Mobile Device Emulating Security Token via NFC Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile communication systems lack efficient methods for securely provisioning mobile devices to emulate security tokens for transactions without requiring physical possession of the token, leading to inconvenience and potential security risks.

Innovation Solution

A mobile communications system and method that allows a mobile device to receive authentication data from a security token via NFC, transmit it to an authentication server for provisioning, and store second authentication data for initiating transactions, enabling the device to emulate the security token for secure transactions without physical possession.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile devices use NFC technology to exchange data with security tokens, then transaction security is improved, but device complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual security token in the mobile device that copies the functionality of a physical security token. The virtual token emulates the authentication and transaction capabilities of the physical token through software implementation, allowing the device to perform security functions without requiring the actual physical token present

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the mobile device and the transaction system. The server verifies the mobile device's credentials and manages the token emulation process, reducing the complexity burden from the mobile device itself while maintaining security through centralized verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical security tokens are required for transactions, then transaction security is maintained, but user convenience deteriorates

Engineering Contradiction:
Improvetransaction securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The virtual security token in the mobile device replicates the authentication capabilities of the physical token, allowing users to perform transactions using their mobile device instead of carrying and physically handling a separate security token. This copying approach maintains security verification while eliminating the need for physical token possession

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The mobile device serves multiple functions by integrating both NFC communication capabilities and virtual security token functionality into a single device. This multi-functionality eliminates the need for separate physical tokens while maintaining security, as the mobile device can both communicate via NFC and provide authentication credentials

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If virtual security tokens are implemented in mobile devices, then user convenience is improved, but security risks increase

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The authentication server acts as a secure intermediary that verifies the mobile device's credentials before allowing token emulation. This centralized verification process ensures that only authorized devices can create virtual tokens, maintaining security control while enabling convenient mobile access

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the authentication server continuously verifies the mobile device's credentials and monitors transaction activities. This ongoing verification provides real-time security validation, ensuring that virtual token usage remains secure while maintaining user convenience

Inventive Principle:
Principle #23Feedback

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables secure and convenient transaction initiation on mobile devices without needing to carry physical security tokens, enhancing user experience and reducing the need for new token issuance, while ensuring security through proximity verification and user authentication.

Implementation Method 1

NFC technology is commonly used for contactless short-range communications based on radio frequency identification (RFID) standards, using magnetic field induction to enable communication between electronic devices

Methodology Applied
Scientific EffectMagnetic field induction: Electromagnetic Induction

Data Source

PatentEP2602980B1Transaction provisioning for mobile wireless communications devices and related methods
Publication Date: 2017.02.15 BLACKBERRY LTD
  • EP2602980B1 patent drawing
  • EP2602980B1 patent drawing
  • EP2602980B1 patent drawing

AI summary

A mobile communications device may include a memory, a transceiver, and a controller coupled with the memory and the transceiver. The controller may be capable of receiving first authentication data from a security token via communication with the security token, where the first authentication data is associated with an account. The controller may also be capable of transmitting the first authentication data via the transceiver, and receiving second authentication data via the transceiver, where the second authentication data is also associated with the account. The controller may be further capable of storing the second authentication data in the memory, and transmitting a transaction request using the second authentication data.