NFC Access Control via Application Signature Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security mechanisms for controlling access to NFC-enabled cards lack granularity and security, as they do not provide per-application filtering, making it possible for rogue applications to access critical information.
Innovation Solution
Implementing an Access Control List (ACL) on a device's memory that stores application signatures and corresponding card identifiers, allowing the processor to determine whether an application is granted or denied access to a specific NFC-enabled card based on its signature and identifier.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control is implemented at the main CPU level or through Secure Element APIs, then access to NFC cards is controlled, but the security granularity is insufficient and rogue applications can still access critical information
Solution Approach 1:
The access control mechanism is segmented into multiple layers: device-level ACL policy storage, application-level signature verification, and card-level identifier matching. This segmentation allows fine-grained control where each layer handles specific aspects of access control, preventing rogue applications from accessing critical information while maintaining manageable complexity through modular design
Solution Approach 2:
An intermediary access control module is introduced between the application layer and the NFC card access layer. This intermediary enforces the ACL policy by verifying application signatures and matching card identifiers before allowing access, thereby enhancing security without requiring complex changes to existing CPU or Secure Element architectures
2Reliability
If per-application access control is implemented via ACL with signatures and card identifiers, then security granularity is improved, but device complexity increases
Solution Approach 1:
Access control policies are pre-configured in the ACL structure with application signatures and corresponding card identifiers before runtime execution. This preliminary action eliminates the need for complex runtime policy generation or evaluation, reducing operational complexity while enabling fine-grained per-application control. The ACL is populated in advance with authorized application-card mappings
Solution Approach 2:
The access control mechanism uses cryptographic signature verification as a parameter to determine access rights. By changing the verification parameter from simple permission flags to cryptographic signature validation, the system achieves robust per-application control without proportionally increasing complexity, as signature verification is a standard cryptographic operation
Data Source
AI summary
The present relates to a method and device for controlling access from the device to a card via a Near Field Communication (NFC) interface of the device. An Access Control List (ACL) is stored at a memory of the device. The ACL comprises application signatures and corresponding card identifiers. A request is received at a processor of the device from a specific application executing on the device. The request is for accessing a particular NFC enabled card via the NFC interface of the device. The request comprises a particular card identifier of the particular card and a specific signature of the specific application. A determination is made by the processor based on the specific signature, the particular card identifier and the ACL. The determination consists in whether the specific application is granted or alternatively denied access to the particular card via the NFC interface.


