In-Vehicle Login Binding Codes for NFC Relay Attack Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current in-vehicle system login methods face challenges in balancing convenience and security, with Bluetooth-based methods vulnerable to relay attacks and remote login methods requiring advance user preparation, leading to poor user experience.
Innovation Solution
A near field communication-based method involving a mobile terminal negotiating a login binding code with a vehicle and a network side device to verify user account login, allowing secure and convenient access without prior boarding preparation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Bluetooth near field communication is used for login, then account verification can be completed, but the system becomes vulnerable to relay attacks and signal interception
Solution Approach 1:
The patent introduces a login binding code as an intermediary verification element between the mobile terminal and the in-vehicle system. Instead of directly verifying Bluetooth signals, the system uses this code as a mediator to establish secure authentication, thereby preventing relay attacks while maintaining login functionality
Solution Approach 2:
The login binding code is pre-negotiated and stored in both the mobile terminal and the in-vehicle system before actual login occurs. This preliminary action ensures that when login is needed, the verification can proceed securely without real-time signal interception risks
2Ease of operation
If remote login via telematics service provider is used, then account login can be completed remotely, but user experience deteriorates due to requiring advance boarding time determination
Solution Approach 1:
The system enables automatic login functionality where the mobile terminal autonomously completes authentication with the in-vehicle system using the pre-stored login binding code, eliminating the need for users to manually determine boarding times or perform advance login preparations
3Ease of operation
If account information is stored locally in the vehicle, then login can be completed without advance preparation, but security is compromised as account information must be stored
Solution Approach 1:
The patent extracts the critical verification element (login binding code) from the complete account information and stores only this essential component locally in both the mobile terminal and in-vehicle system. This extraction allows convenient login while maintaining security by not storing sensitive account details
Data Source
AI summary
Establishing, by a mobile terminal, a near field communication link to a vehicle, where the vehicle corresponds to the in-vehicle system; negotiating a login binding code with the vehicle through the near field communication link; and providing the login binding code to a network side device, where the login binding code is used by the network side device to verify whether the in-vehicle system can be logged in to with the first user account.


