Method and system for submitting transactions using RF ranging while protecting user privacy
Verifying the authenticity of the network, generating session keys and secure communications through mobile devices in the UWB network, solving the problem of insufficient user privacy protection in improving convenience of RFID systems, and realizing the anonymous and secure information submission of users in the UWB network.
Patent Information
- Application Number
- CN202110519886.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-05-28
- Filing Date
- 2021-05-10
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-05-10
AI Technical Summary
While the existing RFID system improves convenience, users' privacy protection is insufficient and vulnerable to attacks.
Mobile devices in the UWB network are used to commit transactions through multiple anchors, including verifying network authenticity, generating session keys, secure communications and location tracking, and submitting sensitive information only within the trigger area.
The protection of user privacy is implemented in the UWB network, ensuring anonymity in non-triggered areas and only revealing user identity in the triggered areas, enhancing security and privacy.
Smart Images

Figure CN113794988B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of RF communication devices, and more particularly to RF communication devices that can submit transactions by interacting with other systems while protecting user privacy. More specifically, the present invention relates to a method for submitting transactions with a mobile device within a UWB network including a plurality of anchors, the UWB network covering a predetermined area having at least one trigger area. In addition, the present invention relates to a corresponding system. Background Art
[0002] RFID-based technologies are widely used in transportation and access control systems. The user holds the card close to the reader and presses it to conduct a transaction. These systems provide a relatively good protection of user privacy because the communication range is short (a few centimeters), and the card can only be accessed when the user actually triggers an RFID transaction.
[0003] To improve usability and convenience, it is expected to replace short-range RFID systems with RF technologies having less restricted communication ranges, such as ultra-wideband (UWB) technology. With such systems having a range of up to tens of meters, transactions can be carried out seamlessly because the user will not have to hold his tag / move close to the reader but only needs to move through a designated area. However, this convenience comes at a cost because it is also easier for attackers to monitor transactions to attack the user's privacy.
[0004] Therefore, a way to overcome the above-mentioned drawbacks may be needed. Summary of the Invention
[0005] This need can be met by the subject matter of the independent claims. Advantageous embodiments of the present invention are set forth in the dependent claims.
[0006] According to a first aspect, there is provided a method for submitting a transaction with a mobile device within a UWB (ultra-wideband) network including a plurality of anchors, the UWB network covering a predetermined area having at least one trigger area, the method comprising: (a) waking up the mobile device after it enters the predetermined area; (b) receiving initial network data at the mobile device; (c) verifying that the UWB network is authentic based on the initial network data; (d) initiating communication between the mobile device and an anchor within the UWB network, including partial mutual authentication; (e) generating a session key for secure communication between the mobile device and the UWB network; (f) tracking the position of the mobile device within the predetermined area based on secure communication using the session key between the mobile device and one or more anchors within the UWB network; and (g) submitting the transaction if the position of the mobile device is within the at least one trigger area.
[0007] This aspect is based on the idea of protecting the user's privacy in several ways during different usage phases. Initially, that is, before the mobile device enters into actual communication with the UWB network, it is verified that the UWB network is genuine (as opposed to an attacker posing as part of the network and aiming to obtain sensitive data from the mobile device). Subsequently, a session key is generated such that when the mobile device moves within a predefined area covered by the UWB network, secure (private) communication with the UWB network can be used to track the location of the mobile device. This communication does not reveal any sensitive information to the network, which only allows the network to track the location of the device without knowing who the user is, payment information, and any other information not required for performing the tracking. Subsequently, once it is determined that the mobile device is within at least one trigger area, for example when the user walks through a designated door in a train station or a similar facility, a transaction is submitted. Only at this stage can sensitive information be transferred from the mobile device to the UWB network as needed to submit the transaction. If the mobile device leaves the predefined area but does not enter a trigger area, the session will end without revealing the user's identity to the UWB network. Thus, as long as the user does not decide to submit a transaction by entering a trigger area (or one of several trigger areas), the user remains completely anonymous to the UWB network.
[0008] In this context, the term "mobile device" may specifically represent a compact electronic device, such as a smartphone, a tablet, a dedicated device, or a similar device that is compact and capable of communicating with the UWB network. More specifically, the mobile device may be loaded with a dedicated application for handling communication.
[0009] In this context, the term "anchor" may specifically represent a node in the UWB network that is capable of transmitting and receiving messages at least in the UWB frequency band.
[0010] In this context, the term "predefined area" may specifically represent an area within which it is possible to communicate with at least one anchor and thus with the UWB network. It should be noted that the exact size and shape of the predefined area also depend on the specific mobile device and its communication capabilities.
[0011] In this context, the term "trigger area" may specifically represent a limited and clearly marked area, such as a door, through which the user can enter or pass in order to indicate their willingness to submit a transaction, for example to start or end a public transport journey segment.
[0012] In this context, the term "initial network data" may specifically represent data that provides basic information about the network, which allows the mobile device to identify the UWB network and perform the first steps required to initiate communication with the UWB network.
[0013] In this context, the term "session key" may specifically represent a key that can only be used in combination within a single communication session.
[0014] According to an embodiment, the steps of verifying that the anchor is genuine include: (a) determining the current location of the mobile device, (b) determining the expected location of the network, and (c) verifying that the current location of the mobile device matches the expected location of the network.
[0015] In other words, determine the expected location of the UWB network, and then check whether the current location of the mobile device (e.g., provided by GPS, mobile network cell ID, nearby WiFi, etc.) matches the expected location of the UWB network. In one example, the expected location is determined to be a certain railway station. Thus, if the mobile device is currently located within the railway station or at least within its nearby environment, the UWB network can be verified as genuine. On the other hand, if the device location does not match the expected network location, this can be regarded as an attempt to attack the mobile device and the UWB network cannot be verified as genuine. If this occurs, the mobile device will not take additional steps for establishing communication with a non-genuine network.
[0016] According to another embodiment, the expected location of the network is determined based on the initial network data and / or mapping at least a part of the initial network data to a database of a certain location.
[0017] In other words, the expected location can be determined based on information contained in the initial network data such as the network ID, etc. This information can directly give an indication of the expected location, or it can be combined with a database that maps the information to a certain location.
[0018] According to another embodiment, the initial network data is broadcast by the anchor.
[0019] Thus, shortly after entering the predetermined area, the mobile device will have received the initial network data, enabling the mobile device to start the verification steps, and if this is successful, continue with additional steps.
[0020] According to another embodiment, the communication is initiated using IEEE802.15.8 or a similar protocol.
[0021] According to another embodiment, the method further includes assigning a random ID to the mobile device for identifying the mobile device during the secure communication with the one or more anchors within the UWB network.
[0022] Thus, by using the random ID to identify the movement during the communication session, the network can track the location of the mobile device as the mobile device moves around within the predetermined area. The next time the mobile device communicates with the UWB network (or communicates with another UWB network at another location), the mobile device will be assigned a new random ID. Thus, it is impossible to track the actual device or its user.
[0023] According to another embodiment, tracking the location of the mobile device includes performing time-of-flight measurements of the communication between the mobile device and each of the one or more anchors.
[0024] Time-of-flight measurements provide information about the distance between the mobile device and each of the anchors participating in the communication with the mobile device. Using this information and triangulation techniques, the current position of the mobile device within a predetermined area can be determined.
[0025] According to another embodiment, each of the one or more anchors sends a message to the mobile device and measures the time before receiving a corresponding response from the mobile device.
[0026] According to another embodiment, the communication used to perform the time-of-flight measurements utilizes UWB.
[0027] According to another embodiment, the step of generating a session key includes: (a) generating a temporary device key at the mobile device while authenticating using a static device key and its certificate, the temporary device key including a temporary device private key and a temporary device public key, (b) generating a temporary anchor key at the anchor while authenticating using a static anchor key and its certificate, the temporary anchor key including a temporary anchor private key and a temporary anchor public key, (c) sharing the temporary device public key with the anchor, (d) sharing the temporary anchor public key and the static anchor key with the mobile device, (e) generating the session key at the mobile device based on the temporary anchor public key and the static device key, and (f) generating the session key at the anchor based on the temporary device public key and the static anchor key.
[0028] In other words, both the mobile device and the anchor generate corresponding temporary keys, namely the temporary device key and the temporary anchor key, respectively. Each temporary key includes a private key and a public key. Additionally, the mobile device and the anchor use their respective static keys and certificates for authentication purposes, i.e., to prove that the mobile device and the anchor are who they claim to be. Then, the mobile device shares the temporary device public key with the anchor. Due to authentication, e.g., a certificate, the anchor details that the temporary device key is provided by the mobile device. Similarly, the anchor shares the temporary anchor public key with the mobile device. Furthermore, the anchor also shares its (public) static anchor key with the mobile device. Subsequently, when both sides (i.e., the mobile device on one side and the anchor on the other side) have obtained the corresponding temporary public keys from the other side, the two sides generate a session key based on the temporary public key received from the other side and their own static keys. This is also known as the principle of agreeing to share a secret. Thus, the session key is known and available only to the mobile device and the anchor and cannot be obtained, generated, or regenerated by a third party.
[0029] According to another embodiment, the method further includes sharing the static device key with the anchor.
[0030] By sharing the static device key and its certificate (e.g., signed by a transportation agency to certify that the device belongs to a group), it can be ensured that non-members cannot connect to the anchor.
[0031] As indicated above, keys are always divided into two types: public keys and private keys. It is the public key that is shared. The public key can be signed by another key, thereby generating a signature. If the signature is from a trusted third party, then when anyone who trusts the authorizing party can check the public key (and other information) guaranteed by that authorizing party, the signature is a certificate.
[0032] According to another embodiment, the static device key is shared with other mobile devices and stored within the secure execution environment of the mobile devices.
[0033] By sharing the static device key with other mobile devices, it is possible to consider the mobile devices as belonging to the same group, such as a travel pass for a public transportation system. The static device key is protected by being stored within the secure execution environment, i.e., stored in a secure area of the memory (hardware) and / or a secure functional area (software).
[0034] According to another embodiment, during the step of initiating communication between the mobile device and the anchor, the public key corresponding to the static anchor key and its certificate are received at the mobile device or retrieved from a database.
[0035] Thereby, the mobile device can authenticate the network and communicate with the network in a secure manner from the start.
[0036] According to another embodiment, submitting the transaction includes simulating a contactless card transaction between the mobile device and an anchor located within or near the trigger area.
[0037] In other words, the actual transaction is performed by exchanging data in the same way as when a user places their RFID or NFC device on a reader in an RFID-based system. Thus, it is only at this stage that sensitive data is exchanged between the mobile device and the UWB network.
[0038] According to a second aspect, there is provided a system comprising: (a) a UWB network including a plurality of anchors, the UWB network covering a predetermined area having at least one trigger area, and (b) at least one mobile device configured to communicate with the UWB network, wherein the system is configured to: (c) wake up the mobile device after the mobile device enters the predetermined area, (d) receive initial network data at the mobile device, (e) verify that the network is genuine based on the initial network data and geofencing information from other sensors, (f) initiate communication between the mobile device and an anchor within the UWB network, including partial mutual authentication, (g) generate a session key for secure communication between the mobile device and the UWB network, (h) track the position of the mobile device within the predetermined area based on secure communication using the session key between the mobile device and one or more anchors within the UWB network, and (i) submit a transaction if the position of the mobile device is within the at least one trigger area.
[0039] This aspect is substantially based on the same idea as the first aspect and provides a system capable of performing the method according to any one of the first aspect and / or the embodiments discussed above.
[0040] According to a third aspect, there is provided a computer program comprising computer-executable instructions which, when executed by a computer, cause the computer to perform the steps of the method according to the first aspect.
[0041] According to a fourth aspect, there is provided a computer program product comprising a computer-readable data carrier loaded with the computer program according to the third aspect.
[0042] It should be noted that the embodiments of the present invention have been described with reference to different subject matters. Specifically, some embodiments have been described with reference to method-type claims, while other embodiments have been described with reference to device-type claims. However, those skilled in the art will understand from the above and the following description that, unless otherwise specified, any combination of features related to different subject matters, specifically the combination of features of method-type claims and features of device-type claims, is also disclosed together with this document, in addition to any combination of features belonging to one type of subject matter.
[0043] Aspects as defined above and other aspects of the present invention will be apparent from the examples of the embodiments described below and will be explained with reference to the examples of the embodiments. The present invention will be described in more detail below with reference to the examples of the embodiments. However, the present invention is not limited to the examples. Description of the Drawings
[0044] Figure 1 Shows a system according to an exemplary embodiment.
[0045] Figure 2 Shows a flowchart of a method according to an exemplary embodiment. Detailed description
[0046] The illustrations in the drawings are schematic. It should be noted that in different drawings, similar or identical elements have the same reference numerals or reference numerals that differ only within the first digit.
[0047] Figure 1 Shows a system 100 according to an exemplary embodiment. The system 100 includes a plurality of anchors 110, 111, 112, 113, 114, 115, 116, 117, 118, 119 arranged across a predetermined area to establish a UWB network covering the predetermined area. There is a designated trigger area 105 within the predetermined area. It should be noted that the limited number of anchors and the reference to only a single trigger area 105 are only used to facilitate the explanation of the embodiment. In other embodiments, the UWB network may include dozens or hundreds of anchors, and as many trigger areas as needed to provide the desired functionality at a given location such as a train station. The system 100 further includes a mobile device 120, such as a smart phone loaded with an application for communicating with the UWB network and for submitting transactions such as checking in and out in a public transportation system.
[0048] Figure 1Show the (same) mobile device 120 at four different locations A, B, C, and D within a predetermined area. At location A (in the lower left corner), the mobile device 120 has just entered the predetermined area and is awakened and ready to connect to the UWB network via the anchor 112, as indicated by arrow A1, which is within the range of the mobile device 120. The wake-up can be initiated by a signal broadcast by the anchor 112 and received by the mobile device 120 (such as Wifi, BLE, or another RF signal), or by using geofencing information based on, for example, GPS or Wifi / BLE. At this stage, the mobile device 120 also receives initial network data, which may include a unique network ID and / or a unique transportation system ID, as well as other information that allows for a faster connection (such as, preferred RF transport layer parameters) and other information that allows for the provision of additional proofs such as timestamps. The additional proofs must be authenticated, for example, by being signed by a dedicated anchor / network key. Then, before attempting to connect to the anchor 112, the mobile device 120 verifies that the UWB network (represented by the anchor 112 in this case) is authentic. This verification uses the information in the initial network data, for example, to determine the expected location of the UWB network and compares the expected location with the current location of the mobile device 120, which is obtained from sources such as GPS, cellular network cell ID, WiFi, etc. The determination of the expected location can utilize, for example, a database stored locally on the mobile device 120 that is periodically supplied and updated, a database stored remotely and accessed via a trusted out-of-band connection such as a cellular network, and / or information broadcast by the anchor 112. In each case, the information must be authenticated, for example, via a secure connection or via public key cryptography. The information can also be timestamped, thereby allowing the device to confirm that the broadcast information and the signature thereon are recent.
[0049] Only when this verification is successful does the mobile device 120 initiate communication with the anchor 112 to start a session. This can be done using the protocol described in IEEE802.15.8 and involves partial mutual authentication and the assignment of a random ID to the mobile device 120 for use during the session. Once a time slot has been allocated, the mobile device 120 and the anchor 112 will generate a partially authenticated session key. This process can utilize one of several existing authentication schemes based on asymmetric cryptography. To maximize protection against attackers (including devices on the same network), a scheme based on generating temporary keys from static and dynamic keys can be used (for example, the scheme described in NIST Special Publication 800-56A: "Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography").
[0050] An exemplary process for generating a session key may include generating a temporary device key at the mobile device 120 while authenticating using a static device key, and generating a temporary anchor key at the anchor 112 while authenticating using a static anchor key. Then, the temporary device key is shared with the anchor 112, and the temporary anchor key and the static anchor key are shared with the mobile device 120. Finally, a session key is generated at the mobile device 120 based on the temporary anchor key and the static device key, and a session key is generated at the anchor 112 based on the temporary device key and the static anchor key. Now, both parties (i.e., the mobile device 120 and the anchor 112) have the session key (commonly referred to as the "common secret") and can use the session key to communicate securely throughout the session. Thereby, the following advantages are obtained: the session key is unknown to eavesdropping adversaries (based on the use and limitations of a multi-party authentication scheme); the session key cannot be computed by a man-in-the-middle adversary and is unknown to the man-in-the-middle adversary; the session key authenticates the anchor identity and proves that the mobile device belongs to the network; the key will be used to derive keys for the remainder of the session.
[0051] Now, in the case of establishing a session key, the mobile device 120 and the UWB network (initially the anchor 112) can communicate securely with each other during the session, specifically, for tracking the position of the mobile device 120 within a predetermined area when the user moves away from Figure 1 the initial position A shown in the lower left corner. When the mobile device 120 moves towards the trigger region 105, the mobile device 120 will respond to messages from one or more anchors within its reach, such that the position of the mobile device 120 can be continuously obtained based on the corresponding time-of-flight measurements - that is, by measuring the time from when an anchor sends a message until the same anchor receives a response from the mobile device 120. By applying triangulation and other possible techniques to the distances repeatedly obtained from the corresponding anchors, not only the position of the mobile device 120 can be tracked, but also the direction and / or speed of the mobile device 120 can be tracked. Figure 1Shows some additional positions of the mobile device 120 along its route leading to the trigger area 105. At position B, the mobile device is connected to anchors 112, 111, and 113, as indicated by the corresponding arrows B1, B2, B3, while at position C further down the route, the mobile device 120 is connected to anchors 113, 114, and 116, as indicated by the corresponding arrows C1, C2, and C3. Finally, at position D, the mobile device has reached within the trigger area 105 and is now communicating with anchor 116. After determining that the mobile device 120 is located within the trigger area 105, the mobile device submits a transaction, for example, by emulating a contactless card transaction with anchor 116. Only at this stage, as part of submitting the transaction, the identity of the user is revealed to the system 100. Thus, if the user decides not to enter the trigger area 105 (or any other trigger area) but simply leave the predefined area (e.g., if he / she just walks through a train station), the system will track the random ID until the end of the session without knowing the identity of the corresponding user.
[0052] Figure 2 Shows a flowchart 200 of a method according to an exemplary embodiment. More specifically, flowchart 200 shows steps similar to the steps described above in connection with Figure 1 The described steps. Method 200 starts at 210, where the mobile device 120 is awakened after it enters the predefined area. Subsequently, at 220, initial network data is received at the mobile device 120, and at 230, as described above, it is verified that the UWB network is authentic based on the initial network data. After verifying that the UWB network is authentic, communication between the mobile device 120 and the anchors within the UWB network is initiated. This step also includes partial mutual authentication between the mobile device 120 and the anchors. At 250, a session key is generated for secure communication between the mobile device 120 and the UWB network, and once this step is completed, at 260, the position of the mobile device 120 within the predefined area is determined using secure communication between the mobile device 120 and one or more anchors within the UWB network using the session key. At 265, it is checked whether the position of the mobile device 120 is within the trigger area 105. If this is not the case, i.e., no, the method returns to step 260 of updating the position of the mobile device 120. On the other hand, if it is determined that the position is within the trigger area 105, i.e., yes, then at 270, a transaction is submitted.
[0053] The transaction will be carried out on the same channel as the channel used for ranging or on a separate channel. The transaction will emulate an RFID transaction on the selected transmission channel. In a typical RFID transaction, the user identity will be disclosed.
[0054] It should be noted that unless otherwise specified, the use of terms such as "upper", "lower", "left", and "right" only refers to the orientation of the corresponding schema.
[0055] It should be noted that the term "comprising" does not exclude other elements or steps, and the use of the article "a" or "an" does not exclude a plurality. In addition, elements described in connection with different embodiments may also be combined. It should also be noted that the reference numerals of the claims should not be interpreted as limiting the scope of the claims.
Claims
1. A method for a mobile device (120) in a UWB network comprising a plurality of anchors (110, 111, 112, 113, 114, 115, 116, 117, 118, 119) to submit a transaction, the UWB network covering a predetermined area having at least one trigger area (105), characterized in that, The method includes waking up (210) the mobile device (120) after the mobile device (120) enters the predetermined area, receiving (220) initial network data at the mobile device (120), verifying (230) that the UWB network is authentic based on the initial network data, initiating (240) communication between the mobile device (120) and an anchor within the UWB network, including partial mutual authentication, generating (250) a session key for secure communication between the mobile device (120) and the UWB network, tracking (260) the position of the mobile device within the predetermined area based on secure communication using the session key between the mobile device (120) and one or more anchors within the UWB network, and submitting (270) the transaction if the position of the mobile device (120) is within the at least one trigger area (105), wherein generating the session key includes generating a temporary device key at the mobile device while authenticating using a static device key and its certificate, the temporary device key including a temporary device private key and a temporary device public key, generating a temporary anchor key at the anchor while authenticating using a static anchor key and its certificate, the temporary anchor key including a temporary anchor private key and a temporary anchor public key, sharing the temporary device public key with the anchor, sharing the temporary anchor public key and the static anchor key with the mobile device, generating the session key at the mobile device based on the temporary anchor public key and the static device key, and generating the session key at the anchor based on the temporary device public key and the static anchor key.
2. The method according to claim 1, wherein Verifying that the UWB network is authentic includes determining the current position of the mobile device, determining the expected position of the UWB network, and verifying that the current position of the mobile device matches the expected position of the UWB network.
3. The method according to claim 2, wherein Determining the expected position of the UWB network based on the initial network data and / or mapping at least a portion of the initial network data to a database of locations.
4. The method according to claim 1, wherein Additionally includes assigning a random ID to the mobile device for identifying the mobile device during the secure communication with the one or more anchors within the UWB network.
5. The method according to claim 1, wherein Tracking the position of the mobile device includes performing time-of-flight measurements of the communication between the mobile device and each of the one or more anchors.
6. The method according to claim 1, characterized in that, Each of the one or more anchors sends a message to the mobile device and measures the time before receiving a corresponding response from the mobile device.
7. The method according to claim 1, characterized in that, The static device key is shared with other mobile devices and stored within a secure execution environment of the mobile device.
8. The method according to claim 7, wherein Receiving, at the mobile device, a public key corresponding to the static anchor key and its certificate during the step of initiating communication between the mobile device and the anchor, or retrieving the public key and its certificate from a database.
9. A system, characterized in that, Includes A UWB network, the UWB network including a plurality of anchors (110, 111, 112, 113, 114, 115, 116, 117, 118, 119), the UWB network covering a predetermined area having at least one trigger area (105), and at least one mobile device (120), the at least one mobile device being configured to communicate with the UWB network, wherein the system is configured to: wake up the mobile device (120) after the mobile device (120) enters the predetermined area, receive initial network data at the mobile device (120), verify that the UWB network is authentic based on the initial network data, initiate communication between the mobile device (120) and the anchors within the UWB network, including partial mutual authentication, generate a session key for secure communication between the mobile device (120) and the UWB network, track the position of the mobile device within the predetermined area based on secure communication using the session key between the mobile device (120) and one or more anchors within the UWB network, and submit a transaction if the position of the mobile device (120) is within the at least one trigger area (105), wherein generating the session key includes generating a temporary device key at the mobile device while authenticating using a static device key and its certificate, the temporary device key including a temporary device private key and a temporary device public key, generating a temporary anchor key at the anchor while authenticating using a static anchor key and its certificate, the temporary anchor key including a temporary anchor private key and a temporary anchor public key, sharing the temporary device public key with the anchor, sharing the temporary anchor public key and the static anchor key with the mobile device, generating the session key at the mobile device based on the temporary anchor public key and the static device key, and generating the session key at the anchor based on the temporary device public key and the static anchor key.
Citation Information
Patent Citations
Augmented beacon and geo-fence systems and methods
US20160302037A1