Today, we use smartphones as multi-purpose devices that communicate with their environment to implement context-aware services, including asset tracking, indoor localization, contact tracing, or access control. As a de-facto standard, Bluetooth is available in virtually every smartphone to provide short-range wireless communication. Importantly, many Bluetooth-driven applications such as Phone as a Key (PaaK) for vehicles and buildings require proximity of legitimate devices, which must be protected against unauthorized access. In earlier access control systems, attackers were able to violate proximity-verification through relay station attacks. However, the vulnerability of Bluetooth against such attacks was yet unclear as existing relay attack strategies are not applicable or can be defeated through wireless distance measurement. In this paper, we design and implement an analog physical-layer relay attack based on low-cost off-the-shelf radio hardware to simultaneously increase the wireless communication range and manipulate distance measurements. Using our setup, we successfully demonstrate relay attacks against Bluetooth-based access control of a car and a smart lock. Further, we show that our attack can arbitrarily manipulate Multi-Carrier Phase-based Ranging (MCPR) while relaying signals over 90 m.
翻译:今天,我们使用智能手机作为多功能设备,与环境环境进行沟通,以实施环境认知服务,包括资产跟踪、室内本地化、接触跟踪或出入控制。作为一个实际标准,几乎每个智能手机都提供蓝牙,提供短距离无线通信。重要的是,许多蓝牙驱动的应用,如车辆和建筑物的“键”电话(PaaK),需要使用合法装置,必须加以保护,防止未经授权的进入。在早期的出入控制系统中,袭击者能够通过中继站袭击违反近距离验证。然而,蓝牙对此类袭击的脆弱性尚不清楚,因为现有的中继攻击战略不适用,或者可以通过无线远程测量击败。在本文件中,我们设计和实施模拟的物理中继攻击,其基础是低成本的现成无线电硬件,以同时增加无线通信范围并操纵远程测量。我们利用我们的设置成功地展示了对蓝牙型汽车和智能锁的出入控制进行中继攻击。此外,我们展示了我们的攻击可以任意操纵多卡连线的中继系统,同时将信号超过90米。