Memory Card Contactless Token Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contactless smartcards can be inadvertently activated by proximity to readers, leading to security concerns and a lack of flexibility in using existing contactless infrastructure, as users often need specific mobile devices tied to particular service providers for secure transactions.
Innovation Solution
A token compatible with a memory card slot in mobile devices that uses hidden commands within standard memory card access protocols to authenticate and control the activation of a contactless device, allowing users to selectively activate or deactivate the antenna for secure and flexible transactions, enabling the use of multiple payment accounts and institutions without requiring specific mobile devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If contactless smartcards are activated by proximity to readers, then contactless transactions can be performed conveniently, but security is compromised as cards can be activated without user knowledge
Solution Approach 1:
The system performs preliminary authentication of the mobile device with the contactless card before allowing activation. The server authenticates the mobile device in advance, and only authenticated devices can activate cards, preventing unauthorized activation while maintaining convenience for legitimate users.
Solution Approach 2:
The system implements feedback mechanisms where the server receives activation requests from readers, verifies the mobile device's authentication status, and provides feedback by allowing or blocking activation. This feedback loop ensures security while maintaining ease of use for authorized devices.
2Reliability
If mobile devices are tied to specific service providers for secure transactions, then transaction security is improved, but flexibility and adaptability are reduced
Solution Approach 1:
The authentication mechanism is designed to be universal rather than provider-specific. The server can authenticate mobile devices from different service providers against a common set of contactless cards, enabling multi-service provider compatibility while maintaining security through centralized authentication.
Solution Approach 2:
The server acts as an intermediary between mobile devices and contactless cards. Instead of direct ties between specific devices and providers, the server mediates authentication, allowing any authenticated device to access any card, thus providing flexibility while maintaining security.
3Ease of manufacture
If existing contactless infrastructure is used, then implementation cost is reduced, but security control and flexibility are limited
Solution Approach 1:
The system merges existing contactless card infrastructure with mobile device authentication capabilities. By combining the card's contactless functionality with mobile device-based authentication (using existing mobile OS features), the system enhances security control while utilizing existing infrastructure to keep implementation costs manageable.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances security and flexibility in contactless transactions by allowing users to control the activation of contactless devices through hidden commands, ensuring secure interactions with third-party readers and supporting multiple accounts and institutions without the need for specific mobile device partnerships.
Implementation Method 1
the RF (radio frequency) antenna of the reader activates the RF antenna attached to the contactless device
Data Source
AI summary
A memory card compatible token includes a host interface, radio circuits to transmit signals and a controller to determine if the memory card access commands are for contactless devices attached to the memory card slot or general memory. User payment account information is stored in the contactless chip as part of the contactless devices. The radio circuits can be activated and deactivated by the user for signal transmission using the controller through a mobile computing device.


