Secure Communication Timing Verification for Card Readers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing card reader communication systems are vulnerable to hijacking and data falsification, where a third party can intercept and alter response data, leading to unauthorized access and potential losses for cardholders, due to the lack of secure communication protocols within the preset Frame Waiting Time (FWT).

Innovation Solution

A method and system for secure communication that involves a first terminal sending a request message and initiating a time counting, followed by a response notification message, allowing the second terminal to send a response message only within a predetermined effective threshold, and verifying signature data to ensure authenticity, thereby preventing hijacking and falsification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the card reader waits for receiving response data within a preset Frame Waiting Time (FWT), then the communication efficiency is improved, but the system becomes vulnerable to hijacking and data falsification

Engineering Contradiction:
Improvecommunication efficiencyVSAvoiddata authenticity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-establishing a trusted timing relationship between the card reader and card. The card reader stores the card's identifier and calculates an expected response time window based on predetermined parameters. When a response is received, the reader verifies whether the response time falls within the calculated window before processing, preventing hijacked responses from being accepted while maintaining efficient communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through a verification mechanism where the card reader checks the timing characteristics of received responses against pre-stored card identifiers and calculated expected time windows. This feedback loop ensures that only responses with valid timing characteristics are processed, automatically rejecting hijacked or falsified responses while maintaining high communication efficiency for legitimate interactions.

Inventive Principle:
Principle #23Feedback

2Speed

If the card reader processes all data received within the FWT, then the response processing speed is improved, but security risks increase due to potential hijacked data

Engineering Contradiction:
Improveresponse processing speedVSAvoidhijacked data risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-calculating and storing the expected response time window for each card based on its identifier and predetermined timing parameters. This preparation is done before actual communication occurs, enabling the card reader to quickly verify incoming responses against pre-established criteria without adding significant processing time, thus maintaining high processing speed while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter verification approach by shifting from verifying data content integrity to verifying timing characteristics. The card reader compares the actual response time against the expected time window derived from predetermined parameters and the card's identifier. This parameter change enables rapid verification that maintains processing speed while effectively detecting hijacked responses with incorrect timing characteristics.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If a third party can hijack and falsify response data, then unauthorized access is enabled, but the system security is compromised

Engineering Contradiction:
Improveremote access capabilityVSAvoidauthorization security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-storing card identifiers and pre-calculating expected response time windows before any communication occurs. This advance preparation creates a security barrier that prevents unauthorized access, as hijacked responses lacking the correct timing characteristics will be rejected by the verification mechanism, even though remote access capability is maintained for legitimate cards.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through a timing verification mechanism that automatically rejects responses not meeting the expected timing criteria. This feedback loop maintains authorization security by ensuring that only responses with valid timing characteristics (indicating legitimate card-to-reader communication) are processed, while blocking unauthorized access attempts through hijacked or falsified data.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11159946B2Method and system for secure communication
Publication Date: 2021.10.26 TENDYRON CORP
  • US11159946B2 patent drawing
  • US11159946B2 patent drawing
  • US11159946B2 patent drawing

AI summary

A method and a system for secure communication are provided, said method including: a first terminal sending a request message to a second terminal, initiating a first time counting according to a preset timing mode when finishing sending the request message (101); the second terminal receiving the request message, and obtaining a response message according to the request message (102); the first terminal sending a response notification message to the second terminal when a value of the first time counting reaches a first value, and initiating a second time counting according to a preset timing mode when finishing sending the response notification message (103); the second terminal receiving the response notification message, and sending a response message to the first terminal (104); the first terminal permitting starting to receive the response message when a value of the second time counting is within an effective threshold of a second value (105).