NFC Target Device Security via PUF Authentication and Privilege Masks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unified NFC cards face security issues due to unauthorized access to sensitive data and the risk of card cloning, as NFC initiators can inadvertently or intentionally retrieve unrelated data, and nefarious parties can clone NFC cards to gain unauthorized access.
Innovation Solution
The NFC target device incorporates a memory circuit for storing sensitive data, an NFC interface for communication, and a processing circuit that manages provider identification numbers and privilege masks, along with a physical unclonable function (PUF) circuit for authentication, ensuring that only authorized providers access designated data and preventing card cloning by generating unique responses to challenges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a unified NFC card stores multiple types of sensitive data for different applications and services, then the convenience for users is improved, but the security risk of unauthorized access to data increases
Solution Approach 1:
The patent segments the sensitive data stored on the NFC card into multiple distinct data sets, where each data set is associated with a specific provider or application. This segmentation allows the card to store diverse information (convenience) while enabling selective access control through provider-specific authentication, thereby mitigating unauthorized access risks.
2Adaptability or versatility
If an NFC initiator can access all data on a unified NFC card, then the functionality for service providers is improved, but the security against data leakage increases
Solution Approach 1:
The patent implements local quality by assigning different access permissions and authentication requirements to different data sets on the NFC card. Each provider can access only the specific data sets relevant to their service, with access granted through provider-specific authentication. This enables tailored functionality for each provider while preventing unauthorized access to unrelated data.
3Device complexity
If NFC card data is stored in a unified structure, then the simplicity of card architecture is improved, but the vulnerability to card cloning increases
Solution Approach 1:
The patent incorporates provider-specific authentication mechanisms and security protocols during the card initialization and data writing phases. Before data is written to the unified NFC card structure, provider credentials and access permissions are pre-configured. This preliminary security setup maintains architectural simplicity while preventing card cloning by ensuring that copied data cannot be accessed without valid provider authentication.
4Adaptability or versatility
If multiple providers can access the NFC card, then the versatility of the unified card system is improved, but the complexity of access management increases
Solution Approach 1:
The patent implements a universal authentication framework that handles multiple providers through a common interface and protocol structure. The NFC card maintains a unified data structure that can accommodate any number of providers, with access control managed through standardized provider-specific authentication mechanisms. This universal approach enables multi-provider support while avoiding the need for separate complex management systems for each provider.
Data Source
AI summary
One feature pertains to a near field communication (NFC) target device comprising a memory circuit adapted to store sensitive data, an NFC interface adapted to transmit and receive information using NFC protocols, and a processing circuit. The processing circuit receives a plurality of provider identification (PID) numbers from a plurality of providers, where each PID number is associated with a different provider. The processing circuit also stores the PID numbers at the memory circuit, and assigns a privilege mask to each PID number received and stored. The NFC target device may also include a physical unclonable function (PUF) circuit. The processing circuit may additionally provide one or more PID numbers as input challenges to the PUF circuit, and receive one or more PUF output responses from the PUF circuit, where the PUF output responses are different from one another and are associated with different providers.


