Air Interface Security for NFC Proximity Cards

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The ISO/IEC 14443 standard lacks security protection mechanisms for its air interface, leading to vulnerabilities such as information interception, counterfeiting, and tampering, which threaten personal property and public security due to the absence of authentication and encryption in non-contact communication systems.

Innovation Solution

Implementing a security method that includes a proximity coupling device transmitting a security parameter request message to a proximity card, followed by the card responding with security parameters to establish a secure link, utilizing mechanisms like Request for Answer To Select (RATS) and Answer To Select (ATS) for authentication and cipher algorithm negotiation, enabling identity authentication and confidential communication without additional hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If the ISO/IEC 14443 standard is used for non-contact communication, then communication convenience and speed are improved, but security protection capability deteriorates due to lack of authentication and encryption mechanisms

Engineering Contradiction:
Improvecommunication speedVSAvoidsecurity protection capability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing security parameters and authentication mechanisms before the actual data transmission occurs. The proximity coupling device and proximity card first negotiate security parameters (including authentication algorithms and cipher algorithms) through preliminary communication, then use these pre-established parameters to protect subsequent data transmission, thus ensuring security without slowing down the actual communication process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of communication by introducing security parameters (authentication algorithms, cipher algorithms, key exchange mechanisms) into the existing ISO/IEC 14443 framework. This allows the system to maintain the original fast non-contact communication characteristics while adding security functionality through parameter expansion rather than fundamental protocol redesign

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security protection mechanisms are added to the air interface, then security capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing security mechanisms that can be integrated into existing proximity card and proximity coupling device without requiring separate dedicated security hardware. The same communication interface and processing units are used for both normal data transmission and security parameter negotiation, making the security functionality multi-functional rather than adding separate complex subsystems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the security protection functions with the existing communication protocol by integrating authentication and encryption mechanisms directly into the ISO/IEC 14443 air interface protocol. The security parameters are negotiated and applied within the same communication flow, combining security functionality with the original communication mechanism rather than separating them into distinct complex systems

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If authentication and encryption mechanisms are implemented, then data security is improved, but communication efficiency deteriorates due to additional negotiation steps

Engineering Contradiction:
Improvedata securityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by completing all security parameter negotiation and authentication setup before the actual data transmission begins. The proximity coupling device and proximity card first exchange security parameters (including selecting authentication algorithms and establishing session keys), then proceed to efficient data transmission using the pre-configured secure channel, thus minimizing the impact on overall communication efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses feedback mechanisms where the proximity card responds to security parameter requests with its supported algorithms and capabilities, allowing the proximity coupling device to select appropriate security parameters based on mutual capabilities. This feedback-based negotiation ensures that security measures are optimized for each specific communication pair, avoiding unnecessary overhead by selecting the most efficient algorithms available

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2838224B1Air interface security method and device
Publication Date: 2018.07.25 CHINA IWNCOMM

AI summary

Provided is an air interface security method. In the process of protocol transmission, the method executes: 1) a short-range coupling device sending a security parameter request message to a short-range card; 2) after receiving the security parameter request message, the short-range card conducting security parameter feedback on the short-range coupling device; and 3) the short-range coupling device and the short-range card establishing a security link according to a security parameter. In addition, also provided are a short-range coupling device, a short-range card, etc. for achieving the abovementioned method. By introducing a security mechanism, the present invention provides a security protection capability for an air interface, can provide an identity authentication function for a short-range coupling device and a short-range card to ensure the validity and authenticity of the identities of both sides in the communications, and at the same time, will not bring an additional hardware overhead to the short-range coupling device and the short-range card.