Wireless Access Card Validation Against Relay Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless smart key systems are vulnerable to relay attacks, which allow attackers to bypass proximity checks and gain unauthorized access to vehicles by relaying signals between the access card and the vehicle's wireless module.
Innovation Solution
Implementing a method that combines proximity checks with authentication checks using unique randomly generated values and challenge values, ensuring that the access card is both authentic and within a specified proximity to the vehicle.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If wireless authentication process is implemented, then access security is improved, but vulnerability to relay attacks increases
Solution Approach 1:
The patent performs a proximity check before the authentication process to verify that the access card is physically close to the terminal. This preliminary action prevents relay attacks by ensuring the card cannot be authenticated if it is being relayed over a distance, while still maintaining the authentication security for legitimate close-proximity access.
Solution Approach 2:
The patent divides the authentication process into two separate stages: a proximity check stage and an authentication stage. The proximity check verifies physical closeness using signal strength or time-of-flight measurements, while the authentication stage verifies card validity. This segmentation allows each stage to address specific security concerns independently, preventing relay attacks while maintaining authentication security.
2Object-affected harmful factors
If proximity check is performed, then relay attack prevention is improved, but authentication complexity increases
Solution Approach 1:
The patent combines the proximity check and authentication check into a single integrated validation process. The terminal first performs the proximity check, then conditionally performs the authentication check only if proximity is confirmed. This merging reduces complexity by eliminating separate independent processes while maintaining both security functions through a unified workflow.
Data Source
AI summary
A method includes performing, by a terminal with an access card, a first relay attack check for the access card in accordance with a local value associated with the terminal and a local value associated with the access card; determining, by the terminal, that the access card has passed the first relay attack check, and based thereon, performing, by the terminal with the access card, an authentication check of the access card in accordance with the local value associated with the terminal, the local value associated with the access card, and a local challenge value associated with the terminal; and determining, by the terminal, that the access card has passed the first relay attack check and the authentication check, and based thereon, validating, by the terminal, the access card.


