Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB Ranging
Patrick Leu (1), Giovanni Camurati (1), Alexander Heinrich (2), Marc, Roeschlin (1), Claudio Anliker (1), Matthias Hollick (2), Srdjan Capkun (1),, Jiska Classen (2) ((1) ETH Zurich, (2) TU Darmstadt)

TL;DR
This paper demonstrates a practical over-the-air attack on UWB distance measurement systems, successfully reducing perceived distances from 12 meters to zero without cryptographic knowledge, raising security concerns.
Contribution
It is the first to show a real-world distance reduction attack on IEEE 802.15.4z UWB systems, including Apple U1 chips, using inexpensive equipment.
Findings
Achieved distance spoofing from 12m to 0m
Attack success probability up to 4%
Requires only a USD 65 device
Abstract
We present the first over-the-air attack on IEEE 802.15.4z High-Rate Pulse Repetition Frequency (HRP) Ultra-WideBand (UWB) distance measurement systems. Specifically, we demonstrate a practical distance reduction attack against pairs of Apple U1 chips (embedded in iPhones and AirTags), as well as against U1 chips inter-operating with NXP and Qorvo UWB chips. These chips have been deployed in a wide range of phones and cars to secure car entry and start and are projected for secure contactless payments, home locks, and contact tracing systems. Our attack operates without any knowledge of cryptographic material, results in distance reductions from 12m (actual distance) to 0m (spoofed distance) with attack success probabilities of up to 4%, and requires only an inexpensive (USD 65) off-the-shelf device. Access control can only tolerate sub-second latencies to not inconvenience the user,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUltra-Wideband Communications Technology · Bluetooth and Wireless Communication Technologies · Cryptographic Implementations and Security
