NFC Security Module Access Control via Request Origin Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile telecommunication devices equipped with near-field communication (NFC) modules are vulnerable to security breaches, particularly in transactions, due to the potential diversion of communication channels between the security module and the NFC router, allowing unauthorized access and fraudulent transactions.
Innovation Solution
Implementing a method where the security module verifies the origin of each request from the NFC router, allowing transactions only if they originate from a near-field communication source, and storing access rights in a non-volatile memory with a table correlating router gate identifiers and logical source identifiers to condition access rights based on the source.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the security module allows communication requests from the NFC router, then the device can perform near-field transactions, but the communication channel may be diverted allowing unauthorized access
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the security module checks the origin of each request against a whitelist of authorized logical sources. This intermediary step (verification process) mediates between the NFC router and the security module, allowing legitimate transactions while blocking diverted or unauthorized communication channels.
Solution Approach 2:
The patent implements preliminary action by pre-configuring a whitelist of authorized logical sources in the security module before transactions occur. This preliminary setup establishes security rules in advance, enabling the security module to quickly verify request origins and prevent unauthorized access without affecting transaction performance.
2Reliability
If the security module verifies the origin of each request, then unauthorized access is prevented, but the processing time and complexity increase
Solution Approach 1:
The verification mechanism uses a pre-configured whitelist of authorized logical sources stored in the security module. By establishing authorization rules in advance, the system avoids complex real-time analysis during transaction processing, reducing operational complexity while maintaining high security standards.
Solution Approach 2:
The patent changes the verification parameter from analyzing complex communication patterns to checking simple identifier matching against the whitelist. This parameter simplification (comparing logical source identifiers) reduces processing complexity and time while maintaining effective security control.
3Reliability
If the security module restricts access to only near-field communication requests, then transaction security is improved, but the flexibility of the communication system is reduced
Solution Approach 1:
The patent applies local quality by differentiating access rights for different logical sources. Instead of a blanket restriction, the security module selectively authorizes specific logical sources (including NFC router and other legitimate sources) while blocking others. This localized authorization approach maintains communication flexibility for authorized sources while ensuring security for transactions.
Solution Approach 2:
The verification mechanism acts as an intermediary that intelligently routes requests based on their origin. It mediates between security requirements and communication flexibility by allowing authorized sources (NFC router, other whitelisted sources) to communicate freely while blocking unauthorized access, thus maintaining both security and flexibility.
Data Source
AI summary
A method for protecting a security module equipping a telecommunication device equipped with a near-field communication router, against an attempt of diversion of a communication channel between a gate of this security module and a gate of the router, wherein, for each request from the router to the security module, the module verifies the rights of access to the information that is contains according to the origin of the request.


