NFC Mobile Device Access Policy Issuance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users without management or access rights for security content cannot access it, especially in closed network or offline environments where service server access is not possible, and existing NFC technologies are limited in peer-to-peer communication for secure content access.

Innovation Solution

An apparatus and method using near-field communication between mobile devices to securely issue access rights for security content, where a first mobile device registers as a content security policy issuance provider and issues a temporary policy to a second mobile device, allowing access without relying on a connection to a service server, utilizing a DRM client application for authentication and policy management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access rights are managed through service server in traditional NFC system, then centralized security control is improved, but system reliability deteriorates in closed network or offline environments where server access is not possible

Engineering Contradiction:
Improveaccess right issuance reliabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized server-based access right management into distributed mobile device-based management. Each mobile device can independently issue access rights to other devices through NFC, eliminating dependency on continuous server connectivity while maintaining security control through local policy storage and execution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables mobile devices to perform self-service access right issuance. Registered mobile devices can autonomously issue access rights to unauthorized devices through NFC communication without requiring server intervention, allowing the system to function independently in offline or closed network environments.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If traditional NFC peer-to-peer communication is used for access right issuance, then ease of operation is improved, but security control deteriorates due to lack of centralized authentication

Engineering Contradiction:
Improveaccess right issuance convenienceVSAvoidaccess right security control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-registering authorized mobile devices with the service server before they need to issue access rights. This pre-authentication establishes trust relationships and policy frameworks in advance, enabling secure peer-to-peer access right issuance without requiring real-time server verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces mobile devices as intermediary agents between the centralized security policy (stored on server) and the access right issuance process. Registered devices store and execute security policies locally, acting as trusted intermediaries that can issue access rights autonomously while maintaining security control through pre-established policy frameworks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If centralized server-based access right management is used, then access right security is improved, but adaptability deteriorates in closed network or offline environments

Engineering Contradiction:
Improveaccess right securityVSAvoidnetwork environment adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamics by transitioning from a static server-dependent access right management system to a dynamic distributed system. Mobile devices can dynamically issue access rights to each other through NFC based on locally stored policies, allowing the system to adapt to various network conditions including offline, closed network, and peer-to-peer environments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies local quality by enabling each mobile device to store and execute security policies locally rather than relying on continuous server communication. This localizes the security control functionality to individual devices, allowing them to independently manage access rights in diverse network environments while maintaining security through locally cached policy frameworks.

Inventive Principle:
Principle #3Local quality

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables secure issuance and access of security content rights between mobile devices in any network environment, including closed or offline settings, by converting a mobile device into a content security policy issuance provider through near-field network communications, ensuring access rights can be granted independently of server connectivity.

Implementation Method 1

a near-field communication (NFC) is one of radio frequency identification (RFID) technologies. It is a contactless near distance wireless communication technology which uses a 13.56 Mhz frequency band and is capable of transmitting data within a distance less than 10 centimeters

Methodology Applied
Scientific EffectNear-field communication (NFC): Electromagnetic Induction

Data Source

PatentUS9967286B2Apparatus and method for controlling access to security content using near field network communication of mobile devices
Publication Date: 2018.05.08 FASOO COM
  • US9967286B2 patent drawing
  • US9967286B2 patent drawing
  • US9967286B2 patent drawing

AI summary

Disclosed is an apparatus for controlling access to a security content using near field network communication of mobile devices. A policy issuance provider registration unit requests a content security policy for a first content, a security content, to a service server, receives the content security policy for the first content, requests to the service server for a first mobile device to be registered as a content security policy issuance provider, and receives a result of registration and a provider policy from the service server. A policy issuance provider converting unit converts the first mobile device to the content security policy issuance provider when receiving a request for access for browsing the first content through near-field network communication from another mobile device in which a DRM client application is being executed. A temporary content security policy issuance unit issues a temporary content security policy for the first content through near-field network communication to the second mobile device so that the second mobile device can browse the first content.