Contactless Service Authentication Using Location-State Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless and contactless services, such as vehicle door opening and payment services, face security vulnerabilities due to relay attacks that allow unauthorized transactions when devices are not in close proximity, leading to insecure operations.

Innovation Solution

A service processing method where devices exchange identifiers indicating their location states, prompting user authentication if the location is abnormal, and verifying signatures to ensure the authenticity of location information, thereby ensuring secure service execution only when both devices are in trusted, valid locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless and contactless transaction manners are used for convenience, then user convenience is improved, but security is worsened due to relay attacks and unauthorized transactions

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary location verification by obtaining location information of both first and second devices before allowing the transaction to proceed. Location state information is sent in advance to indicate whether devices are in expected locations, and authentication is prompted beforehand if location is abnormal, preventing unauthorized transactions before they occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Location information and location state information act as intermediary elements between the two devices. The system uses these intermediaries to verify device proximity and legitimacy, enabling security checks without disrupting the wireless contactless transaction flow

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication is always required for security, then security is improved, but transaction efficiency is worsened due to additional user steps

Engineering Contradiction:
ImprovesecurityVSAvoidtransaction efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different authentication requirements based on local conditions - specifically, whether the location information matches expected location state information. When locations match (normal state), no authentication is needed. When locations don't match (abnormal state), authentication is required. This localized approach to authentication maintains security only where needed

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of always requiring full authentication, the system performs partial verification by checking location information first. Only when location verification fails does it escalate to full user authentication, reducing unnecessary authentication steps while maintaining security

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3819174B1Business processing method and device
Publication Date: 2023.12.13 HUAWEI DEVICE CO LTD
  • EP3819174B1 patent drawingFigure 1
  • EP3819174B1 patent drawingFigure 2
  • EP3819174B1 patent drawingFigure 3

AI summary

Embodiments of this application provide a service processing method and a device, to improve security of a wireless and contactless service. A first device receives a first identifier sent by a second device, where the first identifier is sent by the second device after the second device receives a trigger request used to perform a first service, and the first identifier is in a first state or a second state, the first service is an unlocking service or a payment service; and if the first device determines, based on the received first identifier, to perform authentication, and the authentication succeeds, the first device sends a second identifier to the second device, where the second identifier indicates that it is determined to perform the first service; or if the first device determines, based on the received first identifier, not to perform authentication, the first device sends first location information and a third identifier to the second device, where the first location information is location information of the first device, and the third identifier indicates that a location of the first device and a location of the second device are normal. The embodiments of this application are used for service processing.