Decoupling Transponder Response Time Measurement and Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Transponders, such as smart cards and RFID tags, are vulnerable to relay attacks where the local binding is exploited for criminal acts, and existing methods struggle to effectively detect such attacks due to limitations in response time measurement and authentication processes.
Innovation Solution
A method where a reader and transponder perform response time measurement and authentication in separate steps, using distinct communication messages with a time interval, and include data for authentication in communication messages during response time measurement, allowing for timely decoupling of cryptographic operations and efficient bandwidth usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If response time measurement and authentication are performed in the same step, then the time window for detection is smaller, but the measurement precision of response time deteriorates due to cryptographic operation delays
Solution Approach 1:
The patent divides the authentication process into two separate phases: a first phase dedicated to response time measurement where the transponder sends data without encryption, and a second phase for authentication where cryptographic operations are performed. This segmentation allows precise measurement of the communication time window without the interference of encryption/decryption delays, while still performing complete authentication separately.
2Speed
If the time window for response time measurement is made smaller to detect relay attacks faster, then the detection speed improves, but the reliability of detection deteriorates due to insufficient time for cryptographic operations
Solution Approach 1:
The patent performs response time measurement in advance during the first communication phase before the cryptographic authentication phase. By measuring the time window beforehand when no encryption is involved, the system establishes a baseline for legitimate communication speed. This preliminary measurement allows the system to quickly identify relay attacks without compromising the time needed for subsequent authentication, thereby maintaining both detection speed and reliability.
3Productivity
If data for authentication is transmitted during response time measurement, then bandwidth efficiency improves, but the complexity of the communication protocol increases
Solution Approach 1:
The patent applies different quality requirements to different phases of communication: in the first phase, data is transmitted without encryption to enable precise timing measurement, while in the second phase, the same data is authenticated using cryptographic operations. This local differentiation of security requirements allows efficient bandwidth usage while maintaining protocol manageability by clearly separating measurement and authentication functions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Reader (420) for determining the validity of a connection to a transponder (440), designed to measure a response time of a transponder (440) and to authenticate the transponder (440) in two separate steps. Transponder (440) for determining the validity of a connection to a reader (420), wherein the transponder (440) is designed to provide information for response time measurement to said reader (420) and to provide information for authentication to said reader (420) in two separate steps, wherein at least a part of data used for the authentication is included in a communication message transmitted between the reader (420) and the transponder (440) during the measuring of the response time.