NFC Authentication Tag for Mobile App Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for securing remote access to computer applications using smartphones are inadequate due to vulnerabilities in software-based methods and the cumbersome nature of hardware solutions, which are not well-suited for smartphone interfaces.
Innovation Solution
An authentication device that utilizes Near Field Communication (NFC) technology to generate dynamic credentials by cryptographically combining a secret key with a dynamic variable, presented as an NFC tag to smartphones, allowing secure interaction with remote applications without requiring specific communication interfaces or manual data entry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software-based authentication solutions are used on smartphones, then authentication functionality is provided, but security is compromised due to malware vulnerabilities
Solution Approach 1:
The patent introduces an NFC authentication tag as an intermediary device between the user and the remote application. This physical NFC tag serves as a mediator that generates and transmits authentication credentials through NFC communication, bypassing the vulnerable software layer on the smartphone. The NFC tag acts as a trusted intermediary that cannot be compromised by malware running on the smartphone operating system.
Solution Approach 2:
The patent replaces the software-based authentication system with a hardware-based NFC authentication mechanism. Instead of relying on software applications and operating systems that are vulnerable to malware, the system uses NFC hardware tags and readers to perform authentication. This substitution of mechanical/hardware systems for software systems eliminates the security vulnerability to malware attacks.
2Reliability
If hardware authentication solutions like smart cards or USB tokens are used, then security is improved, but device complexity and interface requirements increase
Solution Approach 1:
The patent leverages the universal NFC capability already present in modern smartphones to provide authentication functionality. Instead of requiring specialized interfaces like smart card readers or USB ports, the solution uses the universally available NFC interface. This makes the authentication system compatible with virtually all contemporary smartphones without adding complexity or requiring additional hardware interfaces.
Solution Approach 2:
The patent uses an NFC authentication tag that can be presented to the smartphone's NFC reader. The tag contains or generates authentication credentials that are read by the NFC interface. This copying approach allows the authentication credentials to be transferred from the NFC tag to the smartphone or directly to the remote application server, eliminating the need for complex interfaces while maintaining security.
3Reliability
If manual data copying for authentication is required, then security can be maintained, but ease of operation deteriorates due to user inconvenience
Solution Approach 1:
The patent implements an automated authentication process where the NFC tag and smartphone automatically exchange authentication data without requiring manual copying by the user. The system performs self-service authentication by automatically generating, transmitting, and verifying credentials through NFC communication. This eliminates the need for users to manually copy one-time passwords or authentication data, greatly improving ease of operation while maintaining security.
Solution Approach 2:
The authentication credentials are prepared and made available in the NFC tag before the authentication transaction occurs. The tag is pre-configured with authentication data or the capability to generate it on-demand. This preliminary preparation allows the authentication to proceed automatically without requiring the user to perform manual copying or data entry actions during the transaction.
4Ease of operation
If NFC authentication tags are used, then ease of operation is improved, but compatibility with smartphone operating systems may be limited
Solution Approach 1:
The NFC authentication tag serves as an intermediary that operates independently of the smartphone's operating system. The tag communicates through the NFC interface using standardized protocols that are supported by all NFC-enabled devices regardless of their operating system. This intermediary approach bypasses OS-specific limitations and provides universal compatibility across different smartphone platforms.
Solution Approach 2:
The patent utilizes the NFC communication parameters and protocols that are standardized across different operating systems. By operating at the NFC hardware protocol level rather than the application software level, the solution achieves compatibility across iOS, Android, and other smartphone operating systems. The NFC interface parameters remain consistent regardless of the underlying OS, enabling broad adaptability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, apparatus, and systems for securing a mobile application are disclosed. Users of the mobile application may be authenticated using a smartphone or other device including a Near-Field Communication (NFC) transfer device capable of NFC communication. An authentication device may be adapted to present itself to the NFC transfer device as an NFC tag and make a dynamic credential available to the NFC transfer device by including the dynamic credential in an NFC tag readable by the NFC transfer device using NFC mechanisms for reading data contents of NFC tags. An access device comprising the NFC transfer device may then provide the dynamic credential to an application server for verification.