NFC Router Security Pipe for Secure Transaction Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile telecommunication devices equipped with near-field communication (NFC) modules are vulnerable to security weaknesses that allow hacking of the security module, enabling unauthorized transactions by diverting communication pipes between the NFC router and the microcontroller.
Innovation Solution
Implementing a method where data transmission between the security module and NFC router is restricted to a reserved pipe or control signal that cannot be generated by the microcontroller, including a signature of the routing table and identifier of the communication pipe, to prevent unauthorized access and ensure secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the mobile telecommunication device is equipped with an NFC router to enable contactless communication functions, then the device can perform electronic purse, access control, and payment functions, but security weaknesses are introduced that allow hacking of the security module
Solution Approach 1:
The patent segments the communication channels into dedicated secure channels for NFC router-to-security-module communication and separate channels for microcontroller access. By creating isolated communication paths with distinct identifiers and routing tables, the system prevents unauthorized access while maintaining NFC functionality. The routing table is divided into secure entries (accessible only to router) and non-secure entries (accessible to microcontroller), resolving the contradiction between versatility and security.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of a dedicated pipe and control signal system between the NFC router and security module. This intermediary layer acts as a mediator that authenticates and validates communication requests, ensuring that only authorized routing changes can occur. The intermediary pipe with its own identifier and routing table entry prevents direct unauthorized access by the microcontroller to security-critical channels.
2Ease of operation
If the routing data between security module and NFC router is made accessible to the microcontroller for control purposes, then ease of operation is improved, but unauthorized diversion of communication pipes becomes possible
Solution Approach 1:
The patent applies local quality by creating different access rights for different parts of the routing system. The routing table is structured with local quality attributes that distinguish between secure routing entries (for NFC router communication) and general routing entries (for microcontroller control). This allows the microcontroller to control general routing while preventing it from diverting secure NFC communication pipes, thus maintaining ease of operation for legitimate control while blocking harmful diversion.
Solution Approach 2:
The patent implements preliminary anti-action by pre-configuring the routing table with secure entries that have restricted access rights. Before any unauthorized diversion can occur, the system has already established protective measures through dedicated pipes and identifiers that prevent the microcontroller from manipulating secure communication paths. This preliminary protective action blocks harmful factors before they can affect the system.
3Reliability
If a dedicated secure pipe is created for NFC router to security module communication, then transaction security is enhanced, but device complexity increases
Solution Approach 1:
The patent merges the secure pipe mechanism with the existing routing infrastructure by integrating the dedicated pipe into the router's routing table management system. The secure pipe shares the same routing table structure and communication protocols as existing channels, but with additional security attributes. This merging approach enhances transaction security while minimizing the increase in device complexity by reusing existing structural elements rather than creating entirely separate systems.
Data Source
AI summary
A method for protecting data contained in a security module of a telecommunication device equipped with a near-field communication router and with a microcontroller, wherein data relative to the routing between the security module and gates of the router assigned to near-field communications are transmitted over a channel accessible by the router only, or by a control signal which is not generated by the microcontroller for the router.


