Mobile Terminal Security Element Token Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contactless transactions on mobile devices are vulnerable to relay attacks, as tokens used for authentication can be intercepted and used by attackers, compromising the security of sensitive services like payments, even with tokenization and Host Card Emulation (HCE) architectures.
Innovation Solution
A method where the mobile terminal's security element verifies the integrity of tokens by calculating and comparing authentication values, ensuring that only the intended terminal can use the token, and allowing offline transactions by validating tokens directly with the security element, preventing corrupt or intercepted tokens from being transmitted.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If tokens are used for authentication in contactless transactions, then the security against data compromise is improved, but the vulnerability to relay attacks worsens
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the security element acts as a mediator between the token and the transaction processing. The security element verifies the token's integrity by calculating and comparing authentication values before the token is used in the transaction, thereby blocking relay attacks without compromising the tokenization benefit
Solution Approach 2:
The patent applies preliminary action by performing token verification before the actual transaction takes place. The security element calculates the authentication value and compares it with the received authentication value in advance, ensuring that only valid tokens bound to the specific terminal can be used, thus preventing relay attacks before they can compromise the transaction
2Reliability
If tokens are verified by the security element through authentication value comparison, then the security against relay attacks is improved, but the transaction complexity worsens
Solution Approach 1:
The patent applies self-service by enabling the security element to autonomously verify token integrity without requiring external verification infrastructure. The security element itself calculates the authentication value using stored secret data and compares it with the received authentication value, making the verification process self-contained and eliminating the need for additional verification servers or complex external protocols
Data Source
AI summary
The invention relates to a method for making a transaction of a contactless application secure, said application (11) being stored in the mobile terminal (10), said transaction taking place between the mobile terminal and a contactless reader (12), said terminal including a security element (14), said method comprising the following steps carried out by the mobile terminal: the application sends (E13) a token representing a piece of sensitive data and a first authentication value relating to the token to the reader, the security element receives (E16) the token and the related first authentication value from the reader, the security element calculates (E17) a second authentication value from the received token and compares the first authentication value with the second authentication value, and sending (E18) the result of the comparison to the reader, said reader cancelling the transaction if the result is negative.

