Contactless Media Device Dual-Key Security Mode Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contactless media devices face security risks due to insecure communications with interface devices, particularly when used in uncontrolled environments, making them vulnerable to attacks like relay attacks and man-in-the-middle attacks.
Innovation Solution
Implementing a dual-security mode system for contactless media devices, where a high security mode is set for authentication and transactions using distinct keys, ensuring encrypted communications, and switching to a low security mode post-authentication for less sensitive interactions, thereby enhancing security and flexibility in communication protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If contactless media device uses insecure communication mode for all interactions, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent implements dynamic security mode switching where the contactless media device transitions between insecure communication mode and secure communication mode based on authentication results. Initially, the device operates in insecure mode for easy interaction, but after successful authentication using security mode key, it switches to secure mode with encrypted communications, thus adapting security levels to operational requirements.
2Reliability
If contactless media device uses high security mode for all interactions, then security is improved, but ease of operation is worsened
Solution Approach 1:
The patent segments communication interactions into two distinct phases: an initial authentication phase using insecure communication mode for simplicity, and a subsequent transaction phase using secure communication mode for protection. This segmentation allows each phase to use the most appropriate security level, avoiding the need for high security mode throughout all interactions.
3Device complexity
If contactless media device uses single authentication key, then device complexity is reduced, but security is worsened due to key compromise
Solution Approach 1:
The patent segments the authentication key into two distinct keys: a security mode key for establishing secure communication mode, and a transaction key for actual data transactions. This segmentation ensures that compromise of one key does not necessarily compromise the other, enhancing security while maintaining manageable device complexity through clear key separation.
Solution Approach 2:
The patent applies different security properties to different parts of the authentication process by using separate keys for mode establishment versus transaction execution. The security mode key provides strong protection for the critical authentication phase, while the transaction key handles data exchange, giving each part the appropriate security quality it needs.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A device may perform a first authentication operation, associated with a contactless media device, using a first key. The first key may permit a security mode of the contactless media device to be modified. The device may cause the contactless media device to set the security mode to a first security mode that causes the contactless media device to secure at least one transmission from the contactless media device. The device may perform a second authentication operation, associated with the contactless media device, using a second key that permits information to be read from or written to the contactless media device. The device may read first secured information from or write second secured information to the contactless media device. The first secured information or the second secured information may be secured based on the security mode of the contactless media device being set to the first security mode.