NFC Router Pipe Identifier Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile telecommunication devices equipped with near field communication (NFC) modules are vulnerable to piracy attempts due to weak security points in their transaction processes, particularly in the communication between the NFC router and the security module, which can lead to unauthorized transactions.

Innovation Solution

A method is implemented to enhance security by using a pipe identifier calculated based on the radio frequency gate identifier, where the pipe identifier is linked to the RF gate identifier through an injective function, and verified by the security module before data transmission, ensuring that data are only sent to the correct radio frequency gate, thereby preventing diversion of communication pipes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If NFC router shares communication pipes with multiple applications and security modules, then communication efficiency and versatility are improved, but security vulnerabilities increase due to potential pipe diversion attacks

Engineering Contradiction:
Improvecommunication versatilityVSAvoidtransaction security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security module verifies the pipe identifier against the RF gate identifier before allowing data transmission, creating a feedback mechanism that detects and prevents pipe diversion attacks. This verification step ensures that data flows only through authorized communication paths while maintaining the router's ability to handle multiple applications.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces a pipe identifier parameter that is calculated as a function of the RF gate identifier. This parameter change enables the system to distinguish between legitimate and diverted communication pipes, allowing the router to maintain versatility while the security module ensures reliability through parameter verification.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If the router uses a shared communication interface for multiple purposes, then device complexity is reduced, but security detection capability deteriorates

Engineering Contradiction:
Improverouter structureVSAvoidpiracy detection
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The pipe identifier is pre-calculated based on the RF gate identifier and stored in the routing table before communication occurs. This preliminary action enables the security module to verify communication integrity without adding complex real-time detection mechanisms, maintaining simple router structure while improving piracy detection capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9185561B2Protection against rerouting in an NFC circuit communication channel
Publication Date: 2015.11.10 STMICROELECTRONICS BELGIUM
  • US9185561B2 patent drawing
  • US9185561B2 patent drawing
  • US9185561B2 patent drawing

AI summary

A method for protecting information contained in a security module of a telecommunication device provided with a near-field communication router, wherein a routing table between the ports of the router contains at least one channel identifier calculated from an identifier of a radiofrequency port of a near-field communication circuit associated with the router.