Dynamic Multi-Record NFC Message Generation for Secure Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for contactless interactions between user devices and access devices often require specialized hardware or software, limiting their compatibility and increasing vulnerability to attacks, as they cannot process transaction and access request messages according to specific security protocols like EMV.

Innovation Solution

A method where a user device generates and transmits dynamic multi-record messages via NFC tags, incorporating a counter value and cryptogram, allowing interaction with access devices that may not support standard security protocols, ensuring secure and compatible access to resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized hardware or software is used in user devices and access devices, then security protocol compliance is improved, but device compatibility deteriorates

Engineering Contradiction:
Improvesecurity protocol complianceVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary translation layer that converts between different message formats (ISO 8583 and NDEF). This mediator enables access devices with specialized security protocols to communicate with user devices using standard protocols, thereby maintaining security compliance while improving compatibility across different device types

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes message parameters based on the capabilities of the accessing device. By detecting whether the access device supports specialized protocols or standard protocols, the system adjusts the message format, encoding, and security implementation accordingly, allowing the same user device to work with both specialized and standard access devices

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If standardized protocols are used for message transmission, then device compatibility is improved, but security against copy and redirect attacks deteriorates

Engineering Contradiction:
Improvedevice compatibilityVSAvoidvulnerability to copy and redirect attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic message generation where the NDEF message contains volatile data that changes with each transaction (such as dynamic cryptograms and transaction-specific identifiers). This dynamic approach maintains compatibility with standard protocols while preventing copy and redirect attacks because each message is unique and time-sensitive

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary security actions by generating dynamic authentication data and cryptograms before the actual transaction occurs. This preliminary generation of secure, unique message content ensures that even though the transmission uses standardized protocols, the messages themselves are resistant to copying and redirection

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12184756B2System and method for using dynamic tag content
Publication Date: 2024.12.31 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12184756B2 patent drawing
  • US12184756B2 patent drawing
  • US12184756B2 patent drawing

AI summary

A method is disclosed. The method includes a user device storing a message data template comprising a plurality of data fields. A multi-record message may be generated using the message data template in response to an interaction between the user device and an access device. To generate the multi-record message, the user device may increment a counter stored on the user device to produce a counter value, and generate a dynamic cryptogram. The user device may additionally retrieve a credential. The counter value, the dynamic cryptogram, and the credential may then be incorporated into the plurality of data fields of the message data template to form the multi-record message. The multi-record message may be transmitted to the access device, where the access device forwards the multi-record message to an authorization computer to authorize or deny the interaction.