Authentication System Segmentation for Relay Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic key systems are vulnerable to illegitimate actions using relays and fake devices that can mimic ID verification without the user's knowledge, compromising communication security.
Innovation Solution
An authentication system that divides the calculation result into multiple parts and transmits them separately, requiring both parts for verification, and includes a detection process to ensure legitimate user usage, using encryption codes and different radio wave frequencies to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication information is transmitted between communication devices, then ID verification can be performed, but the system becomes vulnerable to relay attacks and fake devices
Solution Approach 1:
The authentication system divides the calculation result into multiple parts (first calculation result and second calculation result) and transmits them through different communication paths. The first part is transmitted during the authentication process, while the second part is transmitted during a detection process. This segmentation prevents relay attacks and fake devices from obtaining the complete authentication data, thereby resolving the vulnerability to such attacks while maintaining authentication functionality.
2Ease of operation
If the electronic key is carried remotely from the vehicle, then user convenience is improved, but illegitimate actions can be performed without user knowledge
Solution Approach 1:
The system introduces a detection process as an intermediary mechanism that verifies the legitimacy of communication before completing authentication. The detection process checks whether the communication scenario is legitimate (e.g., electronic key near the vehicle) by evaluating a second calculation result transmitted through a separate channel. This intermediary detection prevents illegitimate actions while allowing convenient remote carrying of the electronic key.
3Device complexity
If a single calculation result is transmitted for authentication, then the authentication process is simple, but the system cannot detect illegitimate communication scenarios
Solution Approach 1:
The authentication system segments the verification process into two independent parts: an authentication process that transmits and verifies the first calculation result, and a detection process that transmits and verifies the second calculation result. This segmentation adds detection capability without significantly increasing overall system complexity, as each part follows a similar verification mechanism but operates in parallel through different communication channels.
4Reliability
If multiple authentication checks are performed, then security is improved, but the processing time increases
Solution Approach 1:
The detection process, which verifies the second calculation result, is performed in parallel with or alongside the authentication process rather than sequentially after it. This preliminary and parallel execution of verification tasks allows the system to perform multiple authentication checks without significantly increasing the total processing time, as both the authentication and detection processes can proceed concurrently through different communication channels.
Data Source
AI summary
An authentication system includes an authentication unit that performs an authentication process between a first communication device and a second communication device when the first communication device and the second communication device communicate. The authentication unit performs the authentication process by transmitting authentication information from one of the first communication device and the second communication device to the other one, calculating the authentication information with an encryption code in each of the first communication device and the second communication device, and evaluating a calculation result. During a processing series in the authentication process, the authentication unit performs a first authentication based on part of the calculation result transmitted between the first and second communication device, and a second authentication based on another part of the calculation result transmitted between the first and second communication device.


