Contextual Authentication via NFC Mobile Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication (MFA) technologies face challenges when users need to access protected resources remotely, particularly when the client computing device lacks an NFC reader, as they cannot wirelessly transmit security keys, leading to limitations in accessing protected resources like virtual sessions.

Innovation Solution

The method employs contextual authentication using near-field communication (NFC) by determining the client computing system's context, such as proximity to an NFC-capable mobile device, to obtain and deliver security keys via peer-to-peer connections or virtual backend systems, enabling secure remote sessions even without direct NFC capabilities on the client device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a physical connection (USB port) is used to transmit security key, then authentication security is improved, but device compatibility and remote access capability deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a mobile device as an intermediary component that bridges the gap between USB security keys and NFC-capable systems. The mobile device receives the security key via USB from the security key device, stores it temporarily, and then transmits it wirelessly via NFC to the target device, enabling authentication in scenarios where direct USB connection is not feasible.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical USB physical connection with wireless NFC communication for the final transmission stage. This substitution allows the security key to be transmitted without physical contact, enabling remote authentication scenarios while maintaining security through the use of encrypted NFC communication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If NFC communication is used for wireless security key transmission, then device compatibility and ease of operation are improved, but authentication security deteriorates

Engineering Contradiction:
Improvewireless transmission capabilityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing the security key on the mobile device through a secure USB connection before the NFC transmission occurs. This preliminary secure establishment ensures that the cryptographic material is safely loaded onto the mobile device, which then acts as a secure intermediary for the wireless transmission.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device serves as a trusted intermediary that manages the security key throughout the authentication process. It securely receives the key via USB, maintains it in a protected environment, and controls its release via NFC only when appropriate authentication conditions are met, thereby maintaining security while enabling wireless operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If security key is stored on client computing device, then authentication speed is improved, but security risk increases

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication system into multiple components: the security key device, the mobile device, and the target system. The security key is not permanently stored on any single device but is temporarily present during the authentication process, reducing the security risk of centralized storage while maintaining authentication speed through the coordinated interaction of segmented components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mobile device provides self-service by managing its own secure storage and transmission of the security key. The key remains protected on the mobile device until needed, at which point it is transmitted temporarily and then can be revoked or updated, allowing fast authentication without long-term security vulnerabilities.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach allows seamless authentication for remote sessions by leveraging NFC capabilities on mobile devices, ensuring secure access to protected resources even when the client device lacks NFC readers, thereby enhancing the usability of MFA in diverse computing environments.

Implementation Method 1

a security key is to be obtained from a near-field communication (NFC) device connected to a mobile device

Methodology Applied
Scientific EffectNear-field communication (NFC):

Data Source

PatentUS12081970B2Contextual authentication for secure remote sessions
Publication Date: 2024.09.03 CITRIX SYSTEMS INC
  • US12081970B2 patent drawing
  • US12081970B2 patent drawing
  • US12081970B2 patent drawing

AI summary

A contextual authentication method includes receiving a request to launch a web service and causing the web service to be launched on a remote browser. When a security event is detected, a security key obtained, based on a context of a client computing system, from a near-field communication (NFC) device connected to a mobile device. The security key is requested and received from the NFC device via the mobile device. The security key is delivered to the web service via the remote browser.