Security Analysis of Time-of-Arrival Estimation via Cross-Correlation under Narrow-Band Conditions
Claudio Anliker, Daniele Coppola, Giovanni Camurati, Srdjan \v{C}apkun

TL;DR
This paper introduces two novel, symbol-agnostic attacks that compromise narrowband ToA estimation via cross-correlation, demonstrating significant distance reduction and practical implementation feasibility.
Contribution
It presents two new attacks on narrowband ToA estimation that do not require real-time symbol detection, expanding understanding of system vulnerabilities.
Findings
Attacks can reduce estimated distance by up to 18 meters.
Prototypes confirm the practical feasibility of NGD-based attack methods.
Simulations show effectiveness against Bluetooth Channel Sounding RTT ranging.
Abstract
Time-of-arrival (ToA) estimation via cross-correlation is an essential building block of time-of-flight ranging. However, in narrowband systems, it is notoriously difficult to protect against distance-decreasing attacks such as Early-Detect/Late-Commit (ED/LC). We present and analyze two new attacks that reshape ranging signals to compromise correlation-based ToA estimation. The first attack multiplies the signal by a symbol-periodic waveform in the time domain, while the second passes it through a negative group delay (NGD) filter. In contrast to ED/LC, our attacks do not require real-time symbol detection or adaptive compensation; they are completely symbol-agnostic. We describe implementation strategies for both attacks and discuss NGD filtering in the context of Bluetooth Channel Sounding (CS), a recent narrowband ranging system. To this end, we simulate an NGD circuit in LTspice…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
