[Paper Review] Security Analysis of two Distance-Bounding Protocols
This paper analyzes the security of two distance-bounding protocols—Hitomi and NUS—demonstrating that both are less secure than claimed. It reveals a full secret key disclosure attack on Hitomi and shows that the success probability of distance fraud against NUS can reach (3/4)^n, with slight improvement if the adversary has computational capabilities.
In this paper, we analyze the security of two recently proposed distance bounding protocols called the Hitomi and the NUS protocols. Our results show that the claimed security of both protocols has been overestimated. Namely, we show that the Hitomi protocol is susceptible to a full secret key disclosure attack which not only results in violating the privacy of the protocol but also can be exploited for further attacks such as impersonation, ma?a fraud and terrorist fraud attacks. Our results also demonstrates that the probability of success in a distance fraud attack against the NUS protocol can be increased up to (3/4)^n and even slightly more, if the adversary is furnished with some computational capabilities.
Motivation & Objective
- To evaluate the actual security guarantees of the Hitomi and NUS distance-bounding protocols.
- To identify and exploit potential vulnerabilities that undermine their claimed security properties.
- To assess the feasibility of key disclosure and distance fraud attacks under realistic adversary models.
- To quantify the success probability of attacks on the NUS protocol, especially with computational enhancements.
Proposed method
- Formal cryptanalysis of the Hitomi protocol to identify flaws in its key exchange mechanism.
- Construction of a full secret key disclosure attack exploiting timing and message structure in Hitomi.
- Analysis of the NUS protocol’s challenge-response mechanism to assess resistance against distance fraud.
- Modeling the adversary’s success probability in distance fraud as (3/4)^n, with extensions for computational advantages.
- Use of timing and side-channel information to mount practical attacks on both protocols.
- Evaluation of the impact of computational capabilities on increasing the success rate of NUS attacks.
Experimental results
Research questions
- RQ1Can the Hitomi protocol be compromised through a full secret key disclosure attack?
- RQ2To what extent does the NUS protocol remain secure against distance fraud attacks?
- RQ3How does the presence of computational capabilities affect the success probability of NUS attacks?
- RQ4Are the security claims of both protocols justified under realistic threat models?
Key findings
- The Hitomi protocol is vulnerable to a full secret key disclosure attack, violating both confidentiality and integrity.
- The success probability of a distance fraud attack on the NUS protocol reaches (3/4)^n, which is significantly higher than previously claimed.
- Even with limited computational capabilities, an adversary can slightly increase the success rate of NUS attacks.
- The vulnerabilities in both protocols undermine their claimed resistance to impersonation, mafia fraud, and terrorist fraud.
- The results indicate that the security claims of both protocols have been overestimated in the literature.
- Practical exploitation of these flaws enables real-world attacks such as key disclosure and fraudulent authentication.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.