Contactless Payment Timing Analysis for Relay Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Contactless payment systems are vulnerable to relay attacks, which intercept and relay payment information without the cardholder's awareness, leading to mistrust and complications due to inconsistent device performance and reliance on complex offline authentication mechanisms.

Innovation Solution

An online approach using artificial intelligence to learn and generate reference processing times, incorporating supervised learning and regression analysis to verify transaction authenticity by comparing measured processing times with reference times, reducing the need for offline data authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If offline data authentication mechanisms are implemented, then relay attack protection is improved, but device complexity and cost increase

Engineering Contradiction:
Improverelay attack protectionVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical PKI-based offline authentication system with an AI-based online authentication system. The terminal device uses machine learning models to analyze transaction patterns and detect relay attacks in real-time, substituting complex cryptographic verification with intelligent pattern recognition that achieves similar security goals without requiring PKI infrastructure installation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an AI model as an intermediary between the terminal device and the payment network. This AI intermediary analyzes transaction data and provides authentication decisions, acting as a mediator that simplifies the authentication process while maintaining high security standards, thereby reducing the complexity burden on terminal devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If offline data authentication is used, then relay attack detection is improved, but false positives and false negatives increase due to device performance variations

Engineering Contradiction:
Improverelay attack detection accuracyVSAvoidtiming measurement consistency
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary training of AI models using historical transaction data to establish baseline authentication patterns before actual relay attack detection begins. This preliminary action enables the system to adapt to normal device performance variations and establish reference patterns, thereby reducing false positives and false negatives during actual authentication operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the AI model continuously learns from authentication outcomes and adjusts its detection thresholds. By analyzing false positives and false negatives from previous transactions, the system refines its timing analysis and pattern recognition, progressively improving measurement precision and reducing authentication errors over time.

Inventive Principle:
Principle #23Feedback

3Reliability

If public key infrastructure is implemented, then authentication security is improved, but implementation cost and complexity at terminals increase

Engineering Contradiction:
Improveauthentication securityVSAvoidterminal implementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the complex PKI infrastructure requirements from the terminal device and relocates the heavy computational and cryptographic functions to the payment network side. The terminal device only needs to collect and transmit transaction data, while the AI-based authentication and cryptographic verification are performed remotely, thereby simplifying terminal implementation while maintaining strong security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses copying of authentication patterns and behavioral biometrics instead of traditional cryptographic key pairs. By analyzing and copying normal transaction patterns, the AI model creates a digital twin of legitimate user behavior that can be verified without requiring complex PKI infrastructure at the terminal, achieving equivalent security with simpler implementation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12488327B2Contactless payment relay attack protection
Publication Date: 2025.12.02 MASTERCARD INT INC
  • US12488327B2 patent drawing
  • US12488327B2 patent drawing
  • US12488327B2 patent drawing

AI summary

A method for contactless payment relay attack protection includes receiving an online authorization request including a cryptogram, a measured processing time, and a reference processing time from a terminal. The cryptogram is verified, and a determination is performed as to whether the measured processing time exceeds the reference processing time. An online authorization response authorizing or declining a monetary transaction is transmitted, based on the determination. An artificial intelligence transaction analysis can be performed based on past and current conditions (e.g., battery level, operating system, open applications) of a payment device such as a mobile phone, past and current conditions of a terminal, and/or a monetary amount. The online authorization response can be based on the artificial intelligence transaction analysis.