Decoupling Transponder Response Time Measurement and Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Transponders, such as smart cards and RFID tags, are vulnerable to relay attacks where the local binding is exploited for criminal acts, and existing methods struggle to effectively detect such attacks due to limitations in response time measurement and authentication processes.

Innovation Solution

A method where a reader and transponder perform response time measurement and authentication in separate steps, using distinct communication messages with a time interval, and include data for authentication in communication messages during response time measurement, allowing for timely decoupling of cryptographic operations and efficient bandwidth usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If response time measurement and authentication are performed in the same step, then the time window for detection is smaller, but the measurement precision of response time deteriorates due to cryptographic operation delays

Engineering Contradiction:
Improveresponse time measurement precisionVSAvoidauthentication time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent divides the authentication process into two separate phases: a first phase dedicated to response time measurement where the transponder sends data without encryption, and a second phase for authentication where cryptographic operations are performed. This segmentation allows precise measurement of the communication time window without the interference of encryption/decryption delays, while still performing complete authentication separately.

Inventive Principle:
Principle #1Segmentation

2Speed

If the time window for response time measurement is made smaller to detect relay attacks faster, then the detection speed improves, but the reliability of detection deteriorates due to insufficient time for cryptographic operations

Engineering Contradiction:
Improvedetection speedVSAvoidrelay attack detection reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent performs response time measurement in advance during the first communication phase before the cryptographic authentication phase. By measuring the time window beforehand when no encryption is involved, the system establishes a baseline for legitimate communication speed. This preliminary measurement allows the system to quickly identify relay attacks without compromising the time needed for subsequent authentication, thereby maintaining both detection speed and reliability.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If data for authentication is transmitted during response time measurement, then bandwidth efficiency improves, but the complexity of the communication protocol increases

Engineering Contradiction:
Improvebandwidth efficiencyVSAvoidcommunication protocol complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies different quality requirements to different phases of communication: in the first phase, data is transmitted without encryption to enable precise timing measurement, while in the second phase, the same data is authenticated using cryptographic operations. This local differentiation of security requirements allows efficient bandwidth usage while maintaining protocol manageability by clearly separating measurement and authentication functions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2291947B1Decoupling of measuring the response time of a transponder and its authentication
Publication Date: 2019.12.18 NXP BV
  • EP2291947B1 patent drawingFigure 1
  • EP2291947B1 patent drawingFigure 2
  • EP2291947B1 patent drawingFigure 3

AI summary

Reader (420) for determining the validity of a connection to a transponder (440), designed to measure a response time of a transponder (440) and to authenticate the transponder (440) in two separate steps. Transponder (440) for determining the validity of a connection to a reader (420), wherein the transponder (440) is designed to provide information for response time measurement to said reader (420) and to provide information for authentication to said reader (420) in two separate steps, wherein at least a part of data used for the authentication is included in a communication message transmitted between the reader (420) and the transponder (440) during the measuring of the response time.