NFC Router Filtering for Secure Transaction Pipes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile telecommunication devices equipped with near-field communication (NFC) modules face security vulnerabilities, particularly in the diversion of communication pipes between the security module and the NFC router, which can lead to unauthorized transactions and hacking attempts.
Innovation Solution
Implementing a filtering mechanism within the NFC router that compares message instruction codes and formats against authorized codes and formats, using a table to determine authorization or denial for each type of control signal, thereby intercepting and blocking unauthorized messages and preventing pipe diversion attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an NFC router is integrated into a mobile telecommunication device to enable contactless communication functions, then the device gains enhanced features such as electronic purse and access control capabilities, but security vulnerabilities arise that allow unauthorized diversion of communication pipes between the security module and NFC router
Solution Approach 1:
The patent introduces an intermediary filtering mechanism positioned between the NFC router and security module. This intermediary layer inspects communication pipes and filters messages based on authorized formats and codes, preventing unauthorized diversion attempts while allowing legitimate contactless transactions to proceed. The intermediary acts as a security gatekeeper that maintains both versatility and reliability.
2Reliability
If the NFC router filters messages addressed to the security module to prevent unauthorized access, then transaction security is improved, but the device complexity increases due to the additional filtering mechanism
Solution Approach 1:
The patent segments the security function into a separate filtering mechanism that operates independently within the NFC router. By dividing the message filtering task into distinct authorized formats and codes defined in a table, the system achieves enhanced security without requiring complete redesign of the entire NFC subsystem. This segmentation allows the filtering mechanism to be implemented as a modular addition.
3Reliability
If the router compares instruction codes with authorized codes to detect hacking attempts, then security against hacking is improved, but the processing time and operational complexity increase
Solution Approach 1:
The patent implements preliminary action by pre-defining all authorized instruction codes and message formats in a lookup table before runtime. During operation, the filtering mechanism simply compares incoming message codes against this pre-established table rather than performing complex real-time analysis. This approach provides strong hacking protection while maintaining fast processing speeds and operational simplicity.
Data Source
AI summary
A method and associated circuits protect data stored in a secure data circuit of a telecommunication device equipped with a near-field communication (NFC) router, a microcontroller, and the secure data circuit. In the method, each message received with the NFC router is parsed to retrieve a communication pipe identifier and an instruction code. The communication pipe identifier and the instruction code are compared to corresponding information in a filter table. Instruction codes of particular messages that attempt to modify a communication pipe by reassigning one end of the communication pipe from the port of the NFC router to a different circuit are acted upon. These messages are blocked from reaching the secure data circuit when the instruction code is not authorized in the filter table, and these messages are permitted when the instruction code is authorized in the filter table.


