NFC Access Control via Application Signature Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security mechanisms for controlling access to NFC-enabled cards lack granularity and security, as they do not provide per-application filtering, making it possible for rogue applications to access critical information.

Innovation Solution

Implementing an Access Control List (ACL) on a device's memory that stores application signatures and corresponding card identifiers, allowing the processor to determine whether an application is granted or denied access to a specific NFC-enabled card based on its signature and identifier.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is implemented at the main CPU level or through Secure Element APIs, then access to NFC cards is controlled, but the security granularity is insufficient and rogue applications can still access critical information

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control mechanism is segmented into multiple layers: device-level ACL policy storage, application-level signature verification, and card-level identifier matching. This segmentation allows fine-grained control where each layer handles specific aspects of access control, preventing rogue applications from accessing critical information while maintaining manageable complexity through modular design

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary access control module is introduced between the application layer and the NFC card access layer. This intermediary enforces the ACL policy by verifying application signatures and matching card identifiers before allowing access, thereby enhancing security without requiring complex changes to existing CPU or Secure Element architectures

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If per-application access control is implemented via ACL with signatures and card identifiers, then security granularity is improved, but device complexity increases

Engineering Contradiction:
Improveper-application access controlVSAvoidACL management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Access control policies are pre-configured in the ACL structure with application signatures and corresponding card identifiers before runtime execution. This preliminary action eliminates the need for complex runtime policy generation or evaluation, reducing operational complexity while enabling fine-grained per-application control. The ACL is populated in advance with authorized application-card mappings

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control mechanism uses cryptographic signature verification as a parameter to determine access rights. By changing the verification parameter from simple permission flags to cryptographic signature validation, the system achieves robust per-application control without proportionally increasing complexity, as signature verification is a standard cryptographic operation

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9977890B2Method and device for controlling access from the device to a card via a NFC interface
Publication Date: 2018.05.22 APPLE INC
  • US9977890B2 patent drawing
  • US9977890B2 patent drawing
  • US9977890B2 patent drawing

AI summary

The present relates to a method and device for controlling access from the device to a card via a Near Field Communication (NFC) interface of the device. An Access Control List (ACL) is stored at a memory of the device. The ACL comprises application signatures and corresponding card identifiers. A request is received at a processor of the device from a specific application executing on the device. The request is for accessing a particular NFC enabled card via the NFC interface of the device. The request comprises a particular card identifier of the particular card and a specific signature of the specific application. A determination is made by the processor based on the specific signature, the particular card identifier and the ACL. The determination consists in whether the specific application is granted or alternatively denied access to the particular card via the NFC interface.