NFC Blocking Unit for Relay Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication terminals are vulnerable to man-in-the-middle (MITM) attacks, particularly in near-field communication (NFC) networks, where attackers can easily relay data between devices using commercially available terminals without hardware modifications, making it difficult to prevent such attacks without significant effort.

Innovation Solution

A mobile communication terminal with a central control unit and a blocking unit that prevents data exchange via a first communication network when data exchange via a second communication network, such as NFC, is detected, thereby blocking the forwarding of sensitive data and preventing relay attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data exchange via first communication network is blocked when NFC data exchange is detected, then security against relay attacks is improved, but communication versatility deteriorates

Engineering Contradiction:
Improvesecurity against relay attacksVSAvoidcommunication versatility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The communication terminal is segmented into multiple independent communication modules (first communication module for general data exchange, second communication module for NFC). Each module operates independently with its own data exchange path, allowing selective blocking of the first module when NFC activity is detected without affecting other communication capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A central control unit acts as an intermediary between the communication modules and the network. It monitors NFC data exchange and controls the blocking of the first communication module, serving as a mediator that coordinates between security requirements and communication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If blocking unit is integrated into communication terminal, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The blocking unit is merged with the central control unit, combining the security function with the existing control infrastructure. This integration allows the blocking functionality to be implemented without adding a completely separate control system, thereby limiting the increase in device complexity while maintaining ease of operation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2767059B1Blocking of data exchange for protecting a near field communication
Publication Date: 2015.11.18 GIESECKEDEVRIENT IP
  • EP2767059B1 patent drawingFigure 1
  • EP2767059B1 patent drawingFigure 2
  • EP2767059B1 patent drawingFigure 3

AI summary

The invention relates to a mobile communication terminal (1) for exchanging data (11) with a second communication terminal (9), which is physically distanced from the first communication terminal (1), via a first communication network (7). The communication terminal (1) has a first communication module (2) for the data exchange (11) with the second communication terminal (9) via the first communication network (7); a second communication module (3) for the data exchange (12) with a portable data carrier (5) via a second communication network (8); and a central control unit (4) for controlling a data exchange between the first communication module (2) and the second communication module (3). The central control unit (4) has a blocking unit (40), said blocking unit (40) blocking (14) the data exchange (11) via the first communication network (7) as soon as the central control unit (4) registers a data exchange (12) via the second communication network (8).