UWB Gate Pre-Authentication for Faster Secure Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing UWB communication systems face inefficiencies in protocol operation times due to extensive application protocol data unit (APDU) exchanges, particularly in gate systems, and lack effective pre-authentication methods for secure transactions.
Innovation Solution
A method is introduced to minimize APDU exchanges by pre-authenticating gates using a preset security key and encrypting payment information, along with exchanging prior data before the first APDU exchange, thereby optimizing the UWB-based transaction process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If extensive APDU exchanges are performed in UWB gate systems, then transaction security and completeness are improved, but protocol operation time increases
Solution Approach 1:
The patent applies preliminary action by performing authentication and key exchange before the main transaction APDU exchanges. The gateway and terminal establish mutual authentication and derive session keys in advance, so that when actual transaction APDUs are exchanged, security is already established, reducing the need for security-related APDU exchanges during the transaction itself.
Solution Approach 2:
The patent segments the communication protocol into distinct phases: authentication phase (exchange of authentication information), key exchange phase (derivation of session keys), and transaction phase (APDU exchanges for actual transactions). This segmentation allows optimization of each phase independently, reducing unnecessary APDU exchanges in the transaction phase while maintaining security.
2Productivity
If pre-authentication is implemented using preset security keys, then transaction efficiency is improved, but device complexity increases
Solution Approach 1:
The patent uses copying by employing preset security keys (master keys) that are pre-loaded in both the gateway and terminal devices. Instead of requiring complex cryptographic key generation and distribution during each transaction, the system uses these pre-copied security keys to enable rapid authentication and session key derivation, significantly improving transaction efficiency.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism using preset security keys that mediate between the gateway and terminal. These pre-shared keys act as a simple, well-understood foundation for establishing secure sessions, avoiding the complexity of more advanced cryptographic protocols while maintaining security and efficiency.
3Loss of time
If prior data exchange is performed before first APDU exchange, then protocol operation time is reduced, but communication overhead increases
Solution Approach 1:
The patent performs preliminary action by exchanging authentication information and deriving session keys before the main transaction APDUs are exchanged. This prior data exchange establishes the communication channel and security context in advance, so that subsequent transaction APDUs can be exchanged more efficiently without repeating authentication procedures.
Solution Approach 2:
The patent changes the parameters of data exchange by using encrypted session keys derived from preset security keys for subsequent communication. This allows the system to reduce the volume of data that needs to be exchanged in clear text during transactions, as authentication and key establishment are completed beforehand using more efficient cryptographic operations.
Data Source
AI summary
A method is provided for operating an ultra-wide band (UWB) device, the method including transmitting, to a gate, a first message including a device identity (ID) for identifying the UWB device and a transaction ID for identifying a transaction of the UWB device, receiving, from the gate, a second message including a gate authentication cryptogram generated based on the device ID and the transaction ID, verifying the gate based on the gate authentication cryptogram, encrypting payment information for the transaction in response to the gate being verified, and transmitting, to the gate, a third message including the encrypted payment information.


