RollBack: A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems

RollBack: A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems
复制标题

回滚:针对汽车远程无钥匙进入系统的新的与时间无关的重放攻击

DOI:
--
复制
发表时间:
2022
期刊:
ACM Trans. Cyber Phys. Syst.
影响因子:
--
通讯作者:
Mun Choon Chan
Mun Choon Chan
中科院分区:
--
文献类型:
--
作者:
Levente Csikor;Hoonwei Lim;Jun Wen Wong;Soundarya Ramesh;Rohini Poolat Parameswarath;Mun Choon Chan

文献摘要

被引文献

相似文献

汽车无钥匙进入(RKE)系统为车主提供了一定程度的便利,使他们无需使用机械钥匙即可锁定和解锁汽车。如今的 RKE 系统采用一次性滚动码,使每次按下遥控钥匙按钮时都独一无二,从而有效防止简单的重放攻击。然而,先前的一种名为 RollJam 的攻击已被证明可以破坏所有基于滚动代码的系统。通过一系列仔细的信号干扰、捕获和重放,攻击者可以意识到后续尚未使用的有效解锁信号。然而,RollJam 需要无限期地持续部署,直到它被利用。否则,如果在未安装 RollJam 的情况下再次使用遥控钥匙,捕获的信号将变得无效。我们引入了 RollBack,这是一种针对当今大多数 RKE 系统的新的重放和重新同步攻击。特别是,我们表明,即使一次性代码在滚动代码系统中变得无效,连续重放一些先前捕获的信号也可以在 RKE 系统中触发类似回滚的机制。换句话说,滚动代码重新同步回过去使用的先前代码,所有后续但已使用的信号再次工作。此外,受害者仍然可以使用密钥卡,而不会注意到攻击前后有任何差异。与 RollJam 不同,RollBack 根本不需要干扰。事实上,它只需要捕获一次信号,并且可以在未来的任何时间根据需要多次利用。这种与时间无关的属性对攻击者特别有吸引力,特别是在汽车共享/租赁场景中,访问密钥卡非常简单。然而,虽然 RollJam 几乎可以击败任何基于滚动代码的系统,但车辆可能有额外的防盗措施来防止钥匙扣故障,从而防止 RollBack。我们对不同品牌和型号的车辆进行的持续分析(使用众包数据)显示,亚洲地区大约 50% 的受检查车辆容易受到回滚的影响,而欧洲和北美等其他地区的影响往往较小。
Automotive Keyless Entry (RKE) systems provide car owners with a degree of convenience, allowing them to lock and unlock their car without using a mechanical key. Today’s RKE systems implement disposable rolling codes, making every key fob button press unique, effectively preventing simple replay attacks. However, a prior attack called RollJam was proven to break all rolling code–based systems in general. By a careful sequence of signal jamming, capturing, and replaying, an attacker can become aware of the subsequent valid unlock signal that has not been used yet. RollJam, however, requires continuous deployment indefinitely until it is exploited. Otherwise, the captured signals become invalid if the key fob is used again without RollJam in place. We introduce RollBack, a new replay-and-resynchronize attack against most of today’s RKE systems. In particular, we show that even though the one-time code becomes invalid in rolling code systems, replaying a few previously captured signals consecutively can trigger a rollback-like mechanism in the RKE system. Put differently, the rolling codes become resynchronized back to a previous code used in the past from where all subsequent yet already used signals work again. Moreover, the victim can still use the key fob without noticing any difference before and after the attack. Unlike RollJam, RollBack does not necessitate jamming at all. In fact, it requires signal capturing only once and can be exploited at any time in the future as many times as desired. This time-agnostic property is particularly attractive to attackers, especially in car-sharing/renting scenarios in which accessing the key fob is straightforward. However, while RollJam defeats virtually any rolling code–based system, vehicles might have additional anti-theft measures against malfunctioning key fobs, hence against RollBack. Our ongoing analysis (with crowd-sourced data) against different vehicle makes and models has revealed that ∼ 50% of the examined vehicles in the Asian region are vulnerable to RollBack, whereas the impact tends to be smaller in other regions, such as Europe and North America.