Secure Communication Timing Verification for Card Readers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing card reader communication systems are vulnerable to hijacking and data falsification, where a third party can intercept and alter response data, leading to unauthorized access and potential losses for cardholders, due to the lack of secure communication protocols within the preset Frame Waiting Time (FWT).
Innovation Solution
A method and system for secure communication that involves a first terminal sending a request message and initiating a time counting, followed by a response notification message, allowing the second terminal to send a response message only within a predetermined effective threshold, and verifying signature data to ensure authenticity, thereby preventing hijacking and falsification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the card reader waits for receiving response data within a preset Frame Waiting Time (FWT), then the communication efficiency is improved, but the system becomes vulnerable to hijacking and data falsification
Solution Approach 1:
The patent applies preliminary action by pre-establishing a trusted timing relationship between the card reader and card. The card reader stores the card's identifier and calculates an expected response time window based on predetermined parameters. When a response is received, the reader verifies whether the response time falls within the calculated window before processing, preventing hijacked responses from being accepted while maintaining efficient communication.
Solution Approach 2:
The patent implements feedback through a verification mechanism where the card reader checks the timing characteristics of received responses against pre-stored card identifiers and calculated expected time windows. This feedback loop ensures that only responses with valid timing characteristics are processed, automatically rejecting hijacked or falsified responses while maintaining high communication efficiency for legitimate interactions.
2Speed
If the card reader processes all data received within the FWT, then the response processing speed is improved, but security risks increase due to potential hijacked data
Solution Approach 1:
The patent applies preliminary action by pre-calculating and storing the expected response time window for each card based on its identifier and predetermined timing parameters. This preparation is done before actual communication occurs, enabling the card reader to quickly verify incoming responses against pre-established criteria without adding significant processing time, thus maintaining high processing speed while ensuring security.
Solution Approach 2:
The patent changes the parameter verification approach by shifting from verifying data content integrity to verifying timing characteristics. The card reader compares the actual response time against the expected time window derived from predetermined parameters and the card's identifier. This parameter change enables rapid verification that maintains processing speed while effectively detecting hijacked responses with incorrect timing characteristics.
3Adaptability or versatility
If a third party can hijack and falsify response data, then unauthorized access is enabled, but the system security is compromised
Solution Approach 1:
The patent applies preliminary action by pre-storing card identifiers and pre-calculating expected response time windows before any communication occurs. This advance preparation creates a security barrier that prevents unauthorized access, as hijacked responses lacking the correct timing characteristics will be rejected by the verification mechanism, even though remote access capability is maintained for legitimate cards.
Solution Approach 2:
The patent implements feedback through a timing verification mechanism that automatically rejects responses not meeting the expected timing criteria. This feedback loop maintains authorization security by ensuring that only responses with valid timing characteristics (indicating legitimate card-to-reader communication) are processed, while blocking unauthorized access attempts through hijacked or falsified data.
Data Source
AI summary
A method and a system for secure communication are provided, said method including: a first terminal sending a request message to a second terminal, initiating a first time counting according to a preset timing mode when finishing sending the request message (101); the second terminal receiving the request message, and obtaining a response message according to the request message (102); the first terminal sending a response notification message to the second terminal when a value of the first time counting reaches a first value, and initiating a second time counting according to a preset timing mode when finishing sending the response notification message (103); the second terminal receiving the response notification message, and sending a response message to the first terminal (104); the first terminal permitting starting to receive the response message when a value of the second time counting is within an effective threshold of a second value (105).


