Multi-Factor Authentication via NFC Electronic Card Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional risk-based authentication methods are inadequate in providing a strong and reliable mechanism for user authentication, especially when accessing protected resources of a non-financial nature, as they rely solely on numerical risk scores without incorporating additional authentication factors.

Innovation Solution

The method involves authenticating users by combining device fingerprint, personal identification number (PIN), and electronic card credentials using near field communication (NFC) between a client apparatus, such as a smartphone, and an integrated circuit credit card, employing the EMV standard for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional risk-based authentication is used with only username and password, then the authentication process is simple and quick, but the authentication strength and reliability are insufficient

Engineering Contradiction:
Improveauthentication strengthVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication factors (device fingerprint, PIN, electronic card credentials via NFC) into a unified authentication process. This merging of different authentication mechanisms creates a multi-factor authentication system that significantly strengthens reliability while managing complexity through integrated processing.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is designed to accept and process multiple types of credentials through a single interface. The system can handle device fingerprints, PINs, and electronic card credentials (EMV standard) universally, allowing one authentication mechanism to serve multiple authentication purposes and strengthen security without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication factors are combined, then authentication strength is significantly improved, but the authentication process becomes more complex and time-consuming

Engineering Contradiction:
Improveauthentication strengthVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing device fingerprints and storing authentication credentials before the actual authentication event. When authentication is needed, the device fingerprint is already captured and electronic card credentials are pre-provisioned, allowing rapid verification without time-consuming setup during the authentication moment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements step-up authentication that skips certain verification steps when risk is low. If initial authentication factors indicate low risk, the system can rush through the process with fewer checks. However, if risk thresholds are exceeded, additional authentication factors are rapidly verified to complete authentication quickly while maintaining security.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Reliability

If electronic card credentials are integrated into the authentication process, then authentication reliability is enhanced, but the device complexity and operational complexity increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by allowing users to automatically present their electronic card credentials through NFC when prompted. The mobile device automatically communicates with the authentication system, and the electronic card credentials are verified without requiring manual intervention beyond holding the card near the device. This maintains ease of operation while integrating complex credential verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The mobile device acts as an intermediary between the user's electronic card and the authentication system. Instead of requiring direct complex interactions between the card and authentication server, the mobile device mediates the communication, handling NFC protocols, credential extraction, and verification processes, thereby simplifying user operation while maintaining authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach provides a robust form of authentication by leveraging multiple factors, significantly reducing the risk of unauthorized access and ensuring secure access to protected resources, even of a non-financial nature.

Implementation Method 1

The smart phone has near field communication circuitry. In these arrangements, performing the analysis of the set of credentials includes: (i) obtaining, as the authentication factor acquired by the client device from the electronic card, a mobile payment credential from the electronic card via the near field communication circuitry of the smart phone

Methodology Applied
Scientific EffectNear field communication (NFC): Electromagnetic Induction

Data Source

PatentUS9516010B1Authenticating a user while the user operates a client apparatus and possesses an electronic card
Publication Date: 2016.12.06 EMC IP HLDG CO LLC
  • US9516010B1 patent drawing
  • US9516010B1 patent drawing
  • US9516010B1 patent drawing

AI summary

A technique perform authentication. The technique involves receiving an authentication request from a user operating a client apparatus (e.g., the user's smart phone). The technique further involves performing, in response to the authentication request, an analysis of a set of credentials obtained from the client apparatus. The set of credentials includes an authentication factor acquired by the client apparatus from an electronic card in possession of the user (e.g., an integrated circuit credit card). The electronic card is separate from the client apparatus. The technique further involves outputting, based on the analysis of the set of credentials, an authentication result indicating whether the processing circuitry deems the user operating the client apparatus to be authentic.