Timestamps Unchained: Toward Secure Distance-Bounding on Commodity Wi-Fi Hardware
Distance-bounding protocols provide strong security guarantees, yet their secure realization depends on high-precision physical-layer timestamping of signal transmission and reception. In principle, modern commodity IEEE 802.11 chipsets fulfill these technical requirements. However, distance-bounding research and experimentation on Wi-Fi remain severely limited, as the required high-precision timestamping functionality on 802.11 hardware is tightly coupled to fixed protocol exchanges (e.g., FTM) implemented in closed-source firmware. This restricts the freedom of open research. Our work overcomes this hurdle by reverse-engineering the high-precision timestamping pipeline of the ESP32-C3 Wi-Fi stack. The analysis reveals that the ESP32-C3 hardware generates precise timestamps for ordinary OFDM frames, not only for FTM-associated ones. This unexposed capability enables precise timestamping of ordinary Wi-Fi traffic and forms the technical basis for implementing custom time-of-flight protocols on low-cost commodity devices. Drawing on this capability, we present the first open-source library extension exposing high-precision timestamping primitives on commodity IEEE 802.11 hardware. To demonstrate the practical utility of our library extension, we implement a proof-of-concept authenticated distance-bounding protocol. Our implementation showcases flexible timing, application-defined frame content, and fully open protocol logic beyond standardized exchanges. Experimental evaluation under line-of-sight conditions shows that proximity decisions with meter-level granularity are achievable. Overall, our work provides an open and auditable foundation for conducting and deploying security research based on time-of-flight on widely available IEEE 802.11 devices.
Timestamps Unchained: Toward Secure Distance-Bounding on Commodity Wi-Fi Hardware
WiSec '26: Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks
| Authors: | Maximilian Tschirschnitz, Daniel Kirschten, Viktor Boskovski, Simon Neuenhausen, and Jens Grossklags |
| Year/month: | 2026/7 |
| Booktitle: | WiSec '26: Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks |
| Editor: | ACM |
| Volume: | 19 |
| Fulltext: | preprint_timestamping_unchained.pdf click here |
Abstract |
|
| Distance-bounding protocols provide strong security guarantees, yet their secure realization depends on high-precision physical-layer timestamping of signal transmission and reception. In principle, modern commodity IEEE 802.11 chipsets fulfill these technical requirements. However, distance-bounding research and experimentation on Wi-Fi remain severely limited, as the required high-precision timestamping functionality on 802.11 hardware is tightly coupled to fixed protocol exchanges (e.g., FTM) implemented in closed-source firmware. This restricts the freedom of open research. Our work overcomes this hurdle by reverse-engineering the high-precision timestamping pipeline of the ESP32-C3 Wi-Fi stack. The analysis reveals that the ESP32-C3 hardware generates precise timestamps for ordinary OFDM frames, not only for FTM-associated ones. This unexposed capability enables precise timestamping of ordinary Wi-Fi traffic and forms the technical basis for implementing custom time-of-flight protocols on low-cost commodity devices. Drawing on this capability, we present the first open-source library extension exposing high-precision timestamping primitives on commodity IEEE 802.11 hardware. To demonstrate the practical utility of our library extension, we implement a proof-of-concept authenticated distance-bounding protocol. Our implementation showcases flexible timing, application-defined frame content, and fully open protocol logic beyond standardized exchanges. Experimental evaluation under line-of-sight conditions shows that proximity decisions with meter-level granularity are achievable. Overall, our work provides an open and auditable foundation for conducting and deploying security research based on time-of-flight on widely available IEEE 802.11 devices. | |
Bibtex:
@inproceedings { https://doi.org/10.1145/3765613.3811688,author = { Maximilian Tschirschnitz and Daniel Kirschten and Viktor Boskovski and Simon Neuenhausen and Jens Grossklags},
title = { Timestamps Unchained: Toward Secure Distance-Bounding on Commodity Wi-Fi Hardware },
year = { 2026 },
month = { July },
booktitle = { WiSec '26: Proceedings of the 19th ACM Conference on Security and Privacy in Wireless and Mobile Networks },
volume = { 19 },
editor = { ACM },
url = { https://dl.acm.org/doi/abs/10.1145/3765613.3811688 },
url = {https://www.sec.in.tum.de/i20/publications/timestamps-unchained-toward-secure-distance-bounding-on-commodity-wi-fi-hardware/@@download/file/preprint_timestamping_unchained.pdf}
}
