NFC Peer-to-Peer Authentication via Encrypted NDEF Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication and secure data transfer systems face limitations in ensuring secure peer-to-peer communication between NFC-enabled devices, particularly in verifying credentials and maintaining data integrity.

Innovation Solution

A system utilizing NFC peer-to-peer capability, where a mobile device with an NFC transceiver securely authenticates with an NFC reader device through the Android NFC Data Exchange Format (NDEF) Push Protocol and Simple NDEF Exchange Protocol, supported by ISO/IEC standards, to exchange encrypted data, ensuring secure data transfer and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If NFC peer-to-peer communication is used for authentication and data transfer, then data transfer speed and convenience are improved, but security risks increase due to potential credential interception and unauthorized access

Engineering Contradiction:
Improvedata transfer speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where credentials are not directly transmitted between devices. Instead, an authentication protocol acts as a mediator that verifies device identities and establishes secure communication channels before allowing data transfer, thus preventing direct credential interception while maintaining fast NFC communication

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the state of credential transmission from clear-text to encrypted form, and dynamically adjusts security parameters such as authentication tokens and session keys during the communication process. This transformation ensures that even if data is intercepted during fast NFC transfer, the encrypted parameters prevent unauthorized access

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional authentication methods are used, then security is maintained through verified credentials, but device complexity and authentication time increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework that can work across different NFC devices and platforms (Android, iOS, etc.) through standardized protocols. This multi-functional approach maintains strong security verification while reducing device-specific complexity by using a common authentication mechanism that handles various credential types and device configurations

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary authentication actions by pre-establishing security credentials and authentication certificates on devices before actual data transfer occurs. This preliminary setup includes pre-shared keys and device identity verification, which streamlines the actual authentication process during use while maintaining high security standards

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If credentials are transmitted in clear-text for simplicity, then ease of operation is improved, but data integrity and security are compromised

Engineering Contradiction:
Improveauthentication simplicityVSAvoiddata integrity
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent replaces the mechanical approach of clear-text credential transmission with an cryptographic system that automatically encrypts and decrypts data. This substitution maintains ease of operation for users (who don't need to manually encrypt data) while ensuring data integrity through automated encryption mechanisms that protect credentials during transmission

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10925102B2System and method for NFC peer-to-peer authentication and secure data transfer
Publication Date: 2021.02.16 SCHLAGE LOCK CO LLC
  • US10925102B2 patent drawing
  • US10925102B2 patent drawing
  • US10925102B2 patent drawing

AI summary

A reader device may generate a first identifier. The reader device may transmit the first identifier to a mobile device. The reader device may receive encrypted data and unencrypted data from the mobile device in which the encrypted data includes a second identifier. The reader device may evaluate whether the first identifier and the second identifier correspond to one another.