NFC Authentication Card for Portable Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication authentication methods, such as those using IEEE 802.11 and NFC, are inadequate for portable devices lacking sufficient input means or an authentication server, leading to insecure connections and user inconvenience in ad-hoc environments.

Innovation Solution

An authentication method utilizing an NFC authentication card that generates and shares authentication information between devices via NFC communication, allowing secure authentication without the need for password input or an authentication server, using a determination step to decide whether to generate or send existing authentication information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication processing is performed using conventional methods (password input, authentication server, or common key cryptography) in portable terminals, then security against unauthorized access is improved, but ease of operation deteriorates due to insufficient input means and user inconvenience

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an authentication card as an intermediary device that stores authentication information and automatically transmits it to the terminal device via NFC communication. This mediator eliminates the need for users to manually input passwords while maintaining security, as the card handles the authentication data transmission automatically when placed on the terminal device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication processing is performed using conventional methods in ad-hoc environments, then security is improved, but device complexity increases due to the need for authentication servers or complex key exchange protocols

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication server functionality from the terminal device and relocates it to the authentication card. The card independently stores authentication information and performs the authentication logic, eliminating the need for complex authentication servers or key exchange protocols in the terminal device itself. This simplifies the terminal device while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If common key cryptography is used for authentication, then ease of operation is improved, but reliability deteriorates because security in key exchange is not provided and keys may be obtained by third persons

Engineering Contradiction:
Improveauthentication simplicityVSAvoidkey exchange security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary authentication by having the authentication card pre-stored with authentication information that is securely transmitted to the terminal device before actual communication begins. The authentication card verifies the terminal device's identity and pre-establishes secure communication channels, preventing third-party key interception while maintaining operational simplicity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7797535B2Authentication method and system, and information processing method and apparatus
Publication Date: 2010.09.14 CANON KK
  • US7797535B2 patent drawing
  • US7797535B2 patent drawing
  • US7797535B2 patent drawing

AI summary

When having established communication with a data processing apparatus, a first apparatus determines whether or not to generate authentication information based on identification information about the data processing apparatus. If it is determined that generation of authentication information is necessary, then the first apparatus generates authentication information and saves it in a memory. If it is determined that generation of authentication information is necessary, the first apparatus sends the generated authentication information to the data processing apparatus with which communication has been established. If it is determined that generation of authentication information is unnecessary, then the first apparatus sends authentication information saved in the memory to the data processing apparatus with which communication has been established. Thereby, authentication between data processing apparatuses is performed with the use of the authentication information sent from the first apparatus.