<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Resistance to Replay Attacks of Remote Control Protocols using the 433 MHz Radio Channel</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Olha Mykhaylova</string-name>
          <email>olha.o.mykhailova@lpnu.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Artem Stefankiv</string-name>
          <email>artem.stefankiv.kb.2020@lpnu.ua</email>
          <email>t@online.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Taras Nakonechny</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Taras Fedynyshyn</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Volodymyr Sokolov</string-name>
          <email>v.sokolov@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Borys Grinchenko Kyiv Metropolitan University</institution>
          ,
          <addr-line>18/2 Bulvarno-Kudriavska str., Kyiv, 04053</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Lviv Polytechnic National University</institution>
          ,
          <addr-line>12 Stepan Bandera str., Lviv, 79000</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>98</fpage>
      <lpage>110</lpage>
      <abstract>
        <p>This study focuses on the analysis of replay attacks, which pose a significant risk to remote control systems using the 433 MHz radio frequency band. A replay attack occurs when an attacker intercepts communications between two legitimate parties and resends the intercepted data to activate a remotely controlled system or commit identity theft. Special attention is paid to the study of the EV1527 protocol and its structure, as well as potential vulnerabilities that can be exploited by attackers. The study includes a detailed analysis of the design documentation on modules using the EV1527 protocol, as well as an assessment of the characteristics of the corresponding antennas and the features of working with hardware and software. The work also includes a comparative analysis of the technical means that can be used to carry out the attack and a demonstration of a practical attack using the HackRF One software-controlled transceiver in a laboratory setting. The main goal of the work is to demonstrate the mechanisms for implementing a replay attack on remote control systems with static code and to develop recommendations for improving the security of these systems. The results of the study are aimed at increasing the understanding of potential risks and vulnerabilities, as well as at determining the feasibility of using such protocols in modern physical security and access control systems.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Radio channel</kwd>
        <kwd>interception</kwd>
        <kwd>replay</kwd>
        <kwd>physical security</kwd>
        <kwd>PT2262</kwd>
        <kwd>HackRF One</kwd>
        <kwd>EV1527</kwd>
        <kwd>NanoVNA V2</kwd>
        <kwd>2</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Remote control systems are an important part
of modern security solutions, providing
convenience and efficiency in managing
physical perimeters—from barriers and
automatic gates to alarm systems. However,
radio communications, which are often the
backbone of these systems, can become
vulnerable, opening the door to potential
attacks [1, 2]. Particular attention in this
context is paid to the vulnerability of
remotecontrol protocols, particularly EV1527, which
can be used to implement signal replay attacks
[3–5].</p>
      <p>
        In this work, we focus on analyzing these
vulnerabilities, using both theoretical and
practical methods to demonstrate possible
attacks in a laboratory setting. The importance
of such research lies in the increasing reliance
on wireless technologies in security systems,
making them a potential target for attackers
and reflecting the need to develop more robust
security protocols [
        <xref ref-type="bibr" rid="ref1">6–8</xref>
        ].
      </p>
      <p>The motivation for this research was the
numerous cases of replay attacks highlighting
the vulnerability of existing systems. Our goal
is not only to identify and demonstrate
vulnerabilities but also to develop
recommendations for improving the security
of using remote control systems. To do this, we
conducted a detailed analysis of the
documentation of the EV1527 and PT2262
protocols and studied the principles of their
operation, message structure, and data
modulation. A comparative analysis of
equipment capable of carrying out such attacks
was also carried out, including the
softwarecontrolled HackRF One transceiver and the
NanoVNA V2.2 vector network analyzer [8–10].</p>
      <p>It is important to note that the development
of remote-control technology has deep roots in
history. From early host and wireless systems
developed in the late 19th century to meet the
control needs of autonomous vehicles,
including torpedoes, to modern wireless
devices that are an integral part of our daily
lives. For example, in the late 1930s, Philco
pioneered a wireless remote controller for
consumer electronic devices, known as
Mystery Control, which used low-frequency
radio transmission. This was a significant
breakthrough in remote control technology.
Another good example could be a set of
modern wearable [12] Bluetooth-connected
devices, which are also used as a part of a
Smart-home setup and may execute remote
control functions.</p>
      <p>Also, a significant step forward in the
development of remote-control technology
was the creation of the first television remote
control by Zenith Radio Corporation in 1950. It
was originally connected to the TV using a
wire, but in 1955 the “Flashmatic” wireless
remote was developed, which controlled the
TV using directional flashes of light [13, 14].</p>
      <p>The structure of the work includes a
literature review, methodology, analysis
results, comparative study, and discussion of
the results. We hope that this work will not
only highlight current challenges in remote
control security but also contribute to the
development of safer solutions in this area.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Analysis of Recent Research and Publications</title>
      <p>Current research in the field of security of
remote control and keyless entry protocols
emphasizes the use of dynamic codes,
especially focusing on the HCS301 protocol.
This protocol is used in keyless entry systems
for vehicles, including car alarms and car
starting systems. One of the key features of the
HCS301 is the use of a patented KeeLoq block
cipher based on a nonlinear feedback shift
register, which provides a high level of
security.</p>
      <p>One of the important studies conducted by
Tobias van Capelleven from Radboud
University Nijmegen is devoted to a
comparative analysis of the security of car
alarm systems based on the EV1527 protocol.
In his work, van Capelleven highlights the
vulnerability of EV1527 to replay attacks,
which calls into question its reliability in a
security context.</p>
      <p>In addition, other sources, such as articles
on the Yaoertai website, go into detail about
the mechanisms and features of the HCS301
Rolling Code Technology. These articles
provide information on the operation of the
HCS301, its benefits, and applications in
various fields including automotive and home
security systems. Particular attention is paid to
how HCS301 technology protects against
various types of attacks, including protection
against replay attacks.</p>
      <p>This analysis of current research and
publications highlights the importance of
understanding the various security protocols
and vulnerabilities that exist in modern remote
control and keyless entry systems. They
provide valuable information that can be used
to improve the security of these systems [11].</p>
    </sec>
    <sec id="sec-3">
      <title>3. Setting Objectives</title>
      <p>The main goal of this study is an in-depth
analysis of the EV1527 protocol, including its
design, principles of operation, and potential
vulnerabilities. The study involves a thorough
review of the design documentation of the
modules that use this protocol, as well as an
analysis of the main characteristics of the
antennas and the features of working with
hardware and software.</p>
      <p>The main tasks of the research include:
1. Analysis of the Design of the EV1527
Protocol: Studying the technical
structure and main components of the
protocol, as well as understanding its
functionality and data transmission
mechanisms.
2. Vulnerability Detection: Identifying
potential weaknesses in the EV1527
protocol, including its susceptibility to
replay attacks and other threats.
3. Comparative Analysis of Equipment:
Evaluation and comparison of different
types of equipment that can be used to
carry out attacks on systems using the
EV1527 protocol.
4. Practical Verification: Performing
experiments and tests in laboratory
conditions to verify theoretical
conclusions and identify real system
vulnerabilities.
5. Evaluation of Feasibility of Using the
Protocol: Based on the received data and
analysis, conclude the practicality and
safety of using the EV1527 protocol in
remote control systems.</p>
      <p>The results of this study will provide
valuable information on the reliability and
security of the EV1527 protocol, which is
critical for its application in security and
remote-control systems. This research is
expected to help developers and engineers in
choosing the most secure and efficient
solutions for their systems.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Analysis of EV1527</title>
    </sec>
    <sec id="sec-5">
      <title>Documentation</title>
    </sec>
    <sec id="sec-6">
      <title>Protocol</title>
      <p>EV1527 is a message encoder chip that uses the
protocol of the same name and was developed by
Silvan Chip Electronics Tech. Co. Ltd (PRC) [4].
This protocol and the microcircuit of the same
name and its clones are used in systems for
remote control of mechanisms, automation
systems, control panels for “smart home”
systems, self-made devices, etc. This widespread
use is due to the relative cheapness of the
microcircuit, the presence of a collision
prevention mechanism, and the simplicity of the
implementation of the receiver and transmitter.
There are ready-made solutions based on this
standard that can be easily integrated into the
existing structure, including access control
devices such as barriers, automatic gates,
automatic shutters, etc.</p>
      <p>The EV1527 chip is manufactured in DIP-8
and TSOP-8 packages and has four data inputs,
one clock input, power inputs, and one code
output that can be transmitted via radio. The
main frequencies for communication are 433
MHz for European countries and 315 MHz for
the USA and Canada. The available
documentation shows a typical circuit for
turning on a microcircuit with a radio
transmitter [4, p. 3] (Fig.1).
The protocol used by this chip is more resistant
to overrun and collision attacks. The protocol
provides for one type of message with a fixed
structure. The message consists of a preamble
and a main part (Fig. 2).
The preamble is 32 bits long and is used to
synchronize the transmitter and receiver. The
structure of the preamble is as follows: one
period of the dominant state and 31 periods of
the recessive state at the output of the chip [4,
p. 2] (Fig. 3).
The main part of the message consists of a key
code and four data bits. The main part of the
message is coded using the sequences “3–1”
(three periods in the dominant state and one
period in the recessive state at the output of
the microcircuit) to transmit a logical one and
the inverted sequence “1–3” to transmit a
logical zero [4, p. 2] (Fig. 4). Analogous coding
is used in the microcircuit PT2262 [5, p. 7].
The key code is specified in twenty bits, which
allows for the existence of 1048576 unique
keys and greatly complicates the execution of a
traversal attack since it is necessary to go
through not only the above number of key
codes but also the 16 button codes used in the
attacked system. The total number of
combinations for a complete search is
16777216 messages.</p>
      <p>However, this protocol uses static code and
does not use cryptographic means to increase
the level of security. The message does not
change after each generation, so a replay attack
is possible [3].</p>
    </sec>
    <sec id="sec-7">
      <title>5. Comparative Analysis of</title>
    </sec>
    <sec id="sec-8">
      <title>EV1527 and PT2262 Protocols</title>
      <p>This section provides a comparative analysis of
two popular remote control protocols: EV1527
and PT2262. Both protocols are often used in
remote control systems, but they have some
key differences.</p>
      <p>EV1527 is a chip developed by Silvan Chip
Electronics Tech. Co. Ltd (PRC), which uses a
fixed message format and does not have
cryptographic protection. The protocol
provides one type of message with a fixed
structure, including a 32-bit preamble and a
main part with a key code and four data bits.
EV1527 uses a collision avoidance mechanism
and is easy to implement.</p>
      <p>PT2262, on the other hand, can have
different message configurations from 6 to 12
bits of key code and 0 to 6 bits of button code.
The protocol provides a synchronization
sequence at the end of the message, which is a
change from EV1527. PT2262 does not have
built-in collision mitigation mechanisms and
uses static addressing.</p>
      <p>One key difference is that if a transmitter is
lost, PT2262-based systems require a code
change on the receiver and other transmitters
to revoke the lost transmitter’s access. The
system based on EV1527 does not have this
drawback, where you can revoke access by
deleting the record of the lost transmitter from
the receiver’s memory.</p>
      <p>In general, although both protocols lack
cryptographic security and are vulnerable to
replay attacks, EV1527 proves to be more
flexible to use and adapt to different user
needs. This makes it a more attractive choice
for modern remote-control systems, despite
existing vulnerabilities.
A replay attack is a form of cyber-attack where an
attacker intercepts communications between
two legitimate parties and resends the
intercepted data. This method is used to gain
unauthorized access to a system or initiate
unwanted actions on behalf of a legitimate
user. Unlike a man-in-the-middle attack, where
the attacker actively interferes with
communication, a replay attack is passive.</p>
      <p>The attack scenario can be described as
follows (Fig. 5):
1. An attacker, whom we’ll call Eve, listens
to the radio frequency range in which the
signal’s receiver and transmitter operate
and record the signal.
2. Alice sends a signal to Bob to activate a
certain mechanism, such as opening an
automatic gate.
3. Bob receives and decodes the signal, and
if it matches the stored code, acts.
4. Eve replays the intercepted signal, and
the system, vulnerable to a replay attack,
perceives this as a signal from Alice and
performs a response action.
At the same time, the attacker must have
opportunities for passive interception and
reproduction.</p>
      <p>The importance of implementing stronger
security mechanisms in these systems is
becoming apparent to reduce the risks of
unauthorized access or control.</p>
      <p>To protect against replay attacks, remote
control systems must incorporate additional
layers of security, such as cryptographic
encoding or the use of dynamic codes that
change with each transmission. For example, the
use of technologies similar to the HCS301 Rolling
Code discussed earlier can significantly improve
the security of remote-control systems.
A replay attack is particularly dangerous
because it does not require the attacker to have
deep technical knowledge or sophisticated
equipment. The ease of implementation of such
attacks makes them a threat to a wide range of
wireless systems, from home automation
systems to more sophisticated access control
systems.</p>
      <p>Understanding these risks and vulnerabilities
is critical for security developers and hardware
manufacturers. This research highlights the need
to continuously update cybersecurity knowledge
and develop more resilient and robust solutions
to prevent similar attacks in the future.</p>
    </sec>
    <sec id="sec-9">
      <title>7. Comparative Analysis of the</title>
    </sec>
    <sec id="sec-10">
      <title>Main Characteristics of</title>
    </sec>
    <sec id="sec-11">
      <title>Antennas for Signal</title>
    </sec>
    <sec id="sec-12">
      <title>Interception</title>
      <p>Conducting a comparative analysis of the main
characteristics of the antennas allows you to
determine the suitability of each of the
available antennas for signal interception and
re-play and to identify their shortcomings
and/or defects.</p>
      <p>The existing receiver and transmitters use
the LPD433 band (433.050 MHz—434.79
MHz), which is within the 70 cm radio amateur
band (430 MHz—440 MHz).</p>
      <p>The range of the LPD433 is divided into 69
channels with a step of 25 kHz, this range is
used for low-power, short-range transmitters.
Short-range transmitters include remote
control systems, home automation systems,
car keyless access systems, low-power
portable walkie-talkies, etc. In Ukraine, the use
of this range is regulated by DSTU ETSI EN 300
220-1:2018 and DSTU ETSI EN 300
2202:2017, which is a harmonization of the
standard ETSI EN 300 220-1 V3.2.1 [15] and
ETSI EN 300 220-2 V3 .1.1 [16]. The limits of
the range are determined by the
recommendation document authored by
CEPT/ERC Rec 70-03 [9]. In the USA, this range
is not used for unlicensed broadcasting, so the
Federal Communications Commission (FCC)
allocated the 315 MHz range for short-term
operation of short-range devices with a limit
on the output electric field strength of
300 μV/m with a transmission duration of up
to 3 minutes [11, with. 20].</p>
      <p>The main requirement for antennas is the
compliance of their operating frequency range
with a given band with a minimum value of
SWR.</p>
      <p>The portable electrical circuit analyzer
NanoVNA [17] and the NanoVNA-Saver
software [18] were used for the comparative
analysis. Four types of antennas were
compared according to the parameters of the
standing wave coefficient and the operating
frequency range. The limit value of SWR for
determining the range of operating
frequencies is 2.000.</p>
      <p>The antennas were measured in vertical
polarization and averaged over five
consecutive measurements.
7.1. Antenna 1
Telescopic antenna with SMA connector, with
a minimum length of 17 cm and a maximum
length of 102 cm. The measurement was
carried out in two antenna length
configurations—minimum and maximum.</p>
      <p>Below are the results of measuring the
parameters of antenna 1 at the minimum
length (Fig. 6, Table 1) and the maximum
length (Fig. 7, Table 2).</p>
      <p>a) b)
Figure 6: Parameters of antenna 1 at the
minimum length: (a) Smith chart and (b)
frequency dependence graph
a) b)
Figure 7: Parameters of antenna 1 at the
maximum length: (a) Smith chart and (b) graph
of dependence of SWR on frequency
7.2. Antenna 2
Telescopic antenna with SMA connector,
minimum length 11.5 cm and maximum length
47.5 cm. Four copies of this antenna are
available. For each of the specimens,
measurements were made in a length
configuration that corresponds to a quarter of
the wavelength of the target range (17.5 cm).
Using the method of pairwise comparison, the
specimen with the best characteristics was
selected (Figs. 10–12). The minimum value of
the standing wave coefficient in terms of
voltage, the frequency at which the minimum
value of CSC was reached, and the input
resistance of the antenna at the frequency with
the minimum CSC were chosen as the criteria
for comparison. The comparison took place in
two rounds, in the first two pairs of specimens
(No. 1 and No. 2 and No. 3 and No. 4,
respectively), were compared in the second
round, and specimens with better
characteristics from the previous rounds were
compared.</p>
      <p>Graphs were constructed using the
sci-kitof library for the Python programming
language [10]. This library supports the
creation and import of Touchstone save files,
which are used in most circuit analyzers in the
NanoVNA-Saver program.</p>
      <p>Round 1.</p>
      <p>A pair of copies No. 1 and No. 2 is compared.
The results of the comparison are shown in
Fig.8.</p>
      <p>a) b)
Figure 8: Parameters of specimens No. 1 and
No. 2 of antenna 2 at the optimal length: (a)
Smith diagram and (b) graph of dependence of
SWR on frequency.</p>
      <p>In Fig. 8, we can see that the values of the wave
resistance for both specimens on the SWR 1.0
line are quite close. Still, specimen No. 2 shows
an additional resonance at a frequency of 882
MHz, uncharacteristic of specimen No. 1. Also,
Fig. 8 demonstrates the superiority of instance
#1 over instance #2 in the 430–440 MHz range.
The minimum value of SWR of instance #2 is at
the beginning of the range and reaches a value
of 1.357 at the end of this range. Specimen No.
1 shows a slightly larger value of SWR of 1.208
at a frequency of 435.058 MHz.</p>
      <p>From the conducted data analysis, it can be
concluded that instance 2 shows the best
indicators in this range.</p>
      <p>A comparison of pair 2 (specimens #3 and
#4) is shown in Fig. 9.</p>
      <p>a) b)
Figure 9: Parameters of instances 3 and 4 of
antenna 2 at the optimal length: (a) Smith
diagram and (b) graph of the dependence of
CSC on frequency
In Fig. 10 we can observe that the values of the
reactive component of the support for both
instances on the SWR 1.0 line are quite close.
Still, instance 2 demonstrates an additional
resonance at a frequency of 882 MHz, which is
uncharacteristic of instance 1.</p>
      <p>Fig. 11 shows the advantage of Instance 1
over Instance 2 in the 430–440 MHz range.
Instance 2’s minimum SWR value is at the
beginning of the range and reaches a value of
1.357 at the end of the range. Instance 1
exhibits a slightly higher SWR of 1.208 at
435.058 MHz.</p>
      <p>From the data analysis, we can conclude
that specimen 2 demonstrates the best
performance in this range.</p>
      <p>A comparison of Pair 2 (Instances №3 and
№4) is shown in Figs. 12–13.</p>
      <p>a) b)
Figure 10: Parameters of instances 1 and 3 of
antenna 2 at optimal length: (a) Smith chart
and (b) graph of SWR versus frequency
Considering the above similarity between the
frequencies of the minimum SWR value and the
corresponding values shown in Fig. 15, we can
conclude that among the available ones, the
best performance is demonstrated by
specimen No. 3, and it is suitable for working
with the target signal.
7.3. Antenna 3
The quad-band car antenna with PL-259
connector is part of the QYT KT-7900D car
radio kit, which is designed to operate in the
136–174 MHz, 220–270 MHz, 350–390 MHz
and 400-4 bands. The antenna is equipped
with a magnetic stand with a SO-239 input
connector and a 7-meter long SYWV 50-3 cable
with a PL-259 connector. Below are the results
of measuring the parameters of antenna 3 in
the signal frequency range (Fig. 13, Table 3).
Blue color indicates the measurement of
parameters when connecting the antenna
through the supplied magnetic stand, and
black—is when connecting the antenna with a
5-meter-long RG-58U70 cable through an
SMA-SO-239 adapter to the antenna.</p>
      <p>a) b)
Figure 11: Antenna 3 parameters: (a) Smith
chart and (b) graph of SWR versus frequency
From Fig. 11, it can be observed that the
magnetic stand hurts the antenna performance.
There is no SWR peak in the 440 MHz range
declared by the manufacturer when using a
magnetic stand.</p>
      <p>Mark 1 Mark 2 Mark 3
Frequency, MHz 419.373 439.469 451.821
SWR by voltage 1.998 1.022 1.999
Return losses, dB –9.552 –39.356 –9.551
Impedance, Ohm 54.9–j36.7 51.0–j0.3 25.5+j5.7</p>
      <p>The results indicate that this antenna can
handle the target signal, but its performance
will be less optimal than that of Antenna 2.
7.4. Antenna 4
A “Ground plane” antenna with a BNC
connector and a complete BNC-SMA cable of
RG-174 type, 3 meters long, the range declared
by the manufacturer is 65–375 MHz. The
antenna consists of a printed circuit board on
which BNC connectors are fixed for the output
and input of the central element and holes for
four grounding elements, made in the form of
telescopic antennas with a length of 20 to 95
cm. Experimentally, it was possible to tune this
antenna to the target range (length of the
central element—47.5 cm, length of grounding
elements—51.5 cm). The antenna was
mounted on a homemade mast at a height of
approximately 175 cm from the floor level.
Below are measurements of this antenna in the
above optimal configuration (Fig. 12, Tab.4).
a) b)
Figure 12: Parameters of antenna 4 at optimal
length: (a) Smith chart and (b) graph of SWR
versus frequency
The measurement results are in the same
range and do not go beyond the established
range, limited by the SWR value of 2.000.</p>
    </sec>
    <sec id="sec-13">
      <title>8. The process of performing a replay attack demonstration</title>
      <p>In this chapter, we will focus on the detailed
study and practical application of signal
interception and replay techniques in wireless
communication systems. Our goal is to explore
and demonstrate how an attacker can use
specialized hardware and software to
intercept and imitate signals to illegally access
or control systems. This process, known as a
replay attack, is a key element in studying
wireless security and developing effective
countermeasures [3–5, 9, 15, 16].</p>
      <p>Equipment:
• Signal transmitters.
• Signal receiver with actuator.
• Transceiver with software control HackRF</p>
      <p>One.
• USB 2.0 A—USB 2.0 Micro-B cable.
• Antenna and connecting cables with
adapters.
• Computer running Kali Linux.
• Radiofrequency spectrum analyzer
gqrx [9].
• Universal Radio Hacker software package
for reverse engineering of wireless
protocols [19].</p>
      <p>Description of equipment:
1. Signal transmitters: transmitter A is a
miniature control transmitter with two
buttons labeled A and B and an LED, black
with silver accents, powered by a 23A cell;
transmitter B is a miniature control
transmitter with four buttons marked A, B,
C, D, and LED, silver color with protective
cover, powered by a 23A element.
2. Signal receiver with actuator—developed
by JoyDeal, a compact receiver and
command decoder of EV1527 and PT2262
standards with a memory for 15 buttons
and a standard helical antenna. The supply
voltage ranges from 3.6 to 24 V; an LED
with a limiting resistor is used as an
actuator.
3. HackRF One software-controlled
transceiver—portable transceiver with
software control HackRF One in the
PortaPack H1 version with the ability to
operate autonomously. The transceiver
has connectors for connecting an antenna,
a built-in oscillator output, and a
synchronization input, as well as a USB
Micro-B power/data connector and a 3.5
mm TRS connector for connecting
headphones and outputting a
demodulated audio signal.
4. USB 2.0 A to USB 2.0 Micro-B cable—data
cable with USB 2.0 A and USB 2.0 Micro-B
connectors, 1 meter long.
5. Antenna and connecting cables with
adapters—instance 3 of antenna 2 was
selected as the working antenna; the
comparative analysis process is described
in paragraph 7. Adapters and connecting
cables are not used.
6. Computer running Kali Linux—Asus Vivo
book 15 X509FJ laptop with Kali Linux
2024.1 special purpose operating system
installed. A description of the procedure
for preparing a computer to perform an
attack is given below.</p>
      <p>Attack Sequence:
• The attacker starts intercepting the signal
using Universal Radio Hacker and waits
for the legitimate user (victim) to send a
signal.
• A legitimate user sends a signal.
• The receiver performs the specified action.
• An attacker, using Universal Radio Hacker,
sends a signal imitating a legitimate user of
the system (victim).
• The receiver performs the specified action
because it cannot distinguish an attacker
from a legitimate user.</p>
      <p>Performing an attack:
1. System preparation. To prepare the
system to work with HackRF One, you need to
install the hackrf, hackrf-doc, hackrf-firmware,
libhackrf-dev, libhackrf0 packages from the
operating system’s package manager
repositories.</p>
      <p>2. Receiver programming. Programming
the receiver occurs by pressing the programming
button a certain number of times to switch to the
required switching mode (instant, switching,
latching, timer) and pressing the desired button
on the transmitter. As previously noted, the
receiver memory has 15 cells. The following
positions have been programmed:
2.1. Button A of transmitter A to
instantaneous mode.
2.2. Button B of the transmitter to switch
mode.
2.3. Button A of transmitter B to timer mode
with a delay of 5 seconds.</p>
      <p>3. Assessing the radio frequency range and
checking signal reception.</p>
      <p>The radio frequency spectrum is estimated
using gqrx [20].</p>
      <p>Gqrx is a program for real-time radio
frequency spectrum analysis, distributed under
the open GPL license [9].</p>
      <p>Execution order:
• Connect an antenna to HackRF One and
connect it to a computer.
• Switch HackRF One to computer mode.
• Launch gqrx on your computer.
• Select HackRF One from the list of devices
and establish a connection.
• Set the receiving frequency to 433.92 MHz.
• Enable monitoring.</p>
      <p>A waterfall graph and a line graph of the signal
will appear on the screen. When you press the
buttons on transmitter A, we observe the
appearance of a signal on the graphs (Fig. 14).
We will carry out a similar procedure for buttons
A, B, C, and D of transmitter B (Fig. 15):
a)</p>
      <p>b)
c) d)
Figure 35: Waterfall graphs of transmitter B
button signals: (a) button A; (b) button B;
(c) button C and (d) button D
From the data obtained, we can conclude that the
connection and configuration of the transceiver
and computer are correct, and assume that
transmitter B is partially operational or does not
have the declared functions. Signals from buttons
that do not transmit a signal (buttons B, C, and D
of transmitter B) are not considered further.
4. Signal interception and analysis.</p>
      <p>To intercept and analyze the signal, the
Universal Radio Hacker software package is used
[19]. This software package has the capabilities
to record signals, analyze them, reverse engineer
wireless protocols, play back recorded signals,
and create new signals based on arbitrary data.
This software package is written in Python and is
distributed under the free license GPLv3.
Installation is done using the pipx package
manager.</p>
      <p>Execution order:
• Connect an antenna to HackRF One and
connect it to a computer.
• Switch HackRF One to computer mode.
• In the File menu, select Record signal.
• Select HackRF One from the list of
available devices.
• Click the update button, which is located
opposite the “Device Identifier” field, and
wait for the serial number to appear in the
field.
• Set the interception frequency to
433.92 MHz.
• Press the “Start” button.
• Wait for the signal to arrive.
• After recording the signal, press the “Stop”
button.
• Save the signal to a file using the Save
button.
• Close the recording window, the saved
signal will automatically open in the main
program window.</p>
      <p>Signals from transmitters A and B,
recognized by the JoyDeal receiver (buttons A
and B of transmitter A and button A of
transmitter B) were intercepted (Fig. 16) and
interpreted (Fig. 17).</p>
      <p>The signal was intercepted with a
configured transceiver bandwidth of 2.0 MHz
and a scanning frequency of 2 million samples
per second.</p>
    </sec>
    <sec id="sec-14">
      <title>9. Conclusions</title>
      <p>In the modern world, where digital technologies
penetrate all areas of our lives, the issue of
security becomes very important. Remote
control systems that use static codes are open to
several potential threats, of which the replay
attack is one of the simplest and most effective.</p>
      <p>This publication analyzes in detail the
vulnerability of the EV1527 protocol, widely
used in simple remote-control systems, to this
type of attack. The laboratory study
demonstrates how a replay attack can be carried
out using specialized equipment, thereby
confirming the critical vulnerability of the
protocol.</p>
      <p>The importance of this research cannot be
overstated, as it highlights fundamental security
flaws in static code-based systems. The
conclusions we have reached provide a strong
argument in favor of moving from using
outdated technologies to more modern and
secure solutions. Systems using dynamic codes,
such as HCS301, provide a significantly higher
level of security by using cryptographic data
protection techniques that make such attacks
difficult or even impossible.</p>
      <p>However, the transition to safer technologies
must be deliberate and systematic. It is necessary
to consider not only the security of protocols but
also the specifics of their application, the
convenience of end users, and the cost of
implementation. In some cases, the use of
general-purpose or specialized protocols that
include complex security mechanisms may be
more appropriate. It is especially applicable to
objects of critical infrastructure, which
undoubtedly need to be well-protected and
resilient from a cybersecurity perspective [21].</p>
      <p>Considering the research conducted, it can be
concluded that the security of remote-control
systems is a critical aspect that requires
immediate attention. The choice of equipment
and technologies should be based not only on
their effectiveness and ease of use but also on
ensuring an adequate level of safety. The use of
dynamic codes and cryptographic protocols is a
key step towards increasing the security of
remotely controlled systems from unauthorized
access.
Information Technologies (2023) 1–5. [20] Princeton Technology Corp, PT2262
doi: 10.1109/CSIT61576.2023.10324031. remote control encoder, LCSC. URL:
[8] V. Sokolov, P. Skladannyi, V. Astapenya, https://datasheet.lcsc.com/lcsc/18092
Bluetooth Low-Energy Beacon
91408_PTC-Princeton-Tech-PT2262Resistance to Jamming Attack, in: IEEE S_C42793.pdf
13th International Conference on [21] S. Yevseiev, et al., Modeling of Security
Electronics and Information Systems for Critical Infrastructure
Technologies (2023) 270–274. doi: Facilities (2022). doi:
10.15587/97810.1109/ELIT61488.2023.10310815. 617-7319-57-2.
[9] Gqrx SDR—Open source software
defined radio by Alexandru Csete</p>
      <p>OZ9AEC. URL: https://www.gqrx.dk/
[10] GitHub—jopohl/urh: Universal Radio</p>
      <p>Hacker: Investigate Wireless Protocols
Like a Boss, GitHub. URL:
https://github.com/jopohl/urh
[11] History of Remote Control, Wikipedia.</p>
      <p>URL: https://en.wikipedia.org/wiki/</p>
      <p>Remote_control#History
[12] I. Opirskyy, et al., Security Research of</p>
      <p>Bluetooth Devices Based on Smart
Watches, Ukrainian Sci. J. Inf. Secur.
29(1) (2023). doi:
10.18372/22255036.29.17548.
[13] What is the History of the Remote</p>
      <p>Control? HowStuffWorks. URL:
https://science.howstuffworks.com/inn
ovation/everyday-innovations/remotecontrol-history.htm
[14] S. Yevseiev, et al., Method of Assessment
of Frequency Resolution for Aircraft,
Eastern-European J. Enterprise Technol.
2, no. 9(122) (2023) 34–45. doi:
10.15587/1729-4061.2023.277898.
[15] Small Range Radio Equipment Operating
in the Frequency Range from 25 MHz to
1000 MHz, Part 2. General Technical
Requirements, DSTU ETSI EN 300
2202:2017 (2019).
[16]
GitHub—NanoVNA-Saver/nanovnasaver: A tool for reading, displaying and
saving data from the NanoVNA, GitHub.</p>
      <p>URL:
https://github.com/NanoVNA</p>
      <p>Saver/nanovna-saver
[17] NanoVNA|Very tiny handheld Vector</p>
      <p>Network Analyzer. URL:
https://nanovna.com/
[18] Open Source RF Engineering. GitHub—
scikit-rf/scikit-rf: RF and Microwave
Engineering Scikit. GitHub. URL:
https://github.com/scikit-rf/scikit-rf
[19] Rec 70-03, Relating to the Use of
Short</p>
      <p>Range Devices (SRD), Montreaux: CEPT
(1997).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>M.</given-names>
            <surname>TajDini</surname>
          </string-name>
          , V. Sokolov,
          <string-name>
            <given-names>P.</given-names>
            <surname>Skladannyi</surname>
          </string-name>
          ,
          <article-title>Performing Sniffing and Spoofing Attack Against ADS-B and Mode S using Software Define Radio</article-title>
          ,
          <source>in: IEEE International Conference on Information and Telecommunication Technologies and Radio Electronics</source>
          (
          <year>2021</year>
          )
          <fpage>7</fpage>
          -
          <lpage>11</lpage>
          . doi:
          <volume>10</volume>
          .1109/UkrMiCo52950.
          <year>2021</year>
          .
          <volume>9716665</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>M. TajDini</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          <string-name>
            <surname>Sokolov</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          <string-name>
            <surname>Buriachok</surname>
          </string-name>
          ,
          <article-title>Men-in-the-Middle Attack Simulation on Low Energy Wireless Devices using Software Define Radio</article-title>
          ,
          <source>in: 8th International Conference on "Mathematics. Information Technologies. Education": Modern Machine Learning Technologies and Data Science</source>
          , vol.
          <volume>2386</volume>
          (
          <year>2019</year>
          )
          <fpage>287</fpage>
          -
          <lpage>296</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <given-names>R.</given-names>
            <surname>Banakh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Piskozub</surname>
          </string-name>
          , Attackers'
          <article-title>Wi-Fi Devices Metadata Interception for Their Location Identification</article-title>
          ,
          <source>IEEE 4th International Symposium on Wireless Systems within the International Conferences on Intelligent Data Acquisition and Advanced Computing Systems</source>
          <volume>8525538</volume>
          (
          <year>2018</year>
          )
          <fpage>112</fpage>
          -
          <lpage>116</lpage>
          . doi:
          <volume>10</volume>
          .1109/IDAACS-SWS.
          <year>2018</year>
          .
          <volume>8525538</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <article-title>Building a Poor Man's Quarter-Wave 433MHz Antenna: Antenna's Construction, Element14</article-title>
          . URL: https://community.element14.com/cha llenges-projects/project14/rf/b/blog /posts/building
          <article-title>-a-poor-man-s-quarterwave-433mhz-antenna-antenna-sconstruction Small Range Radio Equipment Operating in the Frequency Range from 25 MHz to 1000 MHz, Part 1</article-title>
          .
          <string-name>
            <given-names>Technical</given-names>
            <surname>Characteristics</surname>
          </string-name>
          and Test Methods,
          <source>DSTU ETSI EN</source>
          <volume>300</volume>
          <fpage>220</fpage>
          -
          <lpage>1</lpage>
          :
          <year>2018</year>
          (
          <year>2018</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Skladannyi</surname>
          </string-name>
          , N. Korshun, ZigBee Network Resistance to Jamming Attacks,
          <source>in: IEEE 6th International Conference on Information and Telecommunication Technologies and Radio Electronics</source>
          (
          <year>2023</year>
          )
          <fpage>161</fpage>
          -
          <lpage>165</lpage>
          . doi:
          <volume>10</volume>
          .1109/UkrMiCo61577.
          <year>2023</year>
          .
          <volume>10380360</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Skladannyi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Platonenko</surname>
          </string-name>
          ,
          <article-title>Jump-Stay Jamming Attack on Wi-Fi Systems</article-title>
          , in: IEEE 18th International Conference on Computer Science and
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>