Heyden, Martin Reza (2023)
Security Analysis of Samsung's Ultra-Wideband Ecosystem and the Usage of NXP Ultra-Wideband Chips.
Technische Universität Darmstadt
doi: 10.26083/tuprints-00024378
Masterarbeit, Erstveröffentlichung, Verlagsversion
Kurzbeschreibung (Abstract)
Ultra-Wideband (UWB) is a radio technology that uses a high bandwidth and enables use-cases for precise position estimation in close ranges. In recent years, UWB functionality found its way into many smartphones and Internet of Things (IoT) products, including devices from Samsung that use UWB chips by NXP. However, neither the security of Samsung’s UWB ecosystem entities nor the usage and communication of the integrated NXP UWB chips were publicly explored yet. Since UWB integration into smartphones and UWB chips for smartphone-related use-cases are new, only a few directly related works exist. These works analyze the chips’ physical-layer security and the integration of UWB into Apple devices, but no work addresses the firmware security of NXP’s UWB chips and the UWB integration into Samsung’s devices. Therefore, in our thesis, we analyze the security of Samsung’s UWB ecosystem entities, including NXP’s SR100T UWB chip featured on the Samsung Galaxy S21 Ultra, which we use as our test phone. We further assess the security of Samsung’s SmartTag+ that features NXP’s SR040 UWB chip and is part of the ecosystem. Our goal is to identify attack vectors and evaluate a selection of them. Furthermore, to aid our analysis and create attacks in our evaluation, we implement several utilities that help us decode the communication with NXP’s UWB chips, attack the SR100T on our Samsung phone independently of the user space, and simulate attacks against the ecosystem’s entities. In our evaluation, we find several vulnerabilities in different ecosystem entities. In addition, our findings about NXP’s UWB chips and their communication protocols provide a foundation for future research that evaluates the security of UWB chips addressable over Ultra-Wideband Command Interface (UCI) as well as the security of their integration.
Typ des Eintrags: | Masterarbeit | ||||
---|---|---|---|---|---|
Erschienen: | 2023 | ||||
Autor(en): | Heyden, Martin Reza | ||||
Art des Eintrags: | Erstveröffentlichung | ||||
Titel: | Security Analysis of Samsung's Ultra-Wideband Ecosystem and the Usage of NXP Ultra-Wideband Chips | ||||
Sprache: | Englisch | ||||
Referenten: | Hollick, Prof. Dr. Matthias ; Classen, Dr. Jiska | ||||
Publikationsjahr: | 2 Oktober 2023 | ||||
Ort: | Darmstadt | ||||
Kollation: | xviii, 181 Seiten | ||||
DOI: | 10.26083/tuprints-00024378 | ||||
URL / URN: | https://tuprints.ulb.tu-darmstadt.de/24378 | ||||
Kurzbeschreibung (Abstract): | Ultra-Wideband (UWB) is a radio technology that uses a high bandwidth and enables use-cases for precise position estimation in close ranges. In recent years, UWB functionality found its way into many smartphones and Internet of Things (IoT) products, including devices from Samsung that use UWB chips by NXP. However, neither the security of Samsung’s UWB ecosystem entities nor the usage and communication of the integrated NXP UWB chips were publicly explored yet. Since UWB integration into smartphones and UWB chips for smartphone-related use-cases are new, only a few directly related works exist. These works analyze the chips’ physical-layer security and the integration of UWB into Apple devices, but no work addresses the firmware security of NXP’s UWB chips and the UWB integration into Samsung’s devices. Therefore, in our thesis, we analyze the security of Samsung’s UWB ecosystem entities, including NXP’s SR100T UWB chip featured on the Samsung Galaxy S21 Ultra, which we use as our test phone. We further assess the security of Samsung’s SmartTag+ that features NXP’s SR040 UWB chip and is part of the ecosystem. Our goal is to identify attack vectors and evaluate a selection of them. Furthermore, to aid our analysis and create attacks in our evaluation, we implement several utilities that help us decode the communication with NXP’s UWB chips, attack the SR100T on our Samsung phone independently of the user space, and simulate attacks against the ecosystem’s entities. In our evaluation, we find several vulnerabilities in different ecosystem entities. In addition, our findings about NXP’s UWB chips and their communication protocols provide a foundation for future research that evaluates the security of UWB chips addressable over Ultra-Wideband Command Interface (UCI) as well as the security of their integration. |
||||
Alternatives oder übersetztes Abstract: |
|
||||
Status: | Verlagsversion | ||||
URN: | urn:nbn:de:tuda-tuprints-243783 | ||||
Sachgruppe der Dewey Dezimalklassifikatin (DDC): | 000 Allgemeines, Informatik, Informationswissenschaft > 004 Informatik | ||||
Fachbereich(e)/-gebiet(e): | 20 Fachbereich Informatik 20 Fachbereich Informatik > Sichere Mobile Netze |
||||
Hinterlegungsdatum: | 02 Okt 2023 12:07 | ||||
Letzte Änderung: | 11 Okt 2023 06:50 | ||||
PPN: | |||||
Referenten: | Hollick, Prof. Dr. Matthias ; Classen, Dr. Jiska | ||||
Export: | |||||
Suche nach Titel in: | TUfind oder in Google |
Frage zum Eintrag |
Optionen (nur für Redakteure)
Redaktionelle Details anzeigen |