NFC Authentication for Corporate Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of cloud-based storage for corporate data has heightened the demand for enhanced security measures, as traditional login processes with passwords are inadequate for secure access to sensitive information, particularly in enterprise environments.

Innovation Solution

A system and method utilizing Near Field Communication (NFC) for authentication and validation, where a mobile phone with a trusted security zone stores private enterprise credentials, transmitting them securely to a building access sensor and enterprise server, establishing a chain of trust to authenticate users and grant access to corporate data and facilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional login processes with passwords are used, then ease of operation is maintained, but security is insufficient for protecting corporate data

Engineering Contradiction:
ImprovesecurityVSAvoidlogin process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical/password-based authentication system with a biometric authentication system using NFC technology. The mobile device captures biometric data (fingerprint, facial recognition, or iris scan) and transmits it via NFC to the enterprise server, substituting the traditional password entry mechanism with a contactless biometric verification process that enhances security while maintaining user convenience

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a trusted security zone within the mobile device as an intermediary component. This security zone securely stores biometric templates and authentication credentials, acting as a mediator between the biometric sensor and the enterprise server. The security zone processes biometric data locally and only transmits authentication results via NFC, preventing exposure of sensitive biometric information while enabling secure authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud-based storage is used for corporate data, then accessibility is improved, but security risks from hackers and malware increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication actions before granting access to cloud-based corporate data. The system requires successful biometric authentication through the mobile device and NFC transmission before allowing any access to the enterprise network or cloud resources. This preliminary security check ensures that only authenticated users can access cloud-based corporate data, preventing unauthorized access from hackers and malware

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trusted security zone in the mobile device serves as an intermediary that securely handles biometric authentication credentials. It processes biometric data locally, generates authentication tokens, and transmits them via NFC to the enterprise server. This intermediary layer protects sensitive biometric information from exposure to potential hackers and malware while enabling secure access to cloud-based corporate data

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8494576B1Near field communication authentication and validation to access corporate data
Publication Date: 2013.07.23 T MOBILE INNOVATIONS LLC
  • US8494576B1 patent drawing
  • US8494576B1 patent drawing
  • US8494576B1 patent drawing

AI summary

A system for near field communication authentication (NFC) and validation to access corporate data is provided. The system comprises a mobile phone, an enterprise server, a building access sensor coupled to the server, and an enterprise network comprising a domain. The sensor comprises a NFC transceiver. The phone comprises a NFC transceiver and a trusted security zone which comprises private enterprise credentials and an application, where the application establishes a wireless link to the sensor via the NFC transceiver, couples the NFC transceiver with memory storing the credentials, and transmits the credentials to the sensor via the NFC transceiver. The enterprise server comprises a trusted security zone and an application stored in the trusted security zone, where the application receives the credentials via the sensor, authorizes access to the building based on the credentials, and authenticates the user to the domain on the enterprise network.