A Countermeasure to Defend Against Relay Attacks in Wireless Networks
Caimu Tang, Dapeng Oliver Wu · 2006
In this paper, a non-interactive zero-knowledge proof scheme is proposed for secure identification in wireless networks, and it uses a timed oblivious transfer technique to enable a single verifier to identify multiple provers. The verifier and the prover do not need to be synchronized in this scheme. This scheme also enjoys the distance bounding property which makes the proposed scheme invulnerable to the relay attack. We propose to use the order statistic for the detection of relay attackers. We show that it is optimal in terms of minimum variance. Finally, we will shed some light on implementation issues of our proposed scheme. I. INTRODUCTION Recent years have witnessed the urgent needs to secure net- works of low power wireless devices as widespread adoption of these devices in our daily life is imminent. Countermeasure of the relay attack has been one of known hard problems for many challenge-response protocols aimed at applications over these networks. The U.S. government backed e-Passport project (cf. US Border Security Act of 2002) requires that the anti-skimming material has to be used to countermeasure the relay attack. Zero-knowledge proof (ZKP) has been used as a fundamen- tal secure primitive for many challenge-response protocols. On ISO/IEC 18092 compatible devices where enhanced pro- cessing capability is normally present, ZKP primitives can be employed to build secure systems. However, the relay attack has been acknowledged as one effective attack to an interactive ZKP (4), (8). Referring to Fig. 1, P, the prover and V , the verifier are both under the control of an adversary, and they are located between the legitimate prover P and verifier V; V identifies itself as a legitimate verifier to P and P identifies itself as a legitimate prover to V. Interaction in ZKP introduces many problems, namely, communication cost, potential protocol vulnerability, etc. One approach to removing the interaction during ZKP is to use offline pre-computation of a series of public keys for a two-party oblivious transfer (OT) protocol (13), (10), (3). Under this approach, the prover uses the OT protocol to send messages to the verifier through multiple rounds; in each round, the prover uses a different OT public key to encrypt the messages. This non-interactive ZKP can enable a single verifier to identify multiple provers as the same OT public key can be used by many provers in a single round (note that the same OT public key should not be used in different rounds). However, the non-interactive ZKP is still vulnerable to relay attack. One practical approach to defending against the relay attack is to associate the absolute location information digitally