Relay Attacks on Wireless Access Systems and Documented Defenses

Relay Attacks on Wireless Access Systems and Documented Defenses

Every proximity unlock system rests on one hidden assumption: if the lock can hear the credential, the credential must be nearby. A relay attack attacks that assumption directly. Two devices, one near the key and one near the lock, forward the radio conversation between them. The lock hears a perfectly valid exchange. It just has no way to know the exchange traveled a hundred feet through borrowed hardware first.

What the research actually demonstrated

The foundational work here is a 2011 study of passive keyless entry and start systems in cars, which is the same design family that consumer proximity locks and fobs draw from. The researchers built both wired and wireless relays and tested them against ten car models from eight manufacturers. Their published analysis of relay attacks on passive keyless entry systems reports that the attack worked while the genuine key stayed up to fifty meters from the vehicle, non line of sight, and that relaying the signal in only one direction was sufficient.

The critical finding is not the range. It is the independence. The authors describe the relay as working regardless of the modulation, the protocol, or the presence of strong authentication and encryption. The paper was presented at the NDSS Symposium in 2011, so this is not a fresh discovery. It is a well understood structural property of proximity systems that has been public for well over a decade.

Why encryption does not help

People are often surprised that a system using serious cryptography falls to a relay. The reason is simple. A relay never decrypts anything, never forges anything, and never needs a key. It copies bits from one place and replays them somewhere else, in real time, with the original cryptographic content intact. From the lock's point of view every signature checks out, because every signature genuinely was produced by the real credential. The only thing that was falsified is location, and plain challenge and response says nothing about location.

That is why adding stronger encryption to a relay vulnerable product does not fix it. The defense has to measure distance, not identity.

The defense: measuring distance, not just identity

The technical answer is secure ranging, sometimes called distance bounding. Instead of only asking "do you hold the right key," the lock measures how long the signal round trip takes and rejects credentials that are physically too far away. Because radio propagation is bounded by the speed of light, a relay adds delay it cannot subtract.

Ultra wideband radio is the mainstream implementation, and it is a genuine improvement rather than a marketing claim. It is also not magic. Academic work on ultra wideband ranging, including research on detecting distance enlargement attacks in UWB presented at USENIX Security, shows that ranging systems have their own attack surface at the physical signal layer, independent of cryptography. Secure ranging raises the bar substantially. It does not remove the category.

What a homeowner can actually do

  • Turn off passive unlock if you do not need it. Requiring a deliberate button press or an in app confirmation removes the automated proximity assumption entirely. This is the single highest impact setting on most products.
  • Prefer credentials with motion awareness. A fob or phone that stops transmitting when it has been stationary for a while is much harder to harvest overnight, which is when relay attempts on parked vehicles typically occur.
  • Store credentials away from exterior walls. A key left on a hall table two feet from the door is trivially within excitation range from outside. A drawer in an interior room is not.
  • Do not let convenience features stack. Auto unlock combined with a keypad backup combined with a shared cloud account produces more entry paths than most people realize.

Questions worth asking a manufacturer

If a product advertises hands free or proximity unlock, ask how it verifies proximity. Vague answers about encryption are a signal that the vendor is answering a different question. Concrete answers name a ranging technology, describe a distance threshold, and say what happens when ranging fails. Ask whether passive unlock can be disabled entirely and whether the credential sleeps when stationary.

Finally, keep this in proportion. Relay attacks require an attacker to bring equipment and be present at both ends at once. That is a targeted effort, not an opportunistic one. For most homes the mechanical strength of the door and frame remains the larger exposure, and the sensible move is to disable passive unlock, keep credentials away from the entry, and spend the rest of your attention on the physical opening.

Hiring a locksmith instead?

Our directory lists locksmith shops in every US state with their public address, phone, and website, so you can call a real local business instead of a lead broker.

Find a locksmith near you