NFC Identity Verification System for Credential Theft Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity verification methods, primarily based on password verification, are inadequate in security as they can be compromised by brute-force attacks, keyboard input interception, and phishing, leading to potential theft of user credential information.

Innovation Solution

A user identity verification method utilizing near field communication (NFC) where identity verification information is generated and sent to an NFC terminal, prompting the user for acknowledgement, allowing verification without requiring input of identity credentials, thus reducing user input and preventing credential theft.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password verification is used for identity authentication, then the verification process is simple and fast, but the security is insufficient due to brute-force attacks, keyboard input interception, and phishing

Engineering Contradiction:
Improveidentity verification securityVSAvoiduser input requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical keyboard input system with a biometric recognition system. Instead of requiring users to manually type passwords through keyboards, the system uses fingerprint recognition, facial recognition, or other biometric modalities to automatically verify user identity. This substitution eliminates the security vulnerabilities of password-based systems (brute-force attacks, keyloggers, phishing) while maintaining ease of operation through automatic biometric capture and comparison.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a biometric authentication intermediary between the user and the system. Rather than directly verifying passwords entered by users, the system uses biometric data as an intermediary verification layer. The biometric scanner captures physiological data, compares it against stored templates, and uses this intermediary verification to grant or deny access, thereby preventing direct exposure of authentication credentials to potential attackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dynamic passwords are used to avoid interception by Trojan horses, then security is improved, but phishing attacks within a short time period remain possible and user credential input is still required

Engineering Contradiction:
Improveprotection against Trojan horse interceptionVSAvoidphishing attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the dynamic password input mechanism with biometric recognition. Instead of requiring users to enter time-sensitive codes that are vulnerable to phishing, the system captures biometric data (fingerprint, face, iris) and automatically compares it against stored templates. This substitution eliminates both the need for user credential input and the vulnerability to phishing attacks, as biometric data cannot be phished or intercepted in the same way passwords can.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The biometric recognition system performs self-service authentication without requiring user intervention beyond presenting the biometric trait. The system automatically captures the biometric data, processes it through recognition algorithms, and makes authentication decisions. This self-service capability eliminates the need for users to manually input credentials or interact with potentially malicious phishing interfaces, as the entire authentication process occurs automatically through biometric comparison.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If user credential information is required for password verification, then identity authentication can be performed, but there is a potential possibility that the user credential information is illegally captured

Engineering Contradiction:
Improveauthentication processVSAvoidcredential information theft
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent substitutes the credential input mechanism with biometric recognition. Instead of requiring users to type or enter passwords, PINs, or security questions, the system uses biometric scanners to capture physiological data and automatically verify it against stored templates. This substitution maintains authentication functionality while completely eliminating the exposure of credential information to potential theft, as biometric data is captured automatically without user input and cannot be intercepted like traditional credentials.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent extracts the credential verification process from the user input domain and places it in the biometric recognition domain. By separating the authentication function from manual credential entry, the system removes vulnerable credential information from the authentication flow entirely. The biometric template stored in the system serves as the extracted credential reference, while the actual authentication occurs through comparison with live biometric data, preventing any exposure of sensitive credential information.

Inventive Principle:
Principle #2Taking out (Extraction)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances security by verifying user identity through NFC terminal identifiers, reducing the risk of credential theft and phishing, and improving overall identity verification security.

Implementation Method 1

sending, by the password protection apparatus, the identity verification information to an NFC terminal through near field communication with the NFC terminal

Methodology Applied
Scientific EffectNear field communication (NFC): Electromagnetic Induction

Data Source

PatentUS9635018B2User identity verification method and system, password protection apparatus and storage medium
Publication Date: 2017.04.25 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9635018B2 patent drawing
  • US9635018B2 patent drawing
  • US9635018B2 patent drawing

AI summary

A user verification method and system, a password protection apparatus and a storage medium are disclosed, and the method includes: receiving an operation request containing a user identity of a user sent by the user via a user terminal; generating identity verification information according to the user identity; sending the identity verification information to an NFC terminal through near field communication with the NFC terminal, so that the NFC terminal prompts the user to provide identity acknowledgement; receiving identity acknowledgement information from the NFC terminal, if the identity acknowledgement is provided by the user, where the identity acknowledgement information contains an identifier of the NFC terminal; determining whether the user identity matches the identifier of the NFC terminal according to the identity acknowledgement information; and sending operation response information to the user terminal of the user if the user identity matches the identifier of the NFC terminal.