Portable Data Carrier Relay Attack Protection via Position Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for protecting transactions between portable data carriers and terminals, such as those using NFC communication, are vulnerable to relay attacks as they rely on background systems for position verification, which can be tampered with, and do not reliably prevent unauthorized transactions.
Innovation Solution
The method involves the portable data carrier directly comparing its own location with the terminal's location, using information transferred during the transaction, and initiating protective measures if a predetermined threshold of deviation is exceeded, without relying on external verification systems, by utilizing a list of terminal identifications and their associated locations determined through various methods like mobile radio, WLAN, or GPS.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If position verification is performed through background systems, then transaction security is improved, but the system becomes vulnerable to tampering and relay attacks
Solution Approach 1:
The patent extracts the position verification function from external background systems and relocates it to the portable data carrier itself. The data carrier independently determines its own position using onboard sensors (GPS, accelerometer, gyroscope) and compares it with the terminal's position information, eliminating dependency on vulnerable background systems and preventing relay attacks.
Solution Approach 2:
The portable data carrier performs self-verification of its position using onboard sensors and stored reference data. It autonomously determines whether the current position matches the expected position without requiring external verification systems, thereby securing transactions against tampering while maintaining reliability.
2Reliability
If external background systems are used for position verification, then transaction validation is improved, but data security deteriorates due to transfer of sensitive information
Solution Approach 1:
The patent extracts the position verification function from external background systems and relocates it to the portable data carrier itself. The data carrier independently determines its own position using onboard sensors (GPS, accelerometer, gyroscope) and compares it with the terminal's position information, eliminating dependency on vulnerable background systems and preventing relay attacks.
Solution Approach 2:
The portable data carrier performs self-verification of its position using onboard sensors and stored reference data. It autonomously determines whether the current position matches the expected position without requiring external verification systems, thereby securing transactions against tampering while maintaining reliability.
3Reliability
If relay attacks are prevented through position comparison, then transaction security is improved, but the system complexity increases
Solution Approach 1:
The patent merges the position determination function with the existing portable data carrier device. The carrier integrates sensors (GPS receiver, accelerometer, gyroscope) and combines their outputs to determine position, eliminating the need for separate verification systems and reducing overall system complexity while maintaining security.
Solution Approach 2:
The portable data carrier is designed with multi-functionality, serving both as a transaction device and a position determination system. It uses onboard sensors for navigation purposes and simultaneously for security verification, preventing relay attacks without adding dedicated complexity to the transaction system.
Data Source
AI summary
A method for carrying out a transaction between a portable data carrier, such as a chip card, and a terminal is described. An information item (TID) about the terminal is transferred to the portable data carrier upon the transmission of transaction data by a communication between the portable data carrier and the terminal. As a result, the portable data carrier obtains from the information item a locational position (ZID, WID, GID) of the terminal. Further, there is ascertained a locational position (OP) of the portable data carrier to which the portable data carrier has access. Finally, the portable data carrier compares the locational position (ZID, WID, GID) of the terminal with its locational position (OP), and initiates a measure for protecting the transaction in case a deviation between the two locational positions (ZID, WID, GID; OP) exceeds a predetermined threshold.

