Contactless Payment Relay Attack Prevention via WiFi SSID Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless payment systems are vulnerable to relay attacks, where an attacker can deceive a payment terminal into communicating with a fake device connected to a remote terminal, allowing information to be relayed between devices without being physically proximate, which cannot be prevented by encrypting the data stream.
Innovation Solution
Implementing systems and methods that establish communication links with devices to compare lists of WiFi service set identifiers (SSIDs) or measure communication delays to determine if a relay attack is occurring, using multiple communication ports and processors to verify proximity and detect unreasonable delays.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If NFC communication is used to verify proximity, then contactless payment can be enabled, but the system remains vulnerable to relay attacks
Solution Approach 1:
The patent introduces WiFi SSID lists as an intermediary verification mechanism. Instead of relying solely on NFC proximity, the system compares WiFi SSID lists from both the terminal and device to confirm they are in the same physical location. This intermediary check prevents relay attacks while maintaining contactless payment convenience.
Solution Approach 2:
The patent adds a new dimension of verification by using WiFi network environment comparison. Rather than only checking NFC signal presence, the system now verifies proximity through a second dimension - the shared WiFi environment - making relay attacks detectable without affecting payment operation.
2Loss of information
If encryption is applied to data stream, then data confidentiality is improved, but relay attacks cannot be prevented
Solution Approach 1:
The patent performs proximity verification using WiFi SSID comparison before the actual payment data transmission. By establishing that devices are genuinely proximate beforehand, the system prevents relay attacks at the source, making encryption unnecessary for preventing relay (though encryption remains for data confidentiality).
3Reliability
If WiFi SSID comparison is implemented, then relay attack detection capability is improved, but system complexity increases
Solution Approach 1:
The system uses existing WiFi infrastructure and the device's own WiFi capabilities to perform the verification. Both the terminal and device independently obtain WiFi SSID lists from their environments and compare them, requiring no additional external services or complex infrastructure.
Solution Approach 2:
The WiFi SSID comparison mechanism serves multiple functions: it verifies proximity, detects relay attacks, and confirms the device is in the expected location. This single mechanism addresses multiple security concerns without requiring separate systems for each function.
Data Source
AI summary
The systems, methods and apparatuses described herein provide an apparatus configured for preventing relay attacks on a communication link between the apparatus and a communication partner. The apparatus may comprise a communication port, a timer and a processor. The processor may be configured to generate a request, transmit the request through the communication link using the communication port and start counting time using the timer, receive a response via the communication port and stop the timer, receive authentication data via the communication port, authenticate the authentication data, compare the counted time with a predefined threshold, compare a first field within the request with a second field within the response and determine whether there is a relay attack.


