Contactless Transponder Relay Attack Detection via Timing Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication systems, particularly those based on the ISO/IEC 14443 standard, are unable to reliably detect and prevent relay attacks, which occur when a transponder communicates with a remote reader instead of a nearby one, due to the lack of precise timing requirements for response behavior.
Innovation Solution
A method that measures and evaluates the card-specific time period for data processing and transmission between a reading device and a transponder, allowing the reader to determine if a relay attack is present by comparing the measured time with a predetermined limit, and securely transmitting this time period to prevent attackers from simulating legitimate responses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If distance-bounding protocol is implemented to detect relay attacks, then security against relay attacks is improved, but compatibility with existing ISO/IEC 14443 standard is worsened
Solution Approach 1:
The patent copies the timing measurement mechanism from distance-bounding protocols and applies it to the existing ISO/IEC 14443 contactless communication framework. The reader measures the time between sending a command and receiving a response, creating a timing-based security check that works within the existing standard without requiring protocol modifications.
Solution Approach 2:
The patent changes the parameter being measured from physical distance (as in distance-bounding) to response time. By measuring the time taken for the transponder to process and respond to commands, the system achieves security against relay attacks while maintaining compatibility with the existing communication standard.
2Measurement precision
If precise timing measurement is implemented, then detection accuracy of relay attacks is improved, but system complexity is worsened
Solution Approach 1:
The transponder itself provides the timing information by including its response processing time in the communication exchange. The reader simply measures the total time from command transmission to response reception, and the transponder's own behavior (command processing time) serves as the security verification mechanism, eliminating the need for external timing devices.
3Reliability
If multiple challenge-response exchanges are performed, then security against relay attacks is improved, but communication time is worsened
Solution Approach 1:
The patent performs a limited number of challenge-response exchanges (exactly three as required by ISO/IEC 14443) rather than multiple repetitions. This partial action is sufficient to achieve the desired security level while minimizing the time loss, as the timing measurement provides strong security evidence that reduces the need for extensive verification.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This method enables high-accuracy detection of relay attacks without modifying existing ISO/IEC 14443 standards, ensuring secure communication by filtering out noise and reducing the likelihood of successful attacks through repeated measurements and secure authentication.
Implementation Method 1
The method is based on the fact that electromagnetic waves propagate at almost the speed of light, but are never faster
Data Source
AI summary
The invention relates to a method for operating a communication system, which comprises a transponder (12) having at least one antenna, particularly in the form of a portable data carrier, and a read unit (10) having at least one antenna. The read unit (10) is designed to exchange data with the transponder (12). An exchange of data between the transponder (12) and the read unit (10) is possible within a predefined range. The time of a command (30) transmitted from the read unit (10) to the transponder (12) is measured and evaluated and a corresponding response (34) of the transponder (12) by the read unit (10) is received. In the process a card-specific duration (T_cc) is processed, wherein the card-specific duration (T_icc) states how long the transponder (12) takes to receive and process a command (30) received by the read unit (10) and to send a corresponding response (34).


