Contactless Service Authentication Using Location-State Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless and contactless services, such as vehicle door opening and payment services, face security vulnerabilities due to relay attacks that allow unauthorized transactions when devices are not in close proximity, leading to insecure operations.
Innovation Solution
A service processing method where devices exchange identifiers indicating their location states, prompting user authentication if the location is abnormal, and verifying signatures to ensure the authenticity of location information, thereby ensuring secure service execution only when both devices are in trusted, valid locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless and contactless transaction manners are used for convenience, then user convenience is improved, but security is worsened due to relay attacks and unauthorized transactions
Solution Approach 1:
The system performs preliminary location verification by obtaining location information of both first and second devices before allowing the transaction to proceed. Location state information is sent in advance to indicate whether devices are in expected locations, and authentication is prompted beforehand if location is abnormal, preventing unauthorized transactions before they occur
Solution Approach 2:
Location information and location state information act as intermediary elements between the two devices. The system uses these intermediaries to verify device proximity and legitimacy, enabling security checks without disrupting the wireless contactless transaction flow
2Reliability
If authentication is always required for security, then security is improved, but transaction efficiency is worsened due to additional user steps
Solution Approach 1:
The system applies different authentication requirements based on local conditions - specifically, whether the location information matches expected location state information. When locations match (normal state), no authentication is needed. When locations don't match (abnormal state), authentication is required. This localized approach to authentication maintains security only where needed
Solution Approach 2:
Instead of always requiring full authentication, the system performs partial verification by checking location information first. Only when location verification fails does it escalate to full user authentication, reducing unnecessary authentication steps while maintaining security
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of this application provide a service processing method and a device, to improve security of a wireless and contactless service. A first device receives a first identifier sent by a second device, where the first identifier is sent by the second device after the second device receives a trigger request used to perform a first service, and the first identifier is in a first state or a second state, the first service is an unlocking service or a payment service; and if the first device determines, based on the received first identifier, to perform authentication, and the authentication succeeds, the first device sends a second identifier to the second device, where the second identifier indicates that it is determined to perform the first service; or if the first device determines, based on the received first identifier, not to perform authentication, the first device sends first location information and a third identifier to the second device, where the first location information is location information of the first device, and the third identifier indicates that a location of the first device and a location of the second device are normal. The embodiments of this application are used for service processing.