RFID, NFC & UWB · Study deck

UWB Applications and Security

UWB means ultra wideband radio, a method that uses very short pulses across a wide range of frequencies.

Radio Remi is your guide for this deck.

access-controlasset-trackingsecure-ranging
Radio Remi, the module guide, in a scene from this chapter.
iotclass.org

After studying this chapter

Learning objectives

You will be able to:

  • Explain: The timing arithmetic explains why policy cannot stop at "near." Radio waves travel at roughly 300,000,000 m/s, so 1 ns of one-way flight time is about 0.30 m.
  • Explain: The practitioner question is not "Did we get a range?" It is "Can this range be trusted enough for this action?" Signal strength offers little defense because strength is not distance.
  • Build a UWB secure-access evidence chain (credential, freshness, distance evidence, policy, fallback, audit) and explain why a nearby credential is not sufficient authorization by itself
iotclass.org

Major section

In 60 Seconds

A distance estimate must be fresh, tied to the right identity, and inside a clear policy.

  • Ultra-wideband is a radio method that uses very short pulses across a wide range of frequencies; it is shortened to UWB.
  • UWB applications succeed when distance or position evidence changes an action: unlock, locate, warn, guide, count, or deny.
  • Security is not automatic.
iotclass.org

Major section

Secure Ranging as Decision Evidence

The reason UWB is useful in cars, phones, badges, locks, tools, and warehouse tags is not just centimeter-class positioning under good conditions.

  • A robust UWB application joins four checks: credential authorization, time-bounded ranging evidence, policy rules for the physical zone, and a fallback when confidence is low.
  • A phone presents a valid credential, then the cabinet receives a UWB result of 0.74 m with a fresh timestamp and normal confidence.
  • The distance number did not become false; it became insufficient for the action.
  • That helps resist false-proximity claims, but the application still owns privacy, logging, operator override, and retest rules.
iotclass.org

Major section

Application Fit

The main reason to choose UWB is not that it is new or precise.

  • The reason is that an application has a decision that depends on trusted physical evidence.
  • That ordering makes guide, deny depend on: Access.
  • Carry: Access into the evidence for application fit.
  • Each family should name the action it controls.
UWB application map linking use cases to required evidence and action
UWB application map linking use cases to required evidence and action
iotclass.org

Major section

Secure Access Evidence Chain

Secure access requires more than a short distance estimate.

  • The system has to prove the credential is authorized, the ranging exchange is fresh, the measured proximity fits the policy, and the fallback path is safe.
  • Skipping zone and action would leave reason and result unsupported.
UWB secure access evidence chain from credential to policy action
UWB secure access evidence chain from credential to policy action
iotclass.org

Major section

Relay Resistance

Relay attacks try to make a far credential appear nearby by forwarding messages through another link.

  • Extra path and processing delay should make the credential appear farther away, not closer.
  • Both: Direct path and: Relayed path need evidence.

Why it matters

UWB secure ranging helps because distance is inferred from timing evidence.

UWB relay-resistance review comparing direct secure ranging with relayed false proximity
UWB relay-resistance review comparing direct secure ranging with relayed false proximity
iotclass.org

Major section

Why RSSI Proximity Fails and ToF Needs Protection

In a door pilot, run 50 authorized attempts from inside the allowed side and 50 denied attempts from the outside side.

  • If the allowed side produces 48/50 fresh, high-confidence ranges below 1.2 m, and the outside side produces 0/50 accepted unlock decisions, the boundary rule is behaving.
  • Keeping every raw coordinate forever can create privacy and governance risk without improving the operational decision.
  • The practitioner question is not "Did we get a range?" It is "Can this range be trusted enough for this action?" Signal strength offers little defense because strength is not distance.
iotclass.org

Major section

STS, Timing, and Acceptance Policy

Ordinary relays usually add delay, which should make a credential look farther away.

  • The IEEE 802.15.4z Scrambled Timestamp Sequence is a cryptographically generated pseudo-random sequence embedded in the ranging exchange.
  • The receiver timestamps energy that correlates with the expected STS, so a forged pulse that does not match should be rejected.
  • The dangerous distance-reduction attack is different: it tries to make the receiver timestamp an early signal and therefore subtract distance.

Key terms

STS protection
STS protection is meant to make that early signal unpredictable and unusable.
iotclass.org

Major section

STS, Timing, and Acceptance Policy (continued)

The timing arithmetic explains why policy cannot stop at "near." Radio waves travel at roughly 300,000,000 m/s, so 1 ns of one-way flight time is about 0.30 m.

  • STS protection is meant to make that early signal unpredictable and unusable.
  • If the credential is authorized, the side-of-door evidence matches, and confidence is high, the policy may allow the action.
  • If an attack path or poor geometry adds enough delay to report 3.8 m, the result should be denied as too far.
iotclass.org

Major section

Safety and Privacy

UWB can support safety workflows, but it should not be the only guard for a hazardous process unless the safety case explicitly supports that role.

  • Position evidence can be blocked, delayed, stale, or interpreted incorrectly.
  • Privacy review is also required.
  • Fine location evidence can reveal work patterns, personal movement, sensitive visits, or asset usage.
iotclass.org

Major section

Operating Control Loop

UWB applications need operations discipline after installation.

  • The reflector-bias preset below turns “layout changes” into a controlled retest.
  • A secure credential and a confident-looking angle do not by themselves prove that the application inferred the correct side of a cabinet, doorway, or safety boundary.
UWB application operations loop covering install, test, monitor, respond, and retest
UWB application operations loop covering install, test, monitor, respond, and retest
iotclass.org

Major section

Common Mistakes

Forgetting privacy: Fine location evidence requires retention, access, consent, and purpose controls.

  • Skipping authorization: A nearby credential still has to be allowed to perform the action.
  • Ignoring the wrong side of a boundary: Near a door is not the same as being on the permitted side.
  • No retest plan: Moved anchors, layout changes, and new materials can change behavior.
iotclass.org

Deck summary

Key takeaways

A distance estimate must be fresh, tied to the right identity, and inside a clear policy.

  • The reason UWB is useful in cars, phones, badges, locks, tools, and warehouse tags is not just centimeter-class positioning under good conditions.
  • The main reason to choose UWB is not that it is new or precise.
  • Secure access requires more than a short distance estimate.
  • Relay attacks try to make a far credential appear nearby by forwarding messages through another link.
iotclass.org

Retrieval practice

Recall check 1 of 3

Radio Remi says: answer from memory, then check your reasoning.

Q1How should a UWB position estimate be treated in a secure access decision?

AAs absolute proof of exactly who is standing at the door right now.
BAs evidence with confidence, freshness, and a fallback, not a magic location label.
CAs a full replacement for any credential or authorization check at the door.
DAs a value that never requires any fallback or manual override path.
Show answer

Answer: B UWB position is evidence with confidence and fallback rules for a decision, not a magic location label.

iotclass.org

Retrieval practice

Recall check 2 of 3

Radio Remi says: answer from memory, then check your reasoning.

Q2Why does IEEE 802.15.4z STS make UWB secure ranging stronger than RSSI-based proximity for relay-resistant access?

AUWB simply uses higher transmit power, so a relay cannot boost the signal enough.
BUWB encrypts an audio channel so the credential exchange cannot be overheard by a relay.
CRSSI is already accurate enough; relay attacks work only when the application ignores signal strength.
DSTS uses an unpredictable pulse sequence, so an attacker cannot forge early pulses to make time of flight look shorter.
Show answer

Answer: D IEEE 802.15.4z STS makes the valid pulse sequence unpredictable. That helps the receiver reject forged early pulses, while RSSI-only proximity remains vulnerable to relays, amplifiers, antennas, and orientation effects.

iotclass.org

Retrieval practice

Recall check 3 of 3

Radio Remi says: answer from memory, then check your reasoning.

Q3A UWB door system confirms that an authorized phone is nearby, but the confidence is low and the phone appears near the wrong side of the doorway. What should the application do?

ADeny or fall back to a safer manual procedure and record the low-confidence result.
BUnlock because UWB has already confirmed the phone is close.
CAccept the secure range result because the phone's credential has already passed authorization.
DStore the event forever so future analytics can decide whether it was safe.
Show answer

Answer: A UWB access control should combine authorization, fresh secure ranging, confidence, boundary policy, and fallback handling.

iotclass.org

Print reference

Answers

Answer key.

  1. B · UWB position is evidence with confidence and fallback rules for a decision, not a magic location label.
  2. D · IEEE 802.15.4z STS makes the valid pulse sequence unpredictable. That helps the receiver reject forged early pulses, while RSSI-only proximity remains vulnerable to relays, amplifiers, antennas, and orientation effects.
  3. A · UWB access control should combine authorization, fresh secure ranging, confidence, boundary policy, and fallback handling.
iotclass.org