Mobile Device Emulating Security Token via NFC Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile communication systems lack efficient methods for securely provisioning mobile devices to emulate security tokens for transactions without requiring physical possession of the token, leading to inconvenience and potential security risks.
Innovation Solution
A mobile communications system and method that allows a mobile device to receive authentication data from a security token via NFC, transmit it to an authentication server for provisioning, and store second authentication data for initiating transactions, enabling the device to emulate the security token for secure transactions without physical possession.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If mobile devices use NFC technology to exchange data with security tokens, then transaction security is improved, but device complexity increases
Solution Approach 1:
The patent creates a virtual security token in the mobile device that copies the functionality of a physical security token. The virtual token emulates the authentication and transaction capabilities of the physical token through software implementation, allowing the device to perform security functions without requiring the actual physical token present
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the mobile device and the transaction system. The server verifies the mobile device's credentials and manages the token emulation process, reducing the complexity burden from the mobile device itself while maintaining security through centralized verification
2Reliability
If physical security tokens are required for transactions, then transaction security is maintained, but user convenience deteriorates
Solution Approach 1:
The virtual security token in the mobile device replicates the authentication capabilities of the physical token, allowing users to perform transactions using their mobile device instead of carrying and physically handling a separate security token. This copying approach maintains security verification while eliminating the need for physical token possession
Solution Approach 2:
The mobile device serves multiple functions by integrating both NFC communication capabilities and virtual security token functionality into a single device. This multi-functionality eliminates the need for separate physical tokens while maintaining security, as the mobile device can both communicate via NFC and provide authentication credentials
3Ease of operation
If virtual security tokens are implemented in mobile devices, then user convenience is improved, but security risks increase
Solution Approach 1:
The authentication server acts as a secure intermediary that verifies the mobile device's credentials before allowing token emulation. This centralized verification process ensures that only authorized devices can create virtual tokens, maintaining security control while enabling convenient mobile access
Solution Approach 2:
The system implements feedback mechanisms where the authentication server continuously verifies the mobile device's credentials and monitors transaction activities. This ongoing verification provides real-time security validation, ensuring that virtual token usage remains secure while maintaining user convenience
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables secure and convenient transaction initiation on mobile devices without needing to carry physical security tokens, enhancing user experience and reducing the need for new token issuance, while ensuring security through proximity verification and user authentication.
Implementation Method 1
NFC technology is commonly used for contactless short-range communications based on radio frequency identification (RFID) standards, using magnetic field induction to enable communication between electronic devices
Data Source
AI summary
A mobile communications device may include a memory, a transceiver, and a controller coupled with the memory and the transceiver. The controller may be capable of receiving first authentication data from a security token via communication with the security token, where the first authentication data is associated with an account. The controller may also be capable of transmitting the first authentication data via the transceiver, and receiving second authentication data via the transceiver, where the second authentication data is also associated with the account. The controller may be further capable of storing the second authentication data in the memory, and transmitting a transaction request using the second authentication data.


