Contactless Payment Security via Sensor-Based Proximity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contactless payment systems using short-range wireless communication are vulnerable to relay attacks, where attackers intercept and redirect payment data, potentially leading to illegal transactions, as existing countermeasures like GPS-based proximity checks and digital signatures may not be sufficient to prevent data modification and replay attacks.
Innovation Solution
The method involves verifying differences in parameters such as spatial positions or timestamps between a mobile device and a payment terminal before validating a payment transaction, using a secure element to generate unique tokens and applying reversible mathematical operations to ensure the integrity and proximity of the transaction, thereby preventing relay attacks by comparing these parameters with reference values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If GPS-based proximity checks and digital signatures are used to prevent relay attacks, then security against passive relay attacks is improved, but vulnerability to active relay attacks with data modification persists
Solution Approach 1:
The patent applies preliminary action by performing proximity verification using multiple parameters (GPS coordinates, accelerometer data, gyroscope data, barometric pressure) before the payment transaction occurs. This pre-verification ensures that even if data is intercepted and modified during transmission, the attacker cannot replicate the precise combination of parameters from the original location and time, thus preventing active relay attacks.
Solution Approach 2:
The patent introduces intermediary elements by using additional sensor data (accelerometer, gyroscope, barometric pressure) as mediators in the proximity verification process. These intermediaries provide extra layers of verification that go beyond simple GPS coordinates, making it significantly harder for attackers to successfully modify and relay payment data.
2Reliability
If multiple parameters (GPS, accelerometer, gyroscope, barometric pressure) are verified, then security against active relay attacks is improved, but device complexity and processing time increase
Solution Approach 1:
The patent applies universality by using the mobile device's existing sensors (GPS, accelerometer, gyroscope, barometric pressure) for their primary functions while simultaneously utilizing them for security verification. This multi-functionality approach allows the system to enhance security without adding dedicated hardware components, thereby limiting the increase in device complexity.
Solution Approach 2:
The patent changes parameters by combining multiple physical measurements (coordinates, acceleration, rotation, pressure) into a composite verification signature. This parameter transformation approach allows the system to verify proximity through multiple dimensions while maintaining a streamlined verification process that doesn't excessively increase processing time.
3Measurement precision
If transaction parameters include location and timestamp with digital signatures, then detection of relay attacks is improved, but processing time and computational overhead increase
Solution Approach 1:
The patent performs preliminary computation of the verification signature using multiple sensor parameters before the actual payment transaction. By pre-calculating this complex verification data, the system reduces the processing time required during the critical payment moment, thus minimizing time loss while maintaining high detection precision.
Data Source
Figure 1
Figure 2
AI summary
The method, the mobile device, and the payment terminal of the invention relate to security of contactless payment performed during a purchase of products or services by using a short-range wireless communication between the mobile device and the payment terminal. Various external parameters associated to the payment transaction may be exchanged between the mobile device and the payment terminal. Preferred embodiments comprise external parameters such as respective positions of the mobile device and the payment terminal, time stamps related to transaction processing time or identifiers of each the mobile device and the payment terminal. Difference values related to these external parameters are verified by both the mobile device and the payment terminal by carrying out comparison with reference values before validation of the payment transaction by the payment terminal.