RFID Relay Attack Protection via Timing Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contactless communication systems, such as RFID and NFC, are vulnerable to malicious attacks like relay attacks, where a fake reader and card can intercept and retransmit encrypted information, allowing unauthorized transactions without the cardholder's consent, due to lack of precise timing verification and encryption limitations.
Innovation Solution
A method that involves exchanging information on a selected duration value T, with the card sending a return signal at a time t'0+T, where t'0 is the start time adjusted for signal propagation, and using pseudo-random sequences for precise correlation to verify the signal's arrival time within a predetermined margin of error, ensuring the authenticity of the card's response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted communication is used between reader and card, then data security is improved, but relay attacks can still intercept and retransmit encrypted information without decryption
Solution Approach 1:
The patent applies preliminary action by establishing a timing verification mechanism before completing the authentication transaction. The reader sends a challenge at a specific time and expects a response within a predetermined time window, preventing relay attacks that would introduce timing delays
Solution Approach 2:
The patent replaces the reliance on encrypted mechanical communication with a timing-based verification system. Instead of depending solely on encryption to prevent interception, the system uses temporal measurement to detect the presence of relay devices that would necessarily introduce time delays
2Ease of operation
If contactless card remains always active, then ease of use is improved, but unauthorized activation by fake reader and relay attacks become possible
Solution Approach 1:
The patent implements feedback by having the card respond with a timing-verified signal that confirms its genuine presence and active state. The reader receives feedback on whether the response timing matches expected parameters, allowing it to distinguish between genuine card responses and relayed signals
3Reliability
If timing verification with predetermined margin of error is implemented, then relay attack detection is improved, but device complexity increases due to precise timing measurement requirements
Solution Approach 1:
The patent applies parameter changes by introducing a predetermined margin of error parameter that balances detection accuracy with system simplicity. Rather than requiring extremely precise timing measurements, the system uses a reasonable time window that is sufficient to detect relay attacks while maintaining implementation feasibility
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This method effectively protects contactless communication systems by precisely verifying the card's response time, reducing the likelihood of relay attacks and enhancing security against fraudulent transactions.
Implementation Method 1
The transmission is usually done through a radiofrequency magnetic field and it uses an inductive antenna (a simple coil of a few turns) forming part of the reader and an inductive antenna forming part of the card
Implementation Method 2
the energy which enables it to emit its response is supplied inductively by the radio frequency magnetic field produced by the reader's antenna via the antenna of the card
Implementation Method 3
The response of the card is generally established in the form of a modulation of the load of its antenna, which leads to a modulation of the electromagnetic field, which in turn induces a modification of the impedance of the antenna of the reader
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method of protection of a near-field contactless communication system (RFID or the like) against malicious attacks. The method comprises the exchanging between a reader and a contactless card of information regarding a chosen value of duration T, measured with respect to a start instant t0 seen from the reader side, the decoding of this information regarding a value of duration T by the card, the sending by the card of a return signal temporally registered with respect to an instant t'0+T, where t'0 is the start instant such as seen by the card having regard to lags in propagation or processing of the signals received from the reader, the detection of the return signal by the reader, the determination of the temporal registration of the return signal with respect to the start instant t0, and the interruption of the dialogue by the reader if the temporal registration of the return signal detected is not equal to the instant t0+T with a predetermined error margin. The return signal is a pseudo-random sequence.