Simplified synopsis: digital RF frames have preambles, sync symbols, and then bodies. When RX errors occur in the preamble or sync, the radio may "seek" to the next valid-looking preamble or sync. Since most digital RF protocols encode the preamble or the sync using the same symbol set as the body, there are byte sequences that mimic the preamble and sync of a wireless frame.
The RX errors we're talking about happen frequently.
So for instance, if my wireless network was unencrypted, and you DCC'd me on IM and sent me a giant file, and that file had repeated byte sequences that mimicked RF frames, you could inject frames onto my wireless network.
This is the moral equivalent of +++ATH0 for modems back in the day.
Cryptography for which the attacker
has no key is a much greater impediment to remote PIP
injection than it is to a local eavesdropper. This is because the attacker needs to know both the cryptographic
key and the counter or nonce. In the case of a known key
and nonce, an attacker could conceivably work backward
to product a block which, once encrypted, contains a PIP.
The exact procedure for doing so depends upon the presence of numerous cryptographic mistakes by the vector
protocol and is beyond the scope of this paper
This is amazing. I'd love to see someone pull this off.
Simplified synopsis: digital RF frames have preambles, sync symbols, and then bodies. When RX errors occur in the preamble or sync, the radio may "seek" to the next valid-looking preamble or sync. Since most digital RF protocols encode the preamble or the sync using the same symbol set as the body, there are byte sequences that mimic the preamble and sync of a wireless frame.
The RX errors we're talking about happen frequently.
So for instance, if my wireless network was unencrypted, and you DCC'd me on IM and sent me a giant file, and that file had repeated byte sequences that mimicked RF frames, you could inject frames onto my wireless network.
This is the moral equivalent of +++ATH0 for modems back in the day.
Crazy.
Cryptography for which the attacker has no key is a much greater impediment to remote PIP injection than it is to a local eavesdropper. This is because the attacker needs to know both the cryptographic key and the counter or nonce. In the case of a known key and nonce, an attacker could conceivably work backward to product a block which, once encrypted, contains a PIP. The exact procedure for doing so depends upon the presence of numerous cryptographic mistakes by the vector protocol and is beyond the scope of this paper
This is amazing. I'd love to see someone pull this off.