NFC Router Security Pipe for Secure Transaction Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile telecommunication devices equipped with near-field communication (NFC) modules are vulnerable to security weaknesses that allow hacking of the security module, enabling unauthorized transactions by diverting communication pipes between the NFC router and the microcontroller.

Innovation Solution

Implementing a method where data transmission between the security module and NFC router is restricted to a reserved pipe or control signal that cannot be generated by the microcontroller, including a signature of the routing table and identifier of the communication pipe, to prevent unauthorized access and ensure secure transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the mobile telecommunication device is equipped with an NFC router to enable contactless communication functions, then the device can perform electronic purse, access control, and payment functions, but security weaknesses are introduced that allow hacking of the security module

Engineering Contradiction:
Improvecontactless communication functionalityVSAvoidsecurity against hacking
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the communication channels into dedicated secure channels for NFC router-to-security-module communication and separate channels for microcontroller access. By creating isolated communication paths with distinct identifiers and routing tables, the system prevents unauthorized access while maintaining NFC functionality. The routing table is divided into secure entries (accessible only to router) and non-secure entries (accessible to microcontroller), resolving the contradiction between versatility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a dedicated pipe and control signal system between the NFC router and security module. This intermediary layer acts as a mediator that authenticates and validates communication requests, ensuring that only authorized routing changes can occur. The intermediary pipe with its own identifier and routing table entry prevents direct unauthorized access by the microcontroller to security-critical channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the routing data between security module and NFC router is made accessible to the microcontroller for control purposes, then ease of operation is improved, but unauthorized diversion of communication pipes becomes possible

Engineering Contradiction:
Improvemicrocontroller control capabilityVSAvoidunauthorized pipe diversion
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by creating different access rights for different parts of the routing system. The routing table is structured with local quality attributes that distinguish between secure routing entries (for NFC router communication) and general routing entries (for microcontroller control). This allows the microcontroller to control general routing while preventing it from diverting secure NFC communication pipes, thus maintaining ease of operation for legitimate control while blocking harmful diversion.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary anti-action by pre-configuring the routing table with secure entries that have restricted access rights. Before any unauthorized diversion can occur, the system has already established protective measures through dedicated pipes and identifiers that prevent the microcontroller from manipulating secure communication paths. This preliminary protective action blocks harmful factors before they can affect the system.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If a dedicated secure pipe is created for NFC router to security module communication, then transaction security is enhanced, but device complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidcommunication channel structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the secure pipe mechanism with the existing routing infrastructure by integrating the dedicated pipe into the router's routing table management system. The secure pipe shares the same routing table structure and communication protocols as existing channels, but with additional security attributes. This merging approach enhances transaction security while minimizing the increase in device complexity by reusing existing structural elements rather than creating entirely separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9179301B2Protection of a communication channel of a telecommunication device coupled to an NFC circuit against misrouting
Publication Date: 2015.11.03 STMICROELECTRONICS BELGIUM
  • US9179301B2 patent drawing
  • US9179301B2 patent drawing
  • US9179301B2 patent drawing

AI summary

A method for protecting data contained in a security module of a telecommunication device equipped with a near-field communication router and with a microcontroller, wherein data relative to the routing between the security module and gates of the router assigned to near-field communications are transmitted over a channel accessible by the router only, or by a control signal which is not generated by the microcontroller for the router.