Secure Ranging with IEEE 802.15.4z HRP UWB

Xiliang Luo,Cem Kalkanli,Hao Zhou,Pengcheng Zhan,Moche Cohen
DOI: https://doi.org/10.1109/SP54263.2024.00238
2024-10-10
Abstract:Secure ranging refers to the capability of upper-bounding the actual physical distance between two devices with reliability. This is essential in a variety of applications, including to unlock physical systems. In this work, we will look at secure ranging in the context of ultra-wideband impulse radio (UWB-IR) as specified in IEEE 802.15.4z (a.k.a. 4z). In particular, an encrypted waveform, i.e. the scrambled timestamp sequence (STS), is defined in the high rate pulse repetition frequency (HRP) mode of operation in 4z for secure ranging. This work demonstrates the security analysis of 4z HRP when implemented with an adequate receiver design and shows the STS waveform can enable secure ranging. We first review the STS receivers adopted in previous studies and analyze their security vulnerabilities. Then we present a reference STS receiver and prove that secure ranging can be achieved by employing the STS waveform in 4z HRP. The performance bounds of the reference secure STS receiver are also characterized. Numerical experiments corroborate the analyses and demonstrate the security of the reference STS receiver.
Cryptography and Security
What problem does this paper attempt to address?
The paper aims to address the issue of secure ranging in Ultra-Wideband (UWB) Impulse Radio (IR) under the IEEE 802.15.4z standard High Repetition Frequency (HRP) mode. Specifically: 1. **Define Secure Ranging**: The paper first clarifies the concept of secure ranging, which ensures that the measured distance is always greater than or equal to the actual physical distance, even in the presence of malicious attackers attempting to manipulate the ranging waveform. 2. **Analyze Security Vulnerabilities in Existing Receiver Designs**: The paper reviews the secure timestamp sequence (STS) receivers used in previous studies and reveals the security vulnerabilities of these receivers. 3. **Propose a Reference STS Receiver Design**: The authors propose a new reference STS receiver design and demonstrate that this design can achieve secure ranging. Additionally, the performance boundaries of this receiver are analyzed. Through these contributions, the paper demonstrates how to utilize encrypted waveforms (STS) in the 4z HRP mode to achieve secure ranging and provides rigorous theoretical support. These results help to strengthen the foundation of secure ranging and provide support for various application scenarios.