NFC Authentication Intermediary for Mutual Server Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for Near Field Communication (NFC) devices lack secure and efficient mechanisms for mutual authentication between NFC tags and remote servers, particularly in scenarios where multiple devices and servers need to communicate securely.

Innovation Solution

The implementation of a processing device and authentication server system that utilizes NFC interface circuitry and network interface circuitry to perform a challenge/response authentication protocol, with NFC tags supporting cryptographic methods like AES, enabling secure authentication and key management through shared keys and session keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for NFC devices, then device simplicity is maintained, but security and efficiency of mutual authentication between NFC tags and remote servers is insufficient

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary component that mediates between NFC tags and processing devices. The server handles complex authentication protocols, key management, and mutual authentication processes, allowing the NFC tags to remain simple while achieving secure authentication through the server's sophisticated mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct functional components: NFC tags for local identification, processing devices for execution, and an authentication server for secure protocol handling. This segmentation allows each component to be optimized independently, with the server bearing the computational complexity while tags remain simple

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple devices and servers need to communicate securely, then authentication versatility is improved, but system complexity increases

Engineering Contradiction:
Improvedevice-server communication capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication server is designed with universal functionality to handle multiple authentication protocols, support various NFC tag types, and communicate with different processing devices. It provides a standardized interface that enables secure communication between diverse devices and servers without requiring device-specific complex implementations

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses cryptographic copying mechanisms where authentication credentials and session keys are replicated and distributed securely across multiple devices and servers. This allows versatile communication while maintaining security through controlled copying rather than requiring complex unique authentication paths for each device combination

Inventive Principle:
Principle #26Copying

3Reliability

If challenge/response authentication protocol is implemented, then mutual authentication strength is improved, but authentication time increases

Engineering Contradiction:
Improvemutual authentication strengthVSAvoidauthentication duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication server performs preliminary actions by pre-establishing security contexts, maintaining authentication state information, and preparing response protocols before actual authentication events occur. This reduces the time required for mutual authentication during actual use, as the server can leverage pre-computed values and pre-established protocols

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The challenge/response protocol incorporates feedback mechanisms where the server receives authentication challenges from NFC tags, processes them through optimized algorithms, and returns authenticated responses. The feedback loop is designed to minimize processing time through efficient cryptographic operations and parallel processing capabilities

Inventive Principle:
Principle #23Feedback

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides strong mutual authentication between NFC tags and servers, ensuring secure communication and allowing multiple devices and servers to authenticate securely, with features like key rotation and device binding for enhanced security.

Implementation Method 1

Near field communication (NFC) is a set of standards for smartphones and other processing devices for establishing radio communication with one another by touching them together or bringing them into close proximity, typically on a range of a few centimeters. NFC operates at 13.56 MHz on the International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) 18000-3 air interface

Methodology Applied
Scientific EffectNear Field Communication (NFC): Electromagnetic Induction

Data Source

PatentUS9571164B1Remote authentication using near field communication tag
Publication Date: 2017.02.14 RSA SECURITY USA LLC
  • US9571164B1 patent drawing
  • US9571164B1 patent drawing
  • US9571164B1 patent drawing

AI summary

An apparatus comprises a processing device comprising NFC interface circuitry, network interface circuitry, a memory and a processor coupled to the memory. The processing device is configured to establish an NFC connection with an NFC tag using the NFC interface circuitry, establish a network connection with an authentication server using the network interface circuitry, and forward one or more messages between the NFC tag and the authentication server, the one or more messages comprising messages of a challenge/response authentication protocol performed between the NFC tag and the authentication server. Responsive to a successful completion of the challenge/response authentication protocol between the NFC tag and the authentication server, the processing device is authenticated to the authentication server.