Portable Data Carrier Relay Attack Protection via Position Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting transactions between portable data carriers and terminals, such as those using NFC communication, are vulnerable to relay attacks as they rely on background systems for position verification, which can be tampered with, and do not reliably prevent unauthorized transactions.

Innovation Solution

The method involves the portable data carrier directly comparing its own location with the terminal's location, using information transferred during the transaction, and initiating protective measures if a predetermined threshold of deviation is exceeded, without relying on external verification systems, by utilizing a list of terminal identifications and their associated locations determined through various methods like mobile radio, WLAN, or GPS.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If position verification is performed through background systems, then transaction security is improved, but the system becomes vulnerable to tampering and relay attacks

Engineering Contradiction:
Improvetransaction securityVSAvoidvulnerability to tampering and relay attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the position verification function from external background systems and relocates it to the portable data carrier itself. The data carrier independently determines its own position using onboard sensors (GPS, accelerometer, gyroscope) and compares it with the terminal's position information, eliminating dependency on vulnerable background systems and preventing relay attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The portable data carrier performs self-verification of its position using onboard sensors and stored reference data. It autonomously determines whether the current position matches the expected position without requiring external verification systems, thereby securing transactions against tampering while maintaining reliability.

Inventive Principle:
Principle #25Self-service

2Reliability

If external background systems are used for position verification, then transaction validation is improved, but data security deteriorates due to transfer of sensitive information

Engineering Contradiction:
Improvetransaction validationVSAvoidexposure of sensitive transaction data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the position verification function from external background systems and relocates it to the portable data carrier itself. The data carrier independently determines its own position using onboard sensors (GPS, accelerometer, gyroscope) and compares it with the terminal's position information, eliminating dependency on vulnerable background systems and preventing relay attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The portable data carrier performs self-verification of its position using onboard sensors and stored reference data. It autonomously determines whether the current position matches the expected position without requiring external verification systems, thereby securing transactions against tampering while maintaining reliability.

Inventive Principle:
Principle #25Self-service

3Reliability

If relay attacks are prevented through position comparison, then transaction security is improved, but the system complexity increases

Engineering Contradiction:
Improveprotection against relay attacksVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the position determination function with the existing portable data carrier device. The carrier integrates sensors (GPS receiver, accelerometer, gyroscope) and combines their outputs to determine position, eliminating the need for separate verification systems and reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The portable data carrier is designed with multi-functionality, serving both as a transaction device and a position determination system. It uses onboard sensors for navigation purposes and simultaneously for security verification, preventing relay attacks without adding dedicated complexity to the transaction system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10074087B2Method for carrying out a transaction between a portable data carrier and a terminal
Publication Date: 2018.09.11 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US10074087B2 patent drawing
  • US10074087B2 patent drawing

AI summary

A method for carrying out a transaction between a portable data carrier, such as a chip card, and a terminal is described. An information item (TID) about the terminal is transferred to the portable data carrier upon the transmission of transaction data by a communication between the portable data carrier and the terminal. As a result, the portable data carrier obtains from the information item a locational position (ZID, WID, GID) of the terminal. Further, there is ascertained a locational position (OP) of the portable data carrier to which the portable data carrier has access. Finally, the portable data carrier compares the locational position (ZID, WID, GID) of the terminal with its locational position (OP), and initiates a measure for protecting the transaction in case a deviation between the two locational positions (ZID, WID, GID; OP) exceeds a predetermined threshold.