Certificate-Free Public Key Exchange Over NFC

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for establishing a secure channel between devices require the storage of multiple public keys and certificates, which is inefficient and burdensome, especially in systems without a certification authority.

Innovation Solution

A method involving a protocol management computer that utilizes a near-field communications channel to exchange encrypted public keys using initialization keys stored during manufacturing, eliminating the need for certificate storage and simplifying the key exchange process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional certificate-based public key exchange is used, then secure channel establishment is achieved, but device complexity and data storage requirements increase due to multiple public keys and certificates

Engineering Contradiction:
Improvesecure channel establishmentVSAvoidkey storage requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the certificate authority infrastructure from the key exchange process and replaces it with a simplified initialization key mechanism. Instead of storing multiple certificates and public keys, each device stores only a single initialization key generated during manufacturing, dramatically reducing storage requirements while maintaining security through encrypted public key exchange over NFC channels

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary key generation during the device manufacturing process, where initialization keys are generated and stored in secure elements before deployment. This preliminary action eliminates the need for complex runtime key management and certificate storage, as the initialization keys are pre-configured and ready for immediate use in establishing secure channels

Inventive Principle:
Principle #10Preliminary action

2Reliability

If certificate authority systems are implemented, then public key exchange security is improved, but the system requires more public keys to be stored on each device

Engineering Contradiction:
Improvepublic key exchange securityVSAvoidnumber of public keys stored
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent removes the certificate authority layer from the key exchange architecture and replaces it with a direct device-to-device initialization key verification mechanism. Each device verifies the other's public key using its stored initialization key, eliminating the need to store multiple CA certificates and reducing the quantity of stored cryptographic material from multiple keys to a single initialization key per device

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent enables devices to perform self-verification of public keys using their own initialization keys without requiring external certificate authorities. Each device independently verifies the authenticity of the other device's public key by decrypting it with its stored initialization key, eliminating the need for centralized certificate management and reducing storage requirements

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple public keys and certificates are stored for secure communication, then authentication reliability is improved, but data storage efficiency deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddata storage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the essential authentication function from the complex certificate and multiple public key system, retaining only the critical initialization key that was originally embedded in secure elements during manufacturing. This extracted approach maintains authentication reliability through secure NFC-based public key exchange while reducing data storage requirements from multiple certificates and keys to a single initialization key per device

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by storing different types of cryptographic material in appropriate locations: initialization keys are stored in secure elements during manufacturing, while public keys are exchanged and stored temporarily in volatile memory during runtime operations. This localized approach ensures authentication reliability for stored keys while minimizing persistent storage requirements

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250330305A1Techniques for secure data exchanges
Publication Date: 2025.10.23 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20250330305A1 patent drawing
  • US20250330305A1 patent drawing
  • US20250330305A1 patent drawing

AI summary

Systems and methods are for performing a secure exchange of encryption keys (e.g., public keys) between two devices. One or more initialization keys are stored at both devices. In some embodiments, at least one device (e.g., a reader device) stores the initialization key(s) (e.g., a symmetric key, an asymmetric key pair) in local memory as part of performance of a manufacturing process for the device. The second device (e.g., a thin client device) may receive the initialization key(s) from an acceptance cloud (e.g., a server computer configured to perform terminal processing). The initialization key(s) are utilized to perform a secure exchange of the devices' respective public keys. Once these public keys are exchanged, the devices may proceed to establishing a secure connection with which subsequent operations may be performed.