Proximity Verification for Contactless Payment Relay Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Relay attacks in contact and contactless access transactions, such as payment transactions, allow attackers to compromise data between legitimate devices by relaying commands and information over a network, enabling unauthorized access without the physical presence of the victim's card.

Innovation Solution

A method involving a first device establishing a wireless connection with a second device, requesting and receiving location data, determining the distance between them, generating an altered value based on this data, and transmitting it along with an account identifier to a server computer, which analyzes the value to ensure the devices are proximate and authentic, thereby allowing or denying access to a resource based on the determined distance and data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If relay attack is used to conduct access transaction remotely, then convenience of operation is improved, but security and reliability deteriorate

Engineering Contradiction:
Improveconvenience of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by obtaining location data and determining device proximity before allowing the access transaction to proceed. The first device determines its location and the second device's location, calculates the distance between them, and verifies they are within a threshold distance before generating the altered value and completing the transaction. This preliminary verification prevents remote relay attacks while maintaining convenient contactless operation for legitimate nearby users.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If location-based verification is implemented, then security against relay attacks is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages existing multi-functional capabilities of mobile devices, including built-in location determination systems (GPS, Wi-Fi positioning, cellular triangulation) and wireless communication modules. These devices already perform multiple functions such as communication, navigation, and data processing. By utilizing these existing multi-functional components for location-based verification, the system enhances security without requiring entirely new specialized hardware, thereby limiting the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If distance determination based on location data is used, then reliability of access control is improved, but loss of time in transaction processing increases

Engineering Contradiction:
Improvereliability of access controlVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs only the essential location verification steps needed to prevent relay attacks, rather than comprehensive security checks. It obtains location data from existing device capabilities, calculates distance using straightforward geometric formulas, and compares against a threshold. This partial action approach achieves sufficient reliability to block remote attacks while minimizing additional processing time, avoiding excessive verification steps that would unnecessarily slow down legitimate transactions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12015964B2Method and system for location-based resource access
Publication Date: 2024.06.18 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12015964B2 patent drawing
  • US12015964B2 patent drawing
  • US12015964B2 patent drawing

AI summary

A method is disclosed. The method includes establishing, by a first device, a wireless connection to a second device; transmitting a request, by the first device and to the second device, for location data indicative of a location of the second device; receiving, by the first device and from the second device, the location data indicative of the location of the second device; determining, by the first device, a distance between the first device and the second device based at least in part on the received location data; generating, by the first device, an altered value based on the received location data and the determined distance; and transmitting, by the first device and to the second device, the altered value and an account identifier associated with a user of the first device.