Contactless Payment Timing Analysis for Relay Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contactless payment systems are vulnerable to relay attacks, which intercept and relay payment information without the cardholder's awareness, leading to mistrust and complications due to inconsistent device performance and reliance on complex offline authentication mechanisms.
Innovation Solution
An online approach using artificial intelligence to learn and generate reference processing times, incorporating supervised learning and regression analysis to verify transaction authenticity by comparing measured processing times with reference times, reducing the need for offline data authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If offline data authentication mechanisms are implemented, then relay attack protection is improved, but device complexity and cost increase
Solution Approach 1:
The patent replaces the mechanical PKI-based offline authentication system with an AI-based online authentication system. The terminal device uses machine learning models to analyze transaction patterns and detect relay attacks in real-time, substituting complex cryptographic verification with intelligent pattern recognition that achieves similar security goals without requiring PKI infrastructure installation.
Solution Approach 2:
The patent introduces an AI model as an intermediary between the terminal device and the payment network. This AI intermediary analyzes transaction data and provides authentication decisions, acting as a mediator that simplifies the authentication process while maintaining high security standards, thereby reducing the complexity burden on terminal devices.
2Reliability
If offline data authentication is used, then relay attack detection is improved, but false positives and false negatives increase due to device performance variations
Solution Approach 1:
The patent performs preliminary training of AI models using historical transaction data to establish baseline authentication patterns before actual relay attack detection begins. This preliminary action enables the system to adapt to normal device performance variations and establish reference patterns, thereby reducing false positives and false negatives during actual authentication operations.
Solution Approach 2:
The patent implements feedback mechanisms where the AI model continuously learns from authentication outcomes and adjusts its detection thresholds. By analyzing false positives and false negatives from previous transactions, the system refines its timing analysis and pattern recognition, progressively improving measurement precision and reducing authentication errors over time.
3Reliability
If public key infrastructure is implemented, then authentication security is improved, but implementation cost and complexity at terminals increase
Solution Approach 1:
The patent extracts the complex PKI infrastructure requirements from the terminal device and relocates the heavy computational and cryptographic functions to the payment network side. The terminal device only needs to collect and transmit transaction data, while the AI-based authentication and cryptographic verification are performed remotely, thereby simplifying terminal implementation while maintaining strong security.
Solution Approach 2:
The patent uses copying of authentication patterns and behavioral biometrics instead of traditional cryptographic key pairs. By analyzing and copying normal transaction patterns, the AI model creates a digital twin of legitimate user behavior that can be verified without requiring complex PKI infrastructure at the terminal, achieving equivalent security with simpler implementation.
Data Source
AI summary
A method for contactless payment relay attack protection includes receiving an online authorization request including a cryptogram, a measured processing time, and a reference processing time from a terminal. The cryptogram is verified, and a determination is performed as to whether the measured processing time exceeds the reference processing time. An online authorization response authorizing or declining a monetary transaction is transmitted, based on the determination. An artificial intelligence transaction analysis can be performed based on past and current conditions (e.g., battery level, operating system, open applications) of a payment device such as a mobile phone, past and current conditions of a terminal, and/or a monetary amount. The online authorization response can be based on the artificial intelligence transaction analysis.


