NFC Security Module Access Control via Request Origin Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile telecommunication devices equipped with near-field communication (NFC) modules are vulnerable to security breaches, particularly in transactions, due to the potential diversion of communication channels between the security module and the NFC router, allowing unauthorized access and fraudulent transactions.

Innovation Solution

Implementing a method where the security module verifies the origin of each request from the NFC router, allowing transactions only if they originate from a near-field communication source, and storing access rights in a non-volatile memory with a table correlating router gate identifiers and logical source identifiers to condition access rights based on the source.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the security module allows communication requests from the NFC router, then the device can perform near-field transactions, but the communication channel may be diverted allowing unauthorized access

Engineering Contradiction:
Improvetransaction capabilityVSAvoidcommunication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism where the security module checks the origin of each request against a whitelist of authorized logical sources. This intermediary step (verification process) mediates between the NFC router and the security module, allowing legitimate transactions while blocking diverted or unauthorized communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-configuring a whitelist of authorized logical sources in the security module before transactions occur. This preliminary setup establishes security rules in advance, enabling the security module to quickly verify request origins and prevent unauthorized access without affecting transaction performance.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the security module verifies the origin of each request, then unauthorized access is prevented, but the processing time and complexity increase

Engineering Contradiction:
Improveaccess control securityVSAvoidverification mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification mechanism uses a pre-configured whitelist of authorized logical sources stored in the security module. By establishing authorization rules in advance, the system avoids complex real-time analysis during transaction processing, reducing operational complexity while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the verification parameter from analyzing complex communication patterns to checking simple identifier matching against the whitelist. This parameter simplification (comparing logical source identifiers) reduces processing complexity and time while maintaining effective security control.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the security module restricts access to only near-field communication requests, then transaction security is improved, but the flexibility of the communication system is reduced

Engineering Contradiction:
Improvetransaction securityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by differentiating access rights for different logical sources. Instead of a blanket restriction, the security module selectively authorizes specific logical sources (including NFC router and other legitimate sources) while blocking others. This localized authorization approach maintains communication flexibility for authorized sources while ensuring security for transactions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The verification mechanism acts as an intermediary that intelligently routes requests based on their origin. It mediates between security requirements and communication flexibility by allowing authorized sources (NFC router, other whitelisted sources) to communicate freely while blocking unauthorized access, thus maintaining both security and flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9225687B2Access control mechanism for a secure element coupled to an NFC circuit
Publication Date: 2015.12.29 STMICROELECTRONICS (ROUSSET) SAS
  • US9225687B2 patent drawing
  • US9225687B2 patent drawing
  • US9225687B2 patent drawing

AI summary

A method for protecting a security module equipping a telecommunication device equipped with a near-field communication router, against an attempt of diversion of a communication channel between a gate of this security module and a gate of the router, wherein, for each request from the router to the security module, the module verifies the rights of access to the information that is contains according to the origin of the request.