NFC Router Pipe Diversion Detection via Microcontroller Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices equipped with near field communication (NFC) modules are vulnerable to piracy attempts due to the risk of diverting communication pipes between the security module and the NFC router, which can lead to unauthorized transactions and security breaches.

Innovation Solution

Implementing a method to detect and prevent piracy attempts by monitoring the activity of peripherals connected to the NFC router and verifying the existence and integrity of communication pipes between the security module and the NFC router, using a microcontroller to ensure that messages originate from authorized gates and employing signature verification to secure transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a mobile device is equipped with an NFC router to enable contactless card emulation, then the device gains enhanced functionality for transactions and access control, but security vulnerabilities arise due to potential piracy attempts and unauthorized diversion of communication pipes

Engineering Contradiction:
Improvecontactless card emulation functionalityVSAvoidtransaction security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the security module verifies the origin of each received message by checking communication pipe identifiers. The system continuously monitors and validates the communication path, providing real-time feedback to detect and prevent unauthorized pipe diversion attempts, thus maintaining security while enabling NFC functionality

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary verification layer between the NFC router and the security module. The microcontroller acts as a mediator that validates communication pipes before allowing data transmission, preventing direct unauthorized access while maintaining the necessary communication channels for legitimate transactions

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the security module verifies the origin of each received message to detect piracy attempts, then transaction security is enhanced, but the complexity of the communication protocol increases

Engineering Contradiction:
Improvetransaction securityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial verification by checking only critical message attributes (communication pipe identifiers) rather than performing exhaustive validation of all message components. This selective verification approach provides adequate security against pipe diversion while minimizing the increase in protocol complexity and processing overhead

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If communication pipes are monitored and verified to prevent diversion, then unauthorized access is prevented, but transaction processing time increases due to additional verification steps

Engineering Contradiction:
Improvesecurity against piracyVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary verification of communication pipes during the initial connection phase between the NFC router and security module. By validating the communication path beforehand and establishing trusted channels in advance, the system reduces the need for repeated verification during transactions, thus maintaining security while minimizing processing time delays

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11963004B2Detection of a rerouting of a communication channel of a telecommunication device connected to an NFC circuit
Publication Date: 2024.04.16 STMICROELECTRONICS BELGIUM
  • US11963004B2 patent drawing
  • US11963004B2 patent drawing
  • US11963004B2 patent drawing

AI summary

A near field communication (NFC) router of a telecommunication device has communication pipes between gates of the NFC router. The pipes include a set of communication pipes to implement NFC transactions, which are coupled between radio-frequency gates of the NFC router and physical gates of the NFC router assigned to a security circuit. An attempt to use a pipe, other than one of the set, to implement an NFC transaction is detected by, in response to receiving a message in a NFC communication format via a pipe, comparing bits associated with the pipe with stored bits associated with the set of communication pipes. In response to the comparing indicating the pipe is not one of the set of communication pipes, implementation of the NFC transaction is blocked.