Speaker

Yuqiao Yang

Yuqiao Yang

GoGoByte,connected vehicle cybersecurity researcher

Beijing, China

Actions

Yuqiao Yang is a connected vehicle cybersecurity researcher at GoGoByte, a cybersecurity company dedicated to maintaining automobile security from silicon to cloud. He conducts penetration tests on automobile parts, does research on Internet of Vehicles cybersecurity and has obtained numerous patents. Security products which he participated in the development of, have been adopted by many OEMs and suppliers. He holds a bachelor's degree in Electrical Engineering and is studying for a master's degree in Computer Science at the University of Electronic Science and Technology of China.

Area of Expertise

  • Information & Communications Technology

GoGoBark:Interference Attacks on UWB Ranging for IEEE 802.15.4z Standard

The industry generally acknowledges that Ultra Wide Band (UWB) technology can theoretically mitigate the issue of Relay Attacks associated with traditional Low Frequency (LF) and Bluetooth Passive Keyless Entry (PKE) systems. UWB localization technology is increasingly being incorporated into the latest digital car key systems, as the functionality of UWB ranging is directly tied to the car's susceptibility to relay attacks and the proper operation of the car key. However, during a security test project at GoGoByte, we discovered that merely adhering to the IEEE 802.15.4z and Car Connectivity Consortium (CCC) Digital Key standards does not ensure the reliable performance of the UWB ranging function. We have proposed a "sniper" jamming attack on High Rate Pulse (HRP) UWB ranging. For confidentiality reasons, we used the iPhone 14 and AirTag as demonstration devices. Upon activation of the attack device, the UWB-based ranging function of the iPhone fails, with a success rate of 99%. This attack method impacts not only Apple smartphones but also digital car keys that utilize IEEE 802.15.4z HRP UWB ranging.

Yuqiao Yang

GoGoByte,connected vehicle cybersecurity researcher

Beijing, China

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top