NFC Module Marking Unit for Relay Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communication terminals are vulnerable to relay attacks, where attackers can easily intercept and manipulate near-field communication (NFC) data by emulating either an NFC reader or a portable data carrier, making it difficult to distinguish between genuine and forwarded data, thus compromising security.
Innovation Solution
A near-field communication module with a receiving and transmitting unit, conversion unit, and marking unit that identifies and marks data as originating from a trustworthy security element, preventing attackers from emulating a secure entity by ensuring only secure data sources are recognized, thereby preventing relay attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data forwarding is enabled in NFC modules, then communication flexibility is improved, but security against relay attacks deteriorates
Solution Approach 1:
The patent applies preliminary action by marking data with origin information before transmission through the NFC module. The marking unit tags data with identifiers indicating whether it originates from a security element or another source, enabling the receiving device to verify authenticity in advance and prevent relay attacks while maintaining data forwarding capability
Solution Approach 2:
The patent introduces an intermediary marking mechanism that sits between the data source and the NFC communication. The marking unit acts as a mediator that inserts origin identification into the data stream, allowing third-party devices to verify data authenticity without disrupting the underlying data forwarding functionality
2Ease of operation
If commercial communication terminals are used for NFC communication, then ease of operation is improved, but vulnerability to MITM attacks increases
Solution Approach 1:
The patent applies preliminary anti-action by preemptively marking data with origin information before any potential MITM attack can occur. The marking unit identifies and tags data from security elements with trusted identifiers, creating a preventive barrier that neutralizes the effectiveness of man-in-the-middle attacks while maintaining compatibility with commercial terminals
3Measurement precision
If data origin identification is implemented, then measurement precision of data source is improved, but device complexity increases
Solution Approach 1:
The patent extracts the origin identification function into a separate marking unit that operates independently from the core NFC communication functionality. This modular approach allows precise data source identification through marking while keeping the overall device structure manageable by separating security functions from communication functions
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
The invention relates to a near field communication module (3) for exchanging data via a near field communication network (8). It has: a first receiving and transmitting unit (32) for transmitting and receiving the data in a first data format (13) via a near field antenna (30) connected to the first receiving and transmitting unit (32); a second receiving and transmitting unit (33) for transmitting and receiving the data in a second date format (APDU) and having a unit (4) connected to the near field communication module (3); and a conversion unit (34) for converting the data from the first data format (13) into data of the second data format (APDU) and vice versa. The near field communication module (3) has a marking unit (31), wherein the marking units (31) marks the data by using a connection of the connected unit (4) to the second receiving and transmitting unit (33). The invention further relates to a communication terminal having a near field communication module, to the use of the module (3) in a portable data carrier (5) and to a method for marking data in a near field communication module (3).