Next-Gen UWB Key Fobs Aim to Close the Relay Attack Loophole

Car theft has entered a new era where criminals are more likely to hack keyless entry systems than to pick a physical lock. Official data from the U.K. shows that a significant majority of vehicle thefts now involve keyless entry methods, including relay attacks. In response, chipmakers are developing advanced ultra-wideband (UWB) security systems designed to eliminate the vulnerabilities that tech-savvy thieves exploit.
The core problem with previous keyless systems is that they often verify only whether a key is valid, not its physical distance from the car. Even when UWB technology is used to measure distance, automakers sometimes treat it as an optional feature. When UWB readings become unreliable—such as when a key fob is buried in a bag—the system may fall back to ignoring distance data altogether. This creates a loophole that thieves can exploit using two cheap radios that relay signals between the car and the key fob, making the key appear to be right next to the vehicle when it is actually inside a house.
STMicroelectronics has released its new ST64UWB line of security chips, which enforce distance verification based on signal travel time. Unlike signal strength, which can be amplified or spoofed, the timing of UWB signals cannot be manipulated to make a key appear closer than it is. According to Neal Patwari, a professor at the University of Utah, attackers can only delay the signal, which makes the key appear farther away, not closer. This fundamental physical constraint allows automakers to treat proximity as a reliable security check.
However, UWB does not solve every wireless vulnerability. Attackers can still jam the radio channel, preventing a lock command from being received. While this does not grant access, it can leave a car unlocked. But as Patwari notes, drivers will typically notice that their headlights did not flash and will press the lock button again. The bigger remaining challenge is ensuring that vehicles always require distance verification and do not offer a fallback that relaxes this requirement. Chipmakers are betting that improved reliability will make it easier for automakers to enforce strict proximity checks, thereby making relay attacks far harder to execute.
What do you think?