NFC Authentication Session Opening via Autonomous Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current reinforced authentication methods, which rely on physical tokens, are cumbersome due to the need to carry and read a device with a small, unlit screen, require multiple inputs, and can be desynchronized, making them difficult to use and manage.

Innovation Solution

A method using near-field communication (NFC) between a computer terminal and an autonomous device to authenticate by detecting the device, obtaining its identifier and public key, sending an encrypted challenge message, and decrypting a response to open a secure session without entering authentication information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical tokens are used for strong authentication, then security is improved, but ease of operation deteriorates due to the need to carry a device with a small unlit screen and enter multiple pieces of information

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical interaction of manually entering authentication codes from a physical token with an automated wireless communication system. The mobile terminal automatically receives authentication codes via NFC or other wireless communication, eliminating the need for manual typing and improving ease of operation while maintaining security through the same token-based authentication mechanism

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a mobile terminal as an intermediary device between the physical authentication token and the computer terminal. The mobile terminal acts as a mediator that receives authentication codes from the token and automatically transmits them to the computer terminal, simplifying the user interaction while preserving the security benefits of physical token authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Length of moving object

If physical tokens with small unlit screens are used, then device size and durability are improved, but readability of the character sequence deteriorates

Engineering Contradiction:
Improvetoken sizeVSAvoidcharacter sequence readability
Core Design Contradiction:
Length of moving objectVSDifficulty of detecting and measuring

Solution Approach 1:

The mobile terminal serves as an intermediary that receives the hard-to-read character sequence from the small-screened physical token and displays it on its own larger, illuminated screen. This allows the user to easily read the authentication code without requiring the physical token to have a large or illuminated display

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transfers the authentication code display from the two-dimensional constrained space of the physical token's small screen to the mobile terminal's display, utilizing the additional dimension of the mobile device's larger screen real estate to improve readability while keeping the token compact

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If physical tokens are used for authentication, then security is improved, but device complexity increases due to the need for constant synchronization with a token management server

Engineering Contradiction:
Improveauthentication securityVSAvoidtoken management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the mobile terminal to automatically manage the authentication process without requiring manual synchronization with a token management server. The system performs self-service by automatically receiving authentication codes from the physical token and transmitting them to the computer terminal, eliminating the need for complex manual synchronization procedures

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach simplifies the authentication process by eliminating the need to manually input information and reduces the risk of desynchronization, providing a more user-friendly and secure method for opening sessions.

Implementation Method 1

a computer terminal, the computer terminal being configured for near-field communications, via a self-contained device configured for near-field communications

Methodology Applied
Scientific EffectNear-field communication: Electromagnetic Induction

Data Source

PatentEP3674937B1Method for opening a secure session on a computer terminal
Publication Date: 2021.11.10 EVIDIAN
  • EP3674937B1 patent drawingFigure 1~2
  • EP3674937B1 patent drawingFigure 3
  • EP3674937B1 patent drawingFigure 4

AI summary

A method for opening a secure session on a computer terminal, the computer terminal being configured for near-field communications, via an autonomous device configured for near-field communications, characterized in that the session opening is carried out by implementing at least the following steps: - Detection of the autonomous device by the computer terminal, the detection being done by near field; - Obtaining, by the computer terminal via near-field communication, an identifier of the autonomous device; - Obtaining, by the computer terminal, a user identifier and a public key, the user identifier and the public key being associated with the identifier of the autonomous device in a directory server;- Transmission, by the computer terminal via near-field communication, of a challenge message containing a session key and a random number, these elements being encrypted using the public key; - Reception, by the computer terminal via near-field communication, of a challenge resolution message; - Decryption, by the computer terminal, of the challenge message using the session key as the decryption key; if the decryption result yields the random number, then: - Opening, on the computer terminal, of a session for the obtained user ID.