Information communication method

By encrypting the URL in the format-preserving manner at the electronic tag, generating the encrypted URL and decrypting it by a computer, the problem of NFC readers being unable to protect data confidentiality is solved, achieving secure transmission and compatibility.

CN115334495BActive Publication Date: 2025-09-26STMICROELECTRONICS (GRENOBLE 2) SAS
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210504960.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-04-29
Filing Date
2022-05-10
Publication Date
2025-09-26
Estimated Expiration
2042-05-10

AI Technical Summary

Technical Problem

In the prior art, when an NFC reader transmits a URL between an electronic tag and a remote server, it is unable to protect data confidentiality, and the reader needs to be modified to include a decryption element, resulting in compatibility issues.

Method used

A format-preserving encryption algorithm is used to encrypt part of the URL information at the electronic tag, generating a URL including the encrypted part, which is then decrypted by a computer to ensure that the NFC reader cannot access the encrypted data.

Benefits of technology

This enables secure transmission of sensitive data in URLs without the knowledge of the NFC reader, maintaining reader compatibility and convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115334495B_ABST
    Figure CN115334495B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to a method for communicating information. The present disclosure relates to a method for communicating between an electronic tag and a computer connected to the Internet, wherein the electronic tag: encrypts at least a portion of information to be transmitted using a data format-preserving algorithm; generates a URL including at least the encrypted portion of the information; and transmits the URL to an NFC reader.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority from French application No. 2104953, filed on May 11, 2021, the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present disclosure relates generally to the communication of uniform resource locators (URLs), and more particularly to the communication of encrypted URLs. Background Art

[0004] In recent years, the development of the Internet has led to a surge in data in various formats stored on servers, such as documents, images, sounds, etc. Some of this data can be directly accessed via a URL, which corresponds to an access path that may be an Internet address.

[0005] A need exists for improved URL communication. Summary of the Invention

[0006] One embodiment addresses all or some of the disadvantages of URL communications.

[0007] One embodiment provides a method for communication between an electronic tag and a computer connected to the Internet, wherein the electronic tag: encrypts at least a portion of information to be transmitted by using a format-preserving algorithm; generates a URL including at least the encrypted portion of the information; and transmits the URL to an NFC reader.

[0008] Another embodiment provides a system comprising an electronic tag and a computer connected to the Internet, the tag being adapted to encrypt at least a portion of information to be transmitted by using a format-preserving algorithm to generate a URL comprising at least the encrypted information, and transmit the URL to an NFC reader.

[0009] According to one embodiment, the NFC reader accesses the computer via the Internet based on the URL.

[0010] According to one embodiment, the encryption of the information to be transmitted is performed by the FF1 algorithm.

[0011] According to one embodiment, the encrypted portion of the information is in ASCII printable characters.

[0012] According to one embodiment, ASCII printable characters include at least the following characters: "a", "b", "c", "d", "e", "f", "g", "h", "i", "j", "k", "l", "m", "n", "o", "p", "q", "r", "s", "t", "u", "v", "w", "x", "y", "z", "A", "B", "C", "D", "E", "F", "G", "H", "I", "J", "K", "L", "M", "N", "O", "P", "Q", "R", "S", "T", "U", "V", "W", "X", "Y", "Z", "0", "1", "2", "3", "4", "5", "6", "7", "8" and "9".

[0013] According to one embodiment, ASCII printable characters include at least the following characters: “-”, “_”, “.”, and “~”.

[0014] Note that the ASCII printable characters above are separated by commas outside the quotes, which is unconventional in English, but this is to illustrate that specific characters are ASCII printable characters rather than characters with a comma suffix.

[0015] According to one embodiment, the computer is adapted to decrypt and possibly interpret the encrypted portion of the information.

[0016] According to one embodiment, the encrypted portion of the information corresponds to the tag's internal data, which data may be static or modifiable by the tag itself.

[0017] According to one embodiment, the computer is adapted to transmit the response to the reader.

[0018] According to one embodiment, the URL includes the protocol, the domain name, and the encrypted portion of the information in sequence.

[0019] According to one embodiment, in the URL, the encrypted portion of the information is preceded by a "=" character.

[0020] Another embodiment provides an electronic tag suitable for implementing the above method. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] For a more complete understanding of the present invention and its advantages, reference is now made to the following description taken in conjunction with the accompanying drawings, in which:

[0022] Figure 1 A diagram illustrating an embodiment of a near field communication system;

[0023] Figure 2 A diagram illustrating an embodiment of a near field communication circuit;

[0024] Figure 3 Shown in Figure 1 FIGURE 1 shows an embodiment of a near field communication system;

[0025] Figure 4 An embodiment of a URL is shown; and

[0026] Figure 5 Shown is the Figure 4 A flowchart of an embodiment of a method of URL is shown. DETAILED DESCRIPTION

[0027] Similar features are marked with similar reference numerals in the various drawings. In particular, common structural or functional features between the various embodiments may have the same reference numerals and may be provided with the same structure, dimensions, and material properties.

[0028] For clarity, only the operations and elements that are useful for understanding the embodiments described herein are shown and described in detail.

[0029] Unless otherwise specified, when two elements are referred to as being connected together, this means a direct connection without any intervening elements other than conductors; and when two elements are referred to as being coupled together, this means the two elements may be connected or they may be coupled via one or more other elements.

[0030] In the following disclosure, unless otherwise indicated, when reference is made to absolute position qualifiers such as the terms "front," "back," "top," "bottom," "left," "right," etc., or relative position qualifiers such as the terms "above," "below," "higher," "lower," etc., or orientation qualifiers such as "horizontal," "vertical," etc., the orientation shown in the drawings is referred to.

[0031] Unless otherwise indicated, the expressions "about," "approximately," "substantially," and "approximately" mean within 10%, and preferably within 5%.

[0032] Data exchange is facilitated throughout the development of connected devices. As an example, a simple code (such as a QR code) opens a URL pointing to the data in a web browser when read. Data can also be exchanged via Bluetooth, near-field communication (NFC), over the internet, etc.

[0033] The ease of this exchange raises questions about the confidentiality and security of the data in question.

[0034] In some applications, people attempt to transfer data in the form of a URL between an electronic tag and a computer or server connected to the Internet via an NFC reader, such as a phone configured in reader mode. It may then be desirable to transfer the portion of this data corresponding to the data to be protected without the NFC reader being aware of its contents. In other words, it is desirable to use the NFC reader as a communication gateway between the electronic tag and a remote server or computer device, without the NFC reader being able to access at least a portion of the transmitted data.

[0035] One option is to encrypt the entire URL at the tag level before transmitting it to the NFC reader. However, this would require the reader to be able to decrypt at least the portion of the URL that points to the remote server, and would therefore require the NFC reader to share an encryption / decryption mechanism with the tag. However, this would prevent some NFC readers from being used as a communication vector between electronic tags and servers. In other words, the NFC reader would have to be modified to include a decryption component.

[0036] The described embodiments provide for the scenario where only the portion of the URL that includes the data to be protected is encrypted, so that the domain name of the URL remains unencrypted and can therefore be read by an NFC reader.

[0037] To perform this URL encryption, one can consider using traditional binary encryption algorithms and apply them to the URL data to be protected.

[0038] However, in addition to characters from a predefined set, a URL can only be used if it contains only American Standard Code for Information Interchange (ASCII) characters. Therefore, before passing the tag URL to the NFC reader, the electronic tag must be able to convert the binary encrypted data into ASCII characters. This will also require the inclusion of a conversion element in the electronic tag in addition to the encryption element.

[0039] To overcome these issues, a method is proposed for directly encrypting the portion of the URL containing the data to be protected in ASCII characters. Since this portion of the URL (hereinafter referred to as the plaintext) is in ASCII, a format-preserving encryption algorithm is provided. Encryption is performed directly by the tag, and decryption is performed by a computer, making the encrypted data inaccessible to NFC readers.

[0040] Figure 1 An example of a near field communication system of the type to which the described embodiments and implementation modes apply is shown schematically, by way of example, and in block diagram form.

[0041] The context of two different electronic devices, such as a cellular phone (or "smartphone") and an electronic tag, is arbitrarily employed, but the description applies more generally to any system in which a reader, terminal, or other device emits an electromagnetic field that an electronic tag can receive. For simplicity, an NFC device will refer to any electronic device that contains one or more near-field communication (NFC) circuits.

[0042] In the example shown, a first NFC device 100A (DEV1), a cellular phone operating in "reader mode," is able to communicate with a second NFC device 100B (DEV2), in this case an electronic tag, or device in "map" mode, via near-field electromagnetic (EMF) coupling.

[0043] Each NFC device 100A-100B contains near field communication circuitry. Figure 1 Each of the near field communication circuits 102A-102B includes various electronic components or circuits, such as a modulation circuit or a demodulation circuit, for generating or detecting a radio frequency signal by using an antenna (not shown).

[0044] Figure 2 An example of a near field communication circuit 200 is schematically shown in block diagram form. Such a circuit typically includes Figure 1 The device 100A type device may also be included in the device 100B, especially if it is a mapping mode device. If it is an electronic tag, its circuitry is generally simplified compared to the circuit 200.

[0045] In the example shown, the circuit 200 includes a near field communication (NFC) controller 201 or NFC controller. For example, the NFC controller 201 is a microchip or electronic circuit suitable for implementing near field communication.

[0046] In the example shown, the NFC controller 201 is connected to a central processing unit (main CPU) 202. The main CPU 202 is, for example, the CPU of the NFC devices 100A-100B and is typically a microcontroller in practice.

[0047] In the example shown, NFC controller 201 is connected to receive / transmit (Rx / Tx) circuitry 203 or a radio frequency head. According to one embodiment, controller 201 and circuitry 203 are part of the same integrated circuit. Circuitry 203 is connected to an impedance matching circuit or network 205 (matching network) having discrete external components, which is itself connected to antenna 207 (antenna).

[0048] Circuit 203 is adapted to convert digital signals at the NFC controller end into modulated analog signals at the antenna end, and vice versa. Impedance matching circuit 205 is typically configured to maximize the amplitude of signals that can be sent or received by NFC controller 201. Typically, circuit 205 is specifically designed to match the electrical characteristics of antenna 207.

[0049] The near field communication circuit 200 may also include other elements, such as one or more volatile memories or non-volatile memories, or various circuits to implement additional functions. Figure 2 , represented by a single block 209 (FCT).

[0050] When the NFC device 100A and the NFC device 100B ( Figure 1 ), a radio frequency signal or electromagnetic field (EMF) generated by an NFC device 100A is received by another NFC device 100B within range.

[0051] Figure 3 Schematically and in block diagram form, the Figure 1 301. The system 301 includes an NFC electronic tag 303, which communicates with a remote server or remote computing device or remote computer connected to the Internet 307 via an NFC reader 305. The tag 303 and the reader 305 preferably correspond to Figure 1 The tag 100B and reader 100A are shown in FIG.

[0052] According to one embodiment, electronic tag 303 is a tag that draws the energy it needs to operate from the radio frequency field emitted by a reader within its range.

[0053] According to one embodiment, reader 305 is a phone or connected device with suitable functionality to connect to the Internet, such as a connected tablet, watch, computer, etc.

[0054] exist Figure 3 The embodiment shown in FIG provides a scenario in which a tag 303 can transmit information to a server 307. In doing so, the tag 303 encrypts at least a portion of the information to be transmitted, generates a URL including at least the encrypted portion of the information, and transmits the URL to the NFC reader 305 (I).

[0055] According to Figure 3In the embodiment shown in FIG, NFC reader 305 acts as a communication vector between tag 303 and server 307. Specifically, NFC reader 305 does not decrypt the encrypted portion of the information in the URL transmitted to it. However, reader 305 is adapted to recognize the encrypted portion, specifically the URL containing the name of server 307 to which the information is directed. Reader 305 then receives the URL from tag 303, recognizes the name of server 307, and accesses server 307 by opening the URL in a web browser (II).

[0056] According to Figure 3 In the embodiment shown in FIG, the server 307 is adapted to decrypt and optionally interpret the encrypted portion of the information contained in the URL. In an embodiment, after decrypting and interpreting the encrypted portion of the information contained in the URL, the server 307 is adapted to send and transmit a response (III) to the reader 305. The response may be a message to be transmitted to the user of the reader 305 via his / her display screen.

[0057] For example, the response from the server 307 to the reader 305 corresponds to the opening or downloading of a file, image, video, etc.

[0058] Figure 4 An example of URL 401 is shown. Figure 4 In the embodiment shown in FIG, URL 401 includes at least: a communication protocol identifier 403 on the web (http: / / ); a field 405 containing a domain name (www.domain.com / ); and an encrypted portion 407 (XFHGoSziGg8ZCmT7KR0oZ4QjBqYgK9SPDH5EHD).

[0059] Identifier 403 helps indicate to the Internet browser the protocol used to retrieve the content pointed to by the URL. For example, for general Internet searches, the protocol corresponds to (http: / / ), and for searches that follow a secure protocol, the protocol corresponds to (https: / / ). The protocol can also correspond to (mailto:) for opening an email box or (ftp:) for file transfer.

[0060] Field 405 contains the name of the Internet server or computer hosting the content targeted by the URL. Typically, field 405 includes a top-level domain name or extension (in Figure 4 com) preceded by a subdomain or second-level domain (in Figure 4 domain) in the examples shown in ) and indicates "www." if applicable.

[0061] According to one embodiment, field 405 is an Internet Protocol (IP) address.

[0062] The URL may include a portion 409 (index.html?datas) between the field 405 and the encrypted portion 407, corresponding to, for example, a path to access the content in the server 307 targeted by the URL or a parameter or an anchor or the like.

[0063] For example, in part 409, "index.htm" corresponds to the path to access the resource, "?" is a separator, and "datas=xxxxx" is an optional data or query string. More generally, several queries separated by "&" can form a query string.

[0064] According to Figure 4 In the embodiment shown in FIG, the encrypted portion 407 is preceded by a character 407' to indicate the start of the same portion. For example, the encrypted portion 407 is preceded by a "=" character.

[0065] [Table 1]

[0066]

[0067]

[0068] The encrypted portion 407 corresponds to, for example, an ASCII character sequence, and more specifically, a printable ASCII character sequence.

[0069] According to one embodiment, the printable ASCII characters are at least the characters of row A of Table 1, and are preferably limited to the list of characters of row A of Table 1.

[0070] According to another embodiment, the printable ASCII characters are at least the characters in row B of Table 1, and are preferably limited to the list of characters in row B of Table 1.

[0071] In one variation, the printable ASCII characters are at least the characters in rows A and B of Table 1 , and are preferably limited to the list of characters in rows A and B of Table 1 .

[0072] exist Figure 4 The URL shown in Figure 5 The method shown in was constructed.

[0073] Figure 5 The schematic diagram shows the Figure 4 An embodiment of the URL method is shown in FIG. Figure 5 The flowchart shown in enables URL 401 to be as Figure 4 is constructed as shown in FIG. 1 , in particular as a function of the information to be sent.

[0074] The construction of the URL begins with a step during which part of the information to be transferred (the information to be protected) is generated by the NFC electronic tag and combined to form a sequence of characters called plain text 501 .

[0075] Plain text 501 is preferably printable ASCII characters, such as at least the characters in row A of Table 1, preferably only the characters in row A of Table 1, or in one variation, at least the characters in row A and row B of Table 1, preferably only the characters in row A and row B, but not including any characters from row C of Table 1.

[0076] In one variation, plaintext 501 is generated by a device within tag 303 .

[0077] The information to be protected is, for example, data related to an identification number, a product identification number attached to a tag or a unique identification number of a tag, or internal tag data such as tag diagnostics and status data such as counters, time stamps, error or status recovery.

[0078] In an embodiment, the tags do not necessarily generate the same URL and the plain text may change from one URL to another. The plain text 501 depends on the date, time, counter, etc.

[0079] The plain text 501 corresponds to the respective ASCII codes of the individual characters that compose it, preferably combined with a mapping table 503 (character map) linked to the algorithm used in the subsequent steps.

[0080] The algorithm FPE is then applied to encrypt the plaintext 501 using the key 505 (key). An encrypted code sequence 507 (ciphertext) is obtained. The algorithm used for encryption corresponds to the format-preserving algorithm or the algorithm FPE ("Format Preserving Encrypt") that preserves the data format. Thus, the encrypted code sequence 507 corresponds to the printable ASCII character sequence defined above. For example, the algorithm used corresponds to the FF1 algorithm.

[0081] The key 505 may or may not be common to several tags, and may or may not be shared with the remote server 307 .

[0082] Tag 303 generates plaintext 501 corresponding to a sequence of characters: for example, “0123456x0123456xhelloworld”. Each character of text 501 is associated with a value in table 503: “0 1 2 3 4 5 6 59 0 1 2 3 4 5 6 59 43 4047 50 58 50 53 47 39”. Encryption using the key 505 “00 01 02 03 04 05 06 07 08 09 0a0b 0c 0d 0e 0f 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f” by the FF1 algorithm makes it possible to obtain an encrypted code sequence 507: “HGoSziGg8ZCmT7KR0oZ4QjBqYg”.

[0083] Finally, the encrypted code sequence 507 is added to the unencrypted portion 509 to form a URL 511. For example, the unencrypted portion includes an identifier, a domain name, and other related information such as a path or anchor (identifier, domain name, and other information).

[0084] It should be noted that the described embodiments can be applied to tags that contain encrypted URLs in non-volatile memory (or via a fuse-like structure). For example, this particular embodiment is applicable to tags corresponding to coupons.

[0085] An advantage of the described embodiments and modes of implementation is that they allow the data present in the URL to be transmitted between the electronic tag and the server via an NFC reader without the reader being aware of the data.

[0086] Various embodiments and variations have been described. Those skilled in the art will appreciate that certain features of these embodiments may be combined, and those skilled in the art will readily conceive of other variations.

[0087] Finally, based on the functional description provided above, actual implementation of the embodiments and variations described herein is within the capabilities of those skilled in the art.

[0088] Although the description has been described in detail, it should be understood that various changes, substitutions, and modifications may be made without departing from the spirit and scope of the present disclosure as defined by the appended claims. In the various drawings, identical elements are indicated by identical reference numerals. Furthermore, the scope of the present disclosure is not intended to be limited to the specific embodiments described herein, as those of ordinary skill in the art will readily appreciate from this disclosure that processes, machines, manufactures, compositions of matter, devices, methods, or steps currently existing or to be developed in the future may perform substantially the same functions or achieve substantially the same results as the corresponding embodiments described herein. Therefore, the appended claims are intended to include these processes, machines, manufactures, compositions of matter, devices, methods, or steps within their scope.

[0089] Accordingly, the specification and drawings are to be regarded simply as illustrative of the present disclosure, which is defined by the appended claims, and are intended to cover any and all modifications, variations, combinations or equivalents that fall within the scope of the present disclosure.

Claims

1. A communication method, comprising: encrypting, by the electronic tag, information to be transmitted between the electronic tag and an Internet-connected computing device using a format-preserving algorithm, the information including an encrypted portion, the encrypted portion including data modified by the electronic tag; Generating a uniform resource locator (URL) from the electronic tag, wherein the URL at least includes the encrypted portion; The electronic tag transmits the URL to a near field communication (NFC) reader. receiving, by the Internet-connected computing device, the encrypted portion; decrypting, by the Internet-connected computing device, the encrypted portion to generate a decrypted portion; as well as The decrypted portion is interpreted by the Internet-connected computing device. 2 . The method of claim 1 , wherein the NFC reader accesses the Internet-connected computing device via the Internet according to the URL. The method according to claim 1 , wherein the encrypted portion is encrypted according to an FF1 algorithm.

4. The method of claim 1, wherein the encrypted portion comprises American Standard Code for Information Interchange (ASCII) printable characters.

5. The method of claim 4 , wherein the ASCII printable characters include a combination of two or more of the following characters: "a", "b", "c", "d", "e", "f", "g", "h", "i", "j", "k", "l", "m", "n", "o", "p", "q", "r", "s", "t", "u", "v", "w", "x", "y", " z", "A", "B", "C", "D", "E", "F", "G", "H", "I", "J", "K", "L", "M", "N", "O", "P", "Q", "R" , "S", "T", "U", "V", "W", "X", "Y", "Z", "0", "1", "2", "3", "4", "5", "6", "7", "8", and "9".

6. The method of claim 4, wherein the ASCII printable characters include a combination of two or more of the following characters: "a", "b", "c", "d", "e", "f", "g", "h", "i", "j", "k", "l", "m", "n", "o", "p", "q", "r", "s", "t", "u", "v", "w", "x", "y", "z", "A", " B", "C", "D", "E", "F", "G", "H", "I", "J", "K", "L", "M", "N", "O", "P", "Q", "R", "S", "T", "U" , "V", "W", "X", "Y", "Z", "0", "1", "2", "3", "4", "5", "6", "7", "8", "9", "-", "_", "." and "~".

7. The method according to claim 1, wherein the encrypted portion corresponds to internal data of the electronic tag, wherein the internal data includes static data or data modified by the electronic tag.

8. The method of claim 1, further comprising transmitting, by the Internet-connected computing device, a response to the NFC reader.

9. The method according to claim 1, wherein the URL comprises a protocol portion, a domain name portion and the encrypted portion in sequence.

10. The method of claim 1, wherein the encrypted portion is preceded by a "=" character.

11. A communication system comprising: Electronic tags are configured as follows: encrypting information using a format-preserving algorithm, the information including an encrypted portion restricted to two or more combinations of lowercase or uppercase English alphabetic characters and integers '0' to '9', generating a uniform resource locator (URL), said URL including at least said encrypted portion, and transmitting the URL to a near field communication (NFC) reader; as well as An Internet-connected computing device configured to: receiving the encrypted portion, decrypting the encrypted portion to generate a decrypted portion, and Explain the decryption part.

12. The system of claim 11, wherein the NFC reader accesses the Internet-connected computing device via the Internet according to the URL.

13. The system of claim 11, wherein the encrypted portion comprises American Standard Code for Information Interchange (ASCII) printable characters. The system according to claim 11 , wherein the URL comprises a protocol portion, a domain name portion, and the encrypted portion in sequence.

15. The system of claim 11, wherein the encrypted portion is encrypted according to an FF1 algorithm.

16. An electronic tag, comprising a near field communication circuit, wherein the near field communication circuit is configured as follows: encrypting information to be transmitted between the electronic tag and an Internet-connected computing device using a format-preserving algorithm, the information including an encrypted portion, the format-preserving algorithm being based on the FF1 algorithm, the encrypted portion being restricted to two or more combinations of lowercase or uppercase English alphabetic characters and integers '0' to '9'; generating a uniform resource locator (URL), wherein the URL includes at least the encrypted portion; as well as The URL is transmitted to a near field communication (NFC) reader to cause the internet-connected computing device to decrypt the encrypted portion to generate a decrypted portion.

17. The electronic tag of claim 16, wherein the NFC reader accesses the Internet-connected computing device via the Internet according to the URL.

18. The electronic tag according to claim 16, wherein the encrypted portion comprises American Standard Code for Information Interchange (ASCII) printable characters.

19. The electronic tag according to claim 16, wherein the URL comprises a protocol portion, a domain name portion, and the encryption portion in sequence.

20. The electronic tag according to claim 16, wherein the encrypted portion is encrypted according to an FF1 algorithm.

Citation Information

Patent Citations

  • Appareil pour former des collerettes a l'extremite de tubes en matiere tendre

    FR2104953A1

  • Data protection with translation

    CN104094302A

  • Systems and methods for cryptographic authentication of contactless cards

    CN112639854A