Authentication System Segmentation for Relay Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic key systems are vulnerable to illegitimate actions using relays and fake devices that can mimic ID verification without the user's knowledge, compromising communication security.

Innovation Solution

An authentication system that divides the calculation result into multiple parts and transmits them separately, requiring both parts for verification, and includes a detection process to ensure legitimate user usage, using encryption codes and different radio wave frequencies to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication information is transmitted between communication devices, then ID verification can be performed, but the system becomes vulnerable to relay attacks and fake devices

Engineering Contradiction:
Improveauthentication securityVSAvoidrelay attacks and faking actions
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication system divides the calculation result into multiple parts (first calculation result and second calculation result) and transmits them through different communication paths. The first part is transmitted during the authentication process, while the second part is transmitted during a detection process. This segmentation prevents relay attacks and fake devices from obtaining the complete authentication data, thereby resolving the vulnerability to such attacks while maintaining authentication functionality.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the electronic key is carried remotely from the vehicle, then user convenience is improved, but illegitimate actions can be performed without user knowledge

Engineering Contradiction:
Improveuser convenienceVSAvoidillegitimate actions without user awareness
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system introduces a detection process as an intermediary mechanism that verifies the legitimacy of communication before completing authentication. The detection process checks whether the communication scenario is legitimate (e.g., electronic key near the vehicle) by evaluating a second calculation result transmitted through a separate channel. This intermediary detection prevents illegitimate actions while allowing convenient remote carrying of the electronic key.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If a single calculation result is transmitted for authentication, then the authentication process is simple, but the system cannot detect illegitimate communication scenarios

Engineering Contradiction:
Improveauthentication process complexityVSAvoiddetection of illegitimate usage
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The authentication system segments the verification process into two independent parts: an authentication process that transmits and verifies the first calculation result, and a detection process that transmits and verifies the second calculation result. This segmentation adds detection capability without significantly increasing overall system complexity, as each part follows a similar verification mechanism but operates in parallel through different communication channels.

Inventive Principle:
Principle #1Segmentation

4Reliability

If multiple authentication checks are performed, then security is improved, but the processing time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The detection process, which verifies the second calculation result, is performed in parallel with or alongside the authentication process rather than sequentially after it. This preliminary and parallel execution of verification tasks allows the system to perform multiple authentication checks without significantly increasing the total processing time, as both the authentication and detection processes can proceed concurrently through different communication channels.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11356264B2Authentication system
Publication Date: 2022.06.07 KK TOKAI RIKA DENKI SEISAKUSHO
  • US11356264B2 patent drawing
  • US11356264B2 patent drawing
  • US11356264B2 patent drawing

AI summary

An authentication system includes an authentication unit that performs an authentication process between a first communication device and a second communication device when the first communication device and the second communication device communicate. The authentication unit performs the authentication process by transmitting authentication information from one of the first communication device and the second communication device to the other one, calculating the authentication information with an encryption code in each of the first communication device and the second communication device, and evaluating a calculation result. During a processing series in the authentication process, the authentication unit performs a first authentication based on part of the calculation result transmitted between the first and second communication device, and a second authentication based on another part of the calculation result transmitted between the first and second communication device.