NFC Card Binding for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods relying on login IDs and passwords are insecure, as users often write down passwords or use weak ones, and require additional steps for two-factor authentication, which can be inconvenient, especially when accessing the same resources repeatedly under similar circumstances.

Innovation Solution

A system that binds a second authentication factor, such as a security card or smartphone, to a computing device, allowing users to access protected resources without manually reentering authentication information by using a pairing code and tapping the card, which confirms user consent and provides enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication is implemented using smart cards or fobs, then security is enhanced, but user convenience deteriorates due to manual entry requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary binding between the second authentication factor device and the computing device during an initial setup phase. This binding information is stored for future use, so that subsequent authentication operations can proceed automatically without manual intervention, thus maintaining security while improving convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service authentication by automatically utilizing the bound second authentication factor device (such as a smartphone with NFC) to provide authentication credentials without requiring the user to manually enter codes or information. The bound device automatically responds to authentication requests, making the process convenient while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual second factor authentication is required each time, then security is maintained, but time consumption increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The binding operation is performed as a preliminary action during initial setup, storing the relationship between the second authentication factor device and the computing device. This eliminates the need for repeated manual configuration and authentication steps, reducing time consumption while maintaining security through the stored binding information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once binding is established, the system maintains continuous authentication capability through the bound device, allowing repeated authentication operations to proceed automatically without interrupting the user workflow. This eliminates repeated manual steps and reduces overall authentication time across multiple access events.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If authentication information is cached on the computing device, then access speed improves, but security risk increases

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system introduces a bound second authentication factor device as an intermediary that stores and provides authentication credentials securely. Instead of caching sensitive authentication information directly on the computing device, the bound device acts as a secure intermediary that responds to authentication requests, thus improving access speed while reducing security vulnerabilities on the computing device itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11736468B2Enhanced authorization
Publication Date: 2023.08.22 ASSA ABLOY AB
  • US11736468B2 patent drawing
  • US11736468B2 patent drawing
  • US11736468B2 patent drawing

AI summary

Confirming user consent includes prompting the user to tap a card a card reader or a computing device and confirming consent in response to the user taping the card. The user may be prompted for a response in a plurality of possible responses and only a particular one of the possible responses may require taping the card. The user may consent to installation of software on the computing device. The user may be logged in to the computing device. A login ID for the user may be cached and/or may be accessed in connection with the user tapping the card. Confirming user consent may also include obtaining a pairing code for accessing the card and confirming consent in response to the user taping the card and the pairing code allowing access to the card. The pairing code may be cached in the card reader or the computing device.