METHOD FOR DETERMINING A TIMER OFFSET OF AN OSCILLATOR IN A CHIP CARD AND CHIP CARD

The method for determining the timer offset of a chip card's oscillator within a predefined area of a reference timer enhances security by recalibrating the chip card's clock, preventing relay attacks and ensuring accurate time measurement for reliable detection.

DE102024209276A1Inactive Publication Date: 2026-03-26INFINEON TECHNOLOGIES AG
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-25
Publication Date
2026-03-26
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Contactless smart cards, such as NFC chip cards, are vulnerable to relay attacks due to their less accurate and aging-sensitive internal oscillators, which can be manipulated during communication with a compromised reference clock, compromising security.

Method used

A method is implemented to determine the timer offset of the oscillator in the chip card by ensuring it is within a predefined area of a trustworthy reference timer, using a more precise oscillator to recalibrate and authenticate communication, thereby preventing relay attacks.

Benefits of technology

Ensures secure recalibration of the chip card's clock, enhancing its ability to detect and prevent relay attacks, even with advanced communication technologies like 5G, by maintaining high accuracy and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method for determining the timer offset of an oscillator in a chip card is provided. The method comprises: determining whether the chip card is located within a predefined area of ​​a reference timer (110), and if the chip card is located within the predefined area, determining the timer offset of the oscillator using the reference timer (120).
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL AREA

[0001] The present disclosure relates to a method for determining a timer offset of an oscillator in a chip card and to a chip card. BACKGROUND

[0002] A fraud scheme that exploits near field communication (NFC) is a so-called relay attack, in which it is merely simulated that a chip card is within a reader's communication range by using a pair of additional communication partners - one as a fake reader to communicate with the chip card, and one as a fake chip card to communicate with the reader, with the two additional communication partners communicating with each other.

[0003] To detect a relay attack, it is important to have an independent time reference (e.g., an LC oscillator) in the chip card (e.g., a contactless chip card, such as an NFC chip card). In contactless chip cards, the internal oscillator is calibrated / verified during production. The oscillator in a chip card is less accurate and less resistant to aging compared to a more expensive quartz-based oscillator. When the card is in use, it is possible to calibrate the oscillator using the quartz-based reference clock from the reader (magnetic field, e.g., 13.56 MHz).

[0004] However, the field / clockmaker could be manipulated by an ongoing attack. SHORT DESCRIPTION

[0005] A method for determining the timer offset of an oscillator in a smart card is provided. The method comprises: determining whether the smart card is located within a predefined area of ​​reference timing, and if the smart card is located within the predefined area, determining the oscillator's timer offset using the reference timing.

[0006] A chip card is provided. The chip card has an oscillator and an electronic circuit coupled to the oscillator, the electronic circuit being configured to determine whether the chip card is in a predetermined ambient area of ​​a reference timer, and, if the chip card is in the predetermined ambient area, to determine a timer offset of the oscillator using the reference timer.

[0007] The person skilled in the art will recognize further features and advantages of the invention when reading the following detailed description and when looking at the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] The present disclosure is illustrated by way of example and is not limited to the depictions in the accompanying drawings, in which the same reference numerals refer to similar or identical elements. The elements in the drawings are not necessarily shown to scale. The features of the various examples shown can be combined, provided they are not mutually exclusive. Fig. Figure 1 shows a flowchart of a procedure for determining a timer offset of an oscillator in a chip card. Fig. Figure 2a shows a schematic representation of aspects of a method for determining a timer offset of an oscillator in a chip card. Fig. Figure 2b shows a schematic representation of aspects of a method for determining a timer offset of an oscillator in a chip card. Fig. Figure 3 shows a schematic representation of a chip card system with a chip card according to various embodiments. Fig. Figure 4 shows a schematic representation of aspects of a method for determining a timer offset of an oscillator in a chip card. DETAILED DESCRIPTION

[0009] The embodiments described here enable secure recalibration of a contactless smart card (e.g., NFC smart card) in the field by first ensuring that a reader's reference clock is trustworthy. For this purpose, a relay attack protocol can be applied and signed, and only then can the recalibration of the smart card's clock be permitted.

[0010] In various embodiments, a (re-)calibration of a chip card oscillator is performed securely to improve protection against relay attacks in NFC systems.

[0011] In a classic relay attack, communication with both parties (e.g., the chip card and the contactless reader) is initiated by an attacker who then forwards messages between the two parties without manipulating them or necessarily having to read them.

[0012] For example, in the case of an NFC payment, the attacker can use standard NFC phones and the mobile network for the attack.

[0013] Countermeasures for detecting the attack, which are used according to the state of the art and are also employed in the method described herein according to various embodiments, aim to detect that time is required for the additional forwarding (e.g. between the NFC phones), so that a measured response time does not match the expected response time.

[0014] Fig. 2A and Fig. Figure 2B illustrates a corresponding procedure.

[0015] Fig. Case 2A represents a situation where there is no attack on the communication between a contactless reader 220 (also known as a PCD, for Proximity Coupling Device) and the (contactless) smart card 222 (also known as a PICC, for Proximity Integrated Circuit Card). This is demonstrated by the fact that the time measured in the contactless reader 220 (also referred to as the response time) matches the time measured in the smart card 222.

[0016] To ensure that communication actually takes place between the contactless reader 220 and the chip card 222, keys, signatures and / or other authentication data can be exchanged. Fig. 2A and Fig. Figure 2B shows an example of nonce data (nonce stands for "number used once", i.e., a type of one-time key).

[0017] As in Fig. 2A and Fig. As shown in Figure 2B, at least one command, containing, for example, nonce data, can be transmitted from the contactless reader 220 to the chip card 222, and the response time is measured. The response data (which may also contain (other) nonce data) can be transmitted from the chip card 222 to the contactless reader 220, and this response data may include, for example, the exact response time.

[0018] Fig. Figure 2B illustrates this communication in the event of a relay attack. In this case, the message (e.g., nonce data) sent by the contactless reader 220 to the smart card 222 is not received by the smart card 222 (which is outside the reading range of the contactless reader 220), but by a first device 230 of the attacker, which emulates a smart card. From the first device 230, the message is transmitted to a second device 232 of the attacker, which emulates a contactless reader and then transmits the message to the smart card 222.

[0019] The chip card 222 in turn sends the measured time to the contactless reader 220, but is not received by it, but by the second device 232, from which it is transmitted to the first device 230, and only from this to the contactless reader 220.

[0020] The additional time required for transmission between the first device 230 and the second device 232 (in Fig. 2B, represented as a vertical offset between the start and end points of the arrows representing the data transmission), causes the times measured in the contactless reader 220 and the chip card 222 to not match, thus revealing the attack.

[0021] Since this check can be carried out before an intended (e.g., financial) transaction, authorization of the intended transaction can be refused in the event of a detected attack.

[0022] The reaction time ranges from approximately 100 µs to approximately 10 ms. Therefore, the accuracy of the time measurement should be as high as possible. The measurement uncertainty currently ranges from approximately 100 ns to approximately 1 µs.

[0023] If communication between the first device 230 and the second device 232 takes place using, for example, 4G technology, the resulting time difference (also referred to as latency or latency time) between the time determined in the contactless reader 220 and the time determined in the chip card 222 is in a range of approximately 20 to 40 ms.

[0024] Given the above-mentioned reaction time of a maximum of approximately 10 ms and a measurement inaccuracy of a maximum of approximately 1 µs, a time delay of approximately 20 to 40 ms caused by the attack is easily measurable.

[0025] However, if, for example, 5G technology is used for communication between the first device 230 and the second device 232, this allows a latency of down to about 1 ms.

[0026] This means that the reaction time and the latency time can be of approximately the same order of magnitude, and high accuracy in measuring the reaction time can be essential.

[0027] According to a prior art, contactless smart cards 222 typically use an inexpensive oscillator (e.g., a resonant circuit, also known as an LC oscillator) as a clock source, which is less accurate and less resistant to aging than, for example, a quartz-based oscillator. Nevertheless, in the prior art, the smart card oscillator is usually calibrated / tested only once immediately after manufacturing. Typically, an offset is determined for this purpose.

[0028] According to various embodiments, a chip card 222 is provided. See also. Fig. 3, which shows a chip card system 300 with the chip card 222 and a contactless reader 220.

[0029] The chip card 222 can be equipped, as in the prior art, with an inexpensive oscillator 334 (e.g., a resonant circuit, such as an LC oscillator), which can, for example, be part of a chip 330 of the chip card 222 or coupled to the chip 330, for example, by electrically conductive connection to an electronic circuit 332, which can be part of the chip 330. Its calibration can be performed during or immediately after manufacturing. Calibration data, for example, an offset value, can be stored in a memory, for example, a non-volatile memory of the chip card 222.

[0030] To enable accurate measurement of the response time, which may be necessary for the reasons described above in light of new communication technology, an independent time reference (e.g. LC oscillator) with high accuracy is essential in the contactless card.

[0031] When in contact with a 220-bit contactless reader, it may be possible to receive reference clock information that could be used for recalibration.

[0032] However, the (supposed) reference clock could be manipulated.

[0033] Therefore, according to various embodiments, it is first ensured that the chip card 222 is actually located in a designated area (e.g., an NFC communication area) of a reference clock 220, for example, of a contactless reader, such as a chip card reader. The clock signal (also referred to as clock signal or CLK) of the reference clock 220 can, for example, be provided by an oscillator 340, which can be more precise than the oscillator 334 of the chip card 222.

[0034] Fig. Figure 1 shows a flowchart 100 of a method for determining a timer offset of an oscillator 334 in a chip card 222. The flowchart illustrates how, according to various embodiments, it is ensured that the chip card 222 is in a state in which no attack is taking place before a recalibration is permitted, for example in the form of determining a timer offset.

[0035] In various embodiments, it is first determined whether the chip card is located in a predefined area of ​​a reference timer (110), and if the chip card is located in the predefined area (Yes path), the timer offset of the oscillator is determined using the reference timer (120).

[0036] To determine the timer offset, a timer signal provided by the oscillator 334 can be compared with a reference time signal provided by the reference timer 220.

[0037] Although the calibration, which in the prior art is carried out after manufacture, is typically provided in the form of an offset, it is understood that, if necessary, it may be provided as a correction factor or other suitable correction parameter instead of or in addition to an offset.

[0038] In particular, the determination of the timer offset (which enables a recalibration of the timer of the chip card 222, for example by replacing an old stored timer offset with the newly determined timer offset value) is only carried out if it is ensured that the chip card 222 is located in the specified environment of the reference timer 220.

[0039] Otherwise, the determination of the timer offset will not be performed. Furthermore, the execution of a planned transaction, e.g., a financial transaction, may be refused.

[0040] For newly manufactured chip cards 222 or chip cards 222 used regularly (for example, once or several times a year) according to various embodiments, the (re-)calibration performed during the last attack-free use by means of the timer offset determined at that time may be sufficient to provide the accuracy required to detect an attack.

[0041] In Fig. Figure 4 shows an example of communication that takes place between the chip card 222 and the reference clock 220 (e.g. the reader).

[0042] This essentially corresponds to NFC communication standardized according to ISO 14443, whereby “time measurement” illustrates which time is measured and compared in the reference clock 220 and in the chip card 222.

[0043] The communication can, for example, involve authenticating the chip card 222 to the reference timer 220, and accordingly, for example, requesting (using the reference timer 220) and providing (using the chip card 222) authentication data, transmitting signed data (for example, data transmitted from the chip card 222 to the reference timer 220 can be signed using a secret key of the chip card 222), using one-time keys in the form of nonce data, etc.

[0044] In the chip card 222, communication, determining the response time (which can be used to determine whether the chip card 222 is located within the specified area of ​​the reference timer 220), determining the timer offset, managing keys, etc., can be performed in an electronic circuit 332, which can be coupled to the oscillator 334, for example, by an electrical conductor. The electronic circuit 332 can be part of the chip 330 or (for example, parts thereof) connected to the chip 330. The electronic circuit 332 can, for example, include one or more processors, such as controllers, microcontrollers, or security controllers (these, for example, are used in particular for providing or processing data security-relevant information, e.g., for performing cryptographic services, e.g., managing keys).

[0045] Regularly checking / correcting the timer offset ensures that the 222 chip card can function as a sufficiently accurate timer over a longer period of time to reliably detect a relay attack, even if it is carried out using 5G technology.

[0046] Although a chip card 222 is mentioned herein as an example, it should be understood that embodiments also include other NFC communication devices, such as other wearables like smart watches, smart rings, etc.

[0047] The following is a summary of some examples.

[0048] Exemplary embodiment 1 is a method for determining a timer offset of an oscillator in a chip card, the method comprising: determining whether the chip card is located in a predetermined area of ​​a reference timer, and if the chip card is located in the predetermined area, determining the timer offset of the oscillator using the reference timer.

[0049] Exemplary embodiment 2 is a method according to exemplary embodiment 1, wherein the specified environmental area is a near-field communication area of ​​a contactless reader in which the chip card is in a communication connection with the contactless reader.

[0050] Embodiment 3 is a method according to embodiment 1 or 2, wherein, if the determination shows that the chip card is not located in the specified environmental area, the timer offset of the oscillator is not determined.

[0051] Embodiment 4 is a method according to embodiment 2 or 3, wherein the chip card receives a processing task from the contactless reader, wherein the chip card performs the processing task using a clock signal provided by the oscillator and transmits a result of the processing task and a time indication determined by means of the oscillator to the contactless reader.

[0052] Embodiment 5 is a method according to embodiment 4, wherein the processing task is an authentication processing task by means of which the chip card authenticates itself to the contactless reader.

[0053] Embodiment 6 is a method according to embodiment 4 or 5, wherein the result of the processing task is digitally signed by means of a secret key of the chip card, and wherein the digitally signed result is transmitted to the contactless reader.

[0054] Embodiment 7 is a method according to one of embodiments 1 to 6, wherein determining the timer offset of the oscillator using the reference timer involves data transmission using nonce data between the chip card and the reference timer.

[0055] Embodiment 8 is a method according to one of embodiments 1 to 7, further comprising: storing the determined timer offset in the chip card.

[0056] Exemplary embodiment 9 is a chip card comprising: an oscillator and an electronic circuit coupled to the oscillator, wherein the electronic circuit is configured to determine whether the chip card is located in a predetermined ambient area of ​​a reference timer, and, if the chip card is located in the predetermined ambient area, to determine a timer offset of the oscillator using the reference timer.

[0057] Exemplary embodiment 10 is a chip card according to exemplary embodiment 9, wherein the specified environmental area is a near-field communication area of ​​a contactless reader in which the chip card is in a communication connection with the contactless reader.

[0058] Exemplary embodiment 11 is a chip card according to exemplary embodiment 9 or 10, wherein the electronic circuit is further configured not to determine the timer offset of the oscillator if the determination shows that the chip card is not in the specified ambient area.

[0059] Exemplary embodiment 12 is a chip card according to exemplary embodiment 10 or 11, wherein the electronic circuit is further configured to receive a processing task from the contactless reader, to carry out the processing task using a clock signal provided by the oscillator; and to transmit a result of the processing task and a time indication determined by means of the oscillator to the contactless reader.

[0060] Exemplary embodiment 13 is a chip card according to exemplary embodiment 12, wherein the processing task is an authentication processing task by means of which the chip card authenticates itself to the contactless reader.

[0061] Exemplary embodiment 14 is a chip card according to exemplary embodiment 12 or 13, wherein the electronic circuit is further configured to digitally sign the result of the processing task using a secret key of the chip card and to transmit the digitally signed result to the contactless reader.

[0062] Exemplary embodiment 10 is a chip card according to exemplary embodiments 9 to 14, wherein the determination of the timer offset of the oscillator by means of the reference timer comprises a data transmission using nonce data between the chip card and the reference timer.

[0063] Exemplary embodiment 16 is a chip card according to exemplary embodiments 9 to 15, further comprising: a memory configured to store the determined timer offset in the chip card.

[0064] It should be noted that the description and drawings merely illustrate the principles of the proposed methods and devices. A person skilled in the art will be able to implement various arrangements which, although not explicitly described or shown here, embody the principles of the invention and are included within its scope. Furthermore, all examples and embodiments outlined in this document are, in principle and expressly, intended only for explanatory purposes to help the reader understand the principles of the proposed methods and devices. Moreover, all statements in this document that describe principles, aspects, and embodiments of the invention, as well as specific examples thereof, are intended to include their equivalents.

Claims

[1] Method for determining a timer offset of an oscillator in a chip card, comprising the method: Determine whether the chip card is located within a predefined area of ​​a reference timer (110); and If the chip card is located within the specified environmental area, determine the oscillator timer offset using the reference timer (120). [2] Method according to claim 1, wherein the specified environment is a near-field communication area of ​​a contactless reader in which the chip card is in a communication link with the contactless reader. [3] Method according to claim 1 or 2, wherein, if the determination reveals that the chip card is not located in the specified environmental area, the timer offset of the oscillator is not determined. [4] Method according to claim 2 or 3, the chip card receives a processing task from the contactless reader; wherein the chip card performs the processing task using a clock signal provided by the oscillator and transmits a result of the processing task as well as a time indication determined by the oscillator to the contactless reader. [5] Method according to claim 4, wherein the processing task is an authentication processing task by means of which the chip card authenticates itself to the contactless reader. [6] Method according to claim 4 or 5, the result of the processing task is digitally signed using a secret key on the chip card; and the digitally signed result is transmitted to the contactless reader. [7] Method according to any one of claims 1 to 6, wherein determining the timer offset of the oscillator by means of the reference timer comprises data transmission using nonce data between the chip card and the reference timer. [8] Method according to any one of claims 1 to 7, further comprising: Storing the determined timer offset in the chip card. [9] Chip card (222), comprising: an oscillator (334); and an electronic circuit (332) coupled to the oscillator (334), wherein the electronic circuit (332) is configured: • to determine whether the chip card (222) is located within a predefined area of ​​a reference timer (220); and • when the chip card (222) is located in the specified environmental area, to determine a timer offset of the oscillator (334) using the reference timer (220). [10] Chip card (222) according to claim 9, wherein the specified environment is a near-field communication area of ​​a contactless reader in which the chip card (222) is in a communication connection with the contactless reader. [11] Chip card (222) according to claim 9 or 10, wherein the electronic circuit (332) is further configured not to determine the timer offset of the oscillator (334) if the determination shows that the chip card (222) is not located in the specified ambient area. [12] Chip card (222) according to claim 10 or 11, wherein the electronic circuit (332) is further configured as follows: to receive a processing task from the contactless reader; to perform the processing task using a clock signal provided by the oscillator (334); and to transmit a result of the processing task and a time indication determined by means of the oscillator (334) to the contactless reader. [13] Chip card (222) according to claim 12, wherein the processing task is an authentication processing task by means of which the chip card (222) authenticates itself to the contactless reader. [14] Chip card (222) according to claim 12 or 13, wherein the electronic circuit (332) is further configured as follows: for digitally signing the result of the processing task using a secret key of the chip card (222); and to transmit the digitally signed result to the contactless reader. [15] Chip card (222) according to any one of claims 9 to 14, wherein determining the timer offset of the oscillator (334) by means of the reference timer (220) comprises data transmission using nonce data between the chip card (222) and the reference timer. [16] Chip card (222) according to any one of claims 9 to 15, further comprising: a memory set up to store the determined timer offset in the chip card (222).

Citation Information

Patent Citations

  • Method of calibrating a clock of a chip card circuit, and associated system

    US20190310682A1