured to compare the received initialization message 709 and the initialization message 703 to determine whether the authentication message is considered authenticating.
- the first key sequence 737, the second key sequence 739 and the initialization message 709 are used to validate the received initialization message and thus to authenticate the sending authentication device.
- the illustrated authentication base 700 further supports an optional ToF verification.
- the authentication base device 700 further includes a timing module 720 configured to determine a signal transit time between sending the initialization message 703 and receiving the authentication message 701.
- the determination of the signal transit time in the authentication base device 700 of FIG. 7 is essentially based on performing correlations between expected signal sequences and actually received signal sequences for time measurement of a signal circulation.
- the determination of the signal propagation time makes it possible to estimate the distance between the authentication base device and the authentication device and to limit the zone of the permitted access.
- the cryptography module 712 with verification logic ensures that the correct authentication signal has been received and thus the authentication device is uniquely identified.
- the base authentication device 700 transmits the initialization message 703 (Cvac), possibly containing encrypted information, at time t0 and starts timing in the time module 720.
- the initialization message is sent through transmit filter 730, digital to analog converter 732, analog transmit front end 734 and transmitting antenna.
- the initialization message 703 is combined in combination block 736 with the first key sequence 737 using the first cryptographic method and with the second key sequence 739 using the second cryptographic method to generate a predicted authentication message to which the received authentication message in the corrector 738 correlates is to determine the time of receipt of the authentication signal.
- a correlation with other known signal sequences in the received signal can be used for this purpose, for example with a preamble, a midamble or a postamble.
- the digital part of the authentication base apparatus 700 first the reception of a signal in the corrector 738 is detected (eg based on a preamble), before optionally the encrypted total sequence of the predicted authentication message is correlated with the received signal, in order subsequently to obtain, from a plurality of correlation values, the arrival time TAnclose with higher accuracy to calculate. If the ranging message is divided into several subpackages, these can optionally be combined to determine the runtime.
- Methods for this are, inter alia, combining the correlation to determine the transit times taking into account the respective transmission times of the initiating ranging messages, the determination of the transit times and their evaluation according to the stochastic runtime distribution or parameters based thereon. Examples of such parameters are, for example, minimum, medians, mean values or percentiles, which can be evaluated on the basis of a threshold value.
- the correlation is replaced by a channel estimation - in the time or frequency domain - from which the first path is then detected. Its time (which includes the processing time) is the arrival time TAnclose.
- c vac is the vacuum light velocity or the propagation velocity of the radio waves.
- the encrypted sequence is verified in the cryptography module 712.
- An example implementation does this by accepting a maximum number of bit errors. That is, authentication is successful only if the received initialization message and the initialization message differ by less than an allowable number of bits. Upon successful authentication, the received initialization message and the initialization message correspond to each other.
- the signal-to-noise ratio is optionally additionally determined for this, in order to match it with a minimum value and thus to ensure that the desired bit error threshold value is undershot. If the signal-to-noise ratio is too low, the performance may be increased in the authentication base device, or the command may be given to the mobile authentication device via a communication link to increase the gain. Alternatively, it can also be assumed that the authentication device is too far away from the authentication base device if the signal-to-noise ratio is not sufficient.
- a decision logic 714 it is decided in a decision logic 714 whether the authentication is to be evaluated as successful. This is, according to some embodiments, only the case when the signal propagation time is less than a predetermined threshold and the received initialization message and the reserved, original initialization message correspond to one another.
- the authentication base device may be provided with an adaptive signal amplification (AGC) in the analogue receiver front-end in order to increase the range by a step-wise increase in power.
- AGC adaptive signal amplification
- the selected technology for transmitting the wireless signal is in principle independent.
- the transmission system may use, for example, broadband single carrier modulation.
- a further implementation can use as a transmission method, for example, multi-carrier modulation in which several (eg two) narrow-band subcarriers are distributed in the spectrum and modulated.
- the transmission system may be an ultra-wideband system that operates on ultra wideband signals.
- FIG. 8 shows schematically an implementation of an embodiment of the invention for access control for a motor vehicle 800.
- the motor vehicle 800 has an authentication base device 802 according to an exemplary embodiment of the invention.
- An embodiment of an authentication device 804 is part of a key 806 for the motor vehicle 800.
- aspects have been described in the context of a device, it will be understood that these aspects also constitute a description of the corresponding method, so that a block or a component of a device is also to be understood as a corresponding method step or as a feature of a method step. Similarly, aspects described in connection with or as a method step also represent a description of a corresponding block or detail or feature of a corresponding device.
- embodiments of the invention may be implemented in hardware or in software.
- the implementation can be under Use of a digital storage medium, such as a floppy disk, a DVD, a Blu-Ray Disc, a CD, a ROM, a PROM, an EPROM, an EEPROM or a FLASH memory, a hard disk or other magnetic or optical storage carried out are stored on the electronically readable control signals, which can cooperate with a programmable hardware component or cooperate such that the respective method is performed.
- CPU central processing unit
- GPU graphics processing unit
- ASIC application-specific integrated circuit
- IC integrated circuit
- SOC system on chip
- FPGA Field Programmable Gate Array
- the digital storage medium may therefore be machine or computer readable.
- some embodiments include a data carrier having electronically readable control signals capable of interacting with a programmable computer system or programmable hardware component such that one of the methods described herein is performed.
- One embodiment is thus a data carrier (or a digital storage medium or a computer readable medium) on which the program is recorded for performing any of the methods described herein.
- embodiments of the present invention may be implemented as a program, firmware, computer program or computer program product having program code or data, the program code or data operative to perform one of the methods when the program resides on a processor or a programmable hardware component.
- the program code or the data can also be stored, for example, on a machine-readable carrier or data carrier.
- the program code or the data may be present, inter alia, as source code, machine code or bytecode as well as other intermediate code.
- a further embodiment is further a data stream, a signal sequence or a sequence of signals, which the program for carrying out one of the hereinbefore described represents or represent written procedure.
- the data stream, the signal sequence or the sequence of signals can be configured, for example, to be transferred via a data communication connection, for example via the Internet or another network.
- Embodiments are also data representing signal sequences that are suitable for transmission over a network or a data communication connection, the data represent the program.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mechanical Engineering (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102016104771.6A DE102016104771A1 (de) | 2016-03-15 | 2016-03-15 | Verfahren zum Erzeugen einer Authentifizierungsnachricht, Verfahren zum Authentifizieren, Authentifizierungsgerät und Authentifizierungsbasisgerät |
| PCT/EP2017/052056 WO2017157563A1 (de) | 2016-03-15 | 2017-01-31 | Verfahren zum erzeugen einer authentifizierungsnachricht, verfahren zum authentifizieren, authentifizierungsgerät und authentifizierungsbasisgerät |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3430764A1 true EP3430764A1 (de) | 2019-01-23 |
Family
ID=57965918
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP17703363.6A Withdrawn EP3430764A1 (de) | 2016-03-15 | 2017-01-31 | Verfahren zum erzeugen einer authentifizierungsnachricht, verfahren zum authentifizieren, authentifizierungsgerät und authentifizierungsbasisgerät |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20190074973A1 (de) |
| EP (1) | EP3430764A1 (de) |
| JP (1) | JP2019512958A (de) |
| DE (1) | DE102016104771A1 (de) |
| WO (1) | WO2017157563A1 (de) |
Families Citing this family (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11163050B2 (en) | 2013-08-09 | 2021-11-02 | The Board Of Trustees Of The Leland Stanford Junior University | Backscatter estimation using progressive self interference cancellation |
| CN110100464A (zh) * | 2016-10-25 | 2019-08-06 | 小利兰·斯坦福大学托管委员会 | 反向散射环境ism频带信号 |
| DE102018002157A1 (de) * | 2018-03-16 | 2019-09-19 | Zf Active Safety Gmbh | Vorrichtung und Verfahren zur verschlüsselten Übertragung eines digitalen Steuersignals von einem Kraftfahrzeugschlüssel an ein Kraftfahrzeug |
| DE102018004997A1 (de) | 2018-06-22 | 2019-12-24 | Giesecke+Devrient Mobile Security Gmbh | Diebstahlschutz eines Automobils mittels Kontextmodellierung eines berechtigten Benutzers |
| US10594727B2 (en) | 2018-07-17 | 2020-03-17 | Levl Technologies, Inc. | Relay attack prevention |
| WO2020044233A1 (en) | 2018-08-27 | 2020-03-05 | Levl Technologies, Inc. | Carrier frequency offset modeling for radio frequency fingerprinting |
| WO2020070594A1 (en) | 2018-10-03 | 2020-04-09 | Levl Technologies, Inc. | Carrier frequency estimation for radio frequency fingerprinting |
| US10742449B1 (en) | 2019-06-12 | 2020-08-11 | Apple Inc. | Real time analog front end response estimation for sensing applications |
| EP4004879A1 (de) * | 2019-07-30 | 2022-06-01 | ams Sensors Singapore Pte. Ltd. | Authentifizierung der nähe über die flugzeit |
| WO2023158944A1 (en) * | 2022-02-16 | 2023-08-24 | Qualcomm Incorporated | Techniques for data authentication in wireless communications systems |
Family Cites Families (16)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH01122227A (ja) * | 1987-11-06 | 1989-05-15 | Konica Corp | 伝送装置 |
| US5120939A (en) * | 1989-11-09 | 1992-06-09 | At&T Bell Laboratories | Databaseless security system |
| DE19501004C2 (de) * | 1994-05-03 | 1999-09-16 | Telefunken Microelectron | Verfahren zur verifizierbaren Datenübertragung zwischen einem Transponder und einem Lesegerät |
| DE19523009C2 (de) * | 1995-06-24 | 1998-03-12 | Megamos F & G Sicherheit | Authentifizierungssystem |
| DE19530393A1 (de) * | 1995-08-18 | 1997-02-20 | Antonius Dr Rer Nat Klingler | Verfahren zur vocoderlosen Ver- und Entschlüsselung von analogen und digitalen Kommunikationssignalen auf der Basis deterministisch erzeugten Rauschens |
| FR2748144B1 (fr) * | 1996-04-25 | 1998-06-12 | Sagem | Procede de transmission securisee entre un emetteur et un recepteur, emetteur et recepteur pour la mise en oeuvre du procede |
| DE19632025C2 (de) * | 1996-08-08 | 1998-07-23 | Daimler Benz Ag | Authentikationseinrichtung mit elektronischer Authentikationskommunikation |
| JP2001069136A (ja) * | 1999-08-26 | 2001-03-16 | Toshiba Corp | 映像信号処理システム |
| FR2867289A1 (fr) * | 2004-03-02 | 2005-09-09 | France Telecom | Procede et dispositif pour accomplir une operation cryptographique |
| US9177153B1 (en) * | 2005-10-07 | 2015-11-03 | Carnegie Mellon University | Verifying integrity and guaranteeing execution of code on untrusted computer platform |
| BRPI0822741B1 (pt) * | 2008-05-26 | 2020-07-07 | Nxp B.V. | leitor e método de determinação da validade de uma conexão a um transponder e meio legível por computador |
| EP2247024B1 (de) * | 2009-04-30 | 2015-08-19 | Nxp B.V. | Bestimmung der Gültigkeit einer Verbindung zwischen einem Leser und einem Transponder |
| JP5221476B2 (ja) * | 2009-08-31 | 2013-06-26 | 株式会社東海理化電機製作所 | 車両の電子キーシステム |
| WO2012176408A1 (ja) * | 2011-06-24 | 2012-12-27 | 日本電気株式会社 | 署名検証方法、署名検証システム及び署名検証プログラム |
| JP2013138304A (ja) * | 2011-12-28 | 2013-07-11 | Toyota Motor Corp | セキュリティシステム及び鍵データの運用方法 |
| DE102012219112A1 (de) * | 2012-10-19 | 2014-04-24 | Siemens Aktiengesellschaft | Verwenden einer PUF zur Prüfung einer Authentisierung, insbesondere zum Schutz vor unberechtigtem Zugriff auf eine Funktion eines ICs oder Steuergerätes |
-
2016
- 2016-03-15 DE DE102016104771.6A patent/DE102016104771A1/de active Pending
-
2017
- 2017-01-31 WO PCT/EP2017/052056 patent/WO2017157563A1/de not_active Ceased
- 2017-01-31 EP EP17703363.6A patent/EP3430764A1/de not_active Withdrawn
- 2017-01-31 JP JP2018548902A patent/JP2019512958A/ja active Pending
- 2017-01-31 US US16/084,649 patent/US20190074973A1/en not_active Abandoned
Also Published As
| Publication number | Publication date |
|---|---|
| DE102016104771A1 (de) | 2017-10-05 |
| WO2017157563A1 (de) | 2017-09-21 |
| US20190074973A1 (en) | 2019-03-07 |
| JP2019512958A (ja) | 2019-05-16 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2017157563A1 (de) | Verfahren zum erzeugen einer authentifizierungsnachricht, verfahren zum authentifizieren, authentifizierungsgerät und authentifizierungsbasisgerät | |
| EP3138258B1 (de) | Verfahren zur erzeugung eines geheimnisses oder eines schlüssels in einem netzwerk | |
| DE112005002651B4 (de) | Verfahren und Vorrichtung zur Authentifikation von mobilen Vorrichtungen | |
| DE69727641T2 (de) | Verfahren zum Senden einer sicheren Botschaft in einem Telekommunikationssystem | |
| DE602004000695T2 (de) | Erzeugung von asymmetrischen Schlüsseln in einem Telekommunicationssystem | |
| DE112019005097T5 (de) | Zugriffssysteme für passiven Zutritt/passiven Start mit Tonaustausch | |
| DE102013202001B4 (de) | Verfahren zum Versehen eines mobilen Endgeräts mit einem Authentisierungszertifikat | |
| CN105704245B (zh) | 基于车联网的海量数据处理方法 | |
| EP2961091B1 (de) | Bereitstellen eines gesicherten replika-pseudo-zufallsrauschsignals | |
| CN105897715B (zh) | 车联网数据智能处理方法 | |
| DE19822795A1 (de) | Verfahren und Anordnung zum rechnergestützten Austausch kryptographischer Schlüssel zwischen einer ersten Computereinheit und einer zweiten Computereinheit | |
| EP2011302B1 (de) | Verfahren und system zum manipulationssicheren einrichten eines kryptographischen schlüssels | |
| DE102018009609A1 (de) | Verfahren und System für eine sichere Datenübertragung | |
| EP3657701A2 (de) | Verschleierung von umwelteinflüssen auf den sendeparametern | |
| WO2021249761A1 (de) | Vorbereiten einer steuervorrichtung zur sicheren kommunikation | |
| DE102021119891B4 (de) | Verfahren zur Authentifizierung einer Sendeeinheit durch eine Empfängereinheit | |
| CN112954643B (zh) | 直连通信认证方法、终端、边缘服务节点及网络侧设备 | |
| EP3050244B1 (de) | Bereitstellung und verwendung pseudonymer schlüssel bei hybrider verschlüsselung | |
| DE112013001180B4 (de) | Kommunikationsprotokoll für sichere Kommunikationssysteme | |
| DE102013100756B3 (de) | Verfahren und Vorrichtung zur Authentifizierung eines Nutzers | |
| EP4503502A1 (de) | Verfahren zur lokalen erzeugung quantensicherer schlüssel in einem netzwerk | |
| DE102023122819A1 (de) | Sicherheitssignatur für bluetooth-niedrigenergie-frame-synch.-detektion | |
| DE102004042231A1 (de) | Bestimmung der räumlichen Distanz zwischen kommunizierenden Funkpartnern | |
| DE102005009490B4 (de) | Verfahren, Vorrichtung, Gerät und System zum Schützen eines privaten Kommunikationsschlüssels für eine Fahrzeug-Umwelt-Kommunikation | |
| DE102010021254A1 (de) | Verfahren zur geschützten Vereinbarung eines Sicherheitsschlüssels über eine unverschlüsselte Funkschnittstelle |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20181015 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20200702 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20210803 |