NFC Router Filtering for Secure Transaction Pipes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile telecommunication devices equipped with near-field communication (NFC) modules face security vulnerabilities, particularly in the diversion of communication pipes between the security module and the NFC router, which can lead to unauthorized transactions and hacking attempts.

Innovation Solution

Implementing a filtering mechanism within the NFC router that compares message instruction codes and formats against authorized codes and formats, using a table to determine authorization or denial for each type of control signal, thereby intercepting and blocking unauthorized messages and preventing pipe diversion attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an NFC router is integrated into a mobile telecommunication device to enable contactless communication functions, then the device gains enhanced features such as electronic purse and access control capabilities, but security vulnerabilities arise that allow unauthorized diversion of communication pipes between the security module and NFC router

Engineering Contradiction:
Improvecontactless communication functionsVSAvoidtransaction security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary filtering mechanism positioned between the NFC router and security module. This intermediary layer inspects communication pipes and filters messages based on authorized formats and codes, preventing unauthorized diversion attempts while allowing legitimate contactless transactions to proceed. The intermediary acts as a security gatekeeper that maintains both versatility and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the NFC router filters messages addressed to the security module to prevent unauthorized access, then transaction security is improved, but the device complexity increases due to the additional filtering mechanism

Engineering Contradiction:
Improvetransaction securityVSAvoidfiltering mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security function into a separate filtering mechanism that operates independently within the NFC router. By dividing the message filtering task into distinct authorized formats and codes defined in a table, the system achieves enhanced security without requiring complete redesign of the entire NFC subsystem. This segmentation allows the filtering mechanism to be implemented as a modular addition.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the router compares instruction codes with authorized codes to detect hacking attempts, then security against hacking is improved, but the processing time and operational complexity increase

Engineering Contradiction:
Improvehacking protectionVSAvoidmessage processing simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-defining all authorized instruction codes and message formats in a lookup table before runtime. During operation, the filtering mechanism simply compares incoming message codes against this pre-established table rather than performing complex real-time analysis. This approach provides strong hacking protection while maintaining fast processing speeds and operational simplicity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11962616B2Protection against rerouting a communication channel of a telecommunication device having an NFC circuit and a secure data circuit
Publication Date: 2024.04.16 STMICROELECTRONICS BELGIUM
  • US11962616B2 patent drawing
  • US11962616B2 patent drawing
  • US11962616B2 patent drawing

AI summary

A method and associated circuits protect data stored in a secure data circuit of a telecommunication device equipped with a near-field communication (NFC) router, a microcontroller, and the secure data circuit. In the method, each message received with the NFC router is parsed to retrieve a communication pipe identifier and an instruction code. The communication pipe identifier and the instruction code are compared to corresponding information in a filter table. Instruction codes of particular messages that attempt to modify a communication pipe by reassigning one end of the communication pipe from the port of the NFC router to a different circuit are acted upon. These messages are blocked from reaching the secure data circuit when the instruction code is not authorized in the filter table, and these messages are permitted when the instruction code is authorized in the filter table.