Dual-Interface Security System for Denial-of-Service Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Contactless interfaces in electronic devices are vulnerable to denial-of-service attacks, where attackers can block the device by sending incorrect authentication requests, leading to unauthorized blocking of the card without the user's knowledge, causing damage to both cardholders and providers.

Innovation Solution

The implementation of a dual-interface security system where both contact and contactless interfaces are protected by separate inhibition mechanisms, including indicator values and thresholds, ensuring the user retains access to the secret value even during a denial-of-service attack. This system updates an indicator of incorrect use and applies different inhibitions based on predefined rules, such as time-delays or reduced communication rates, to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a contactless interface is provided for easy access to the device, then ease of operation is improved, but vulnerability to denial-of-service attacks increases

Engineering Contradiction:
Improveaccessibility of interfaceVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides the security protection into separate segments for each interface (contactless interface with indicator 102 and contact interface with indicator 104). Each interface has its own failure counter and inhibition mechanism, allowing independent monitoring and protection. This segmentation prevents a single point of failure and enables targeted response to attacks on specific interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent dynamically changes operational parameters based on detected attack patterns. When excessive failures are detected on the contactless interface, the system modifies the operational state by blocking that interface while maintaining the contact interface. Thresholds and time-delays are adjusted parameters that change based on the severity and pattern of detected attacks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If failure counters are implemented to block the device after excessive incorrect authentication attempts, then security is improved, but false blocking due to attacks worsens user access

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser access availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces intermediary mechanisms between the authentication process and the blocking action. Instead of direct blocking after a fixed number of failures, the system uses indicators (102, 104) that track failures separately for each interface, and applies blocking selectively based on which interface is being attacked. This intermediary layer prevents false blocking by distinguishing between legitimate multiple attempts and coordinated attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The blocking mechanism is made dynamic rather than static. The system continuously monitors failure patterns and adjusts its response in real-time. Time-delays are dynamically applied, and the system can transition between different states (authorized, blocked, time-delayed) based on current conditions. This dynamic approach allows the system to adapt to varying attack patterns while maintaining legitimate access.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If the same failure counter is used for both contactless and contact interfaces, then device complexity is reduced, but the ability to prevent targeted attacks on one interface is lost

Engineering Contradiction:
Improvecounter mechanism simplicityVSAvoidattack prevention capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the failure counting mechanism into separate indicators (102 for contactless, 104 for contact) that independently track failures for each interface. This segmentation allows the system to identify which specific interface is under attack and respond accordingly, preventing attacks on one interface from causing false blocking of the other interface.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

While maintaining separate indicators for each interface, the patent uses a universal blocking mechanism that can be applied to either or both interfaces based on which indicator triggers the threshold. The blocking logic serves multiple functions: it can block individual interfaces selectively, block both interfaces simultaneously, or apply time-delays. This multi-functionality allows a single blocking mechanism to handle various attack scenarios without requiring completely separate protection systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2264632B1Electronic device with two communication interfaces and associated method for securing such device
Publication Date: 2018.04.04 IDEMIA AMERICA CORP
  • EP2264632B1 patent drawingFigure 1~3
  • EP2264632B1 patent drawingFigure 4
  • EP2264632B1 patent drawingFigure 5

AI summary

Electronic device (1000), characterized in that it includes a first interface (1200) adapted to establish communication with an external electronic entity a second interface (1300) also adapted to establish communication with an external electronic entity, means for processing a secret value, adapted to react to reception of a message via either interface control means adapted - to update an indicator of use of said means for using a secret value via either interface, - to apply a first inhibition to communication using the first interface as a function of said indicator, - to apply a second inhibition to communication using the second interface as a function of said indicator, the device being such that for at least one value of the indicator the second inhibition is different from the first.