NFC Security Token with Smart Card Applet for Mobile Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

NFC-enabled security tokens face challenges in security, ease-of-use, and multi-application support, particularly on mobile devices where they are not as secure as traditional methods and require inconvenient manual interaction for code entry and lack support for multiple applications.

Innovation Solution

An NFC-enabled security token with a contactless smart card IC, a built-in clock, and a smart card applet that uses NDEF messages for cryptographic challenge-response protocols, allowing PIN-based access and supporting multiple credentials, while leveraging the mobile device's user interface for ease-of-use and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a security token is implemented as software on a mobile device, then ease of operation is improved, but security deteriorates because the mobile device cannot be trusted per se

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The security token functionality is segmented into two parts: a trusted hardware security element embedded in the mobile device (providing security) and a software application layer (providing ease of operation). The security element is a separate, trusted component that cannot be compromised by the mobile device's operating system or other software.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted security element acts as an intermediary between the mobile device's software interface and the authentication server. This intermediary provides a secure channel for cryptographic operations while the mobile device's display and input interfaces provide user-friendly operation. The security element mediates the authentication process, ensuring security while allowing ease of use through the device's native interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual code entry is required for authentication, then security is improved by user verification, but ease of operation deteriorates due to inconvenient manual interaction

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security token automatically performs cryptographic operations and generates authentication codes without requiring manual user interaction for code entry. The mobile device's display and input interfaces are used automatically by the application, eliminating the need for users to manually transcribe codes while maintaining security through the trusted hardware element.

Inventive Principle:
Principle #25Self-service

3Reliability

If a traditional security token is used with desktop PC, then security is improved through direct connection, but ease of operation deteriorates when accessing services on mobile devices

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security token is designed with universal functionality to work with both desktop PCs and mobile devices. The trusted security element can perform cryptographic operations through multiple communication interfaces (USB, Bluetooth, NFC, or other wireless protocols), allowing the same device to provide secure authentication across different platforms and device types without sacrificing security or requiring manual code entry.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If Bluetooth is used for communication between security token and mobile device, then ease of operation is improved by wireless connection, but reliability deteriorates because Bluetooth is not designed for security tokens

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The trusted security element acts as an intermediary that provides secure cryptographic operations over wireless communication channels. While Bluetooth or other wireless protocols provide ease of operation for communication, all security-critical operations are performed within the protected environment of the security element, which validates and secures the communication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2763370B1Security token and service access system
Publication Date: 2016.12.21 NXP BV
  • EP2763370B1 patent drawingFigure 1~2
  • EP2763370B1 patent drawingFigure 3

AI summary

According to an aspect of the invention, a security token for facilitating access to a remote computing service via a mobile device is conceived, said security token comprising an NFC interface, a smart card integrated circuit and a smart card applet stored in and executable by said smart card integrated circuit, wherein the smart card applet is arranged to support a cryptographic challenge-response protocol executable by the mobile device.