NFC Security Token with Smart Card Applet for Mobile Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
NFC-enabled security tokens face challenges in security, ease-of-use, and multi-application support, particularly on mobile devices where they are not as secure as traditional methods and require inconvenient manual interaction for code entry and lack support for multiple applications.
Innovation Solution
An NFC-enabled security token with a contactless smart card IC, a built-in clock, and a smart card applet that uses NDEF messages for cryptographic challenge-response protocols, allowing PIN-based access and supporting multiple credentials, while leveraging the mobile device's user interface for ease-of-use and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a security token is implemented as software on a mobile device, then ease of operation is improved, but security deteriorates because the mobile device cannot be trusted per se
Solution Approach 1:
The security token functionality is segmented into two parts: a trusted hardware security element embedded in the mobile device (providing security) and a software application layer (providing ease of operation). The security element is a separate, trusted component that cannot be compromised by the mobile device's operating system or other software.
Solution Approach 2:
A trusted security element acts as an intermediary between the mobile device's software interface and the authentication server. This intermediary provides a secure channel for cryptographic operations while the mobile device's display and input interfaces provide user-friendly operation. The security element mediates the authentication process, ensuring security while allowing ease of use through the device's native interfaces.
2Reliability
If manual code entry is required for authentication, then security is improved by user verification, but ease of operation deteriorates due to inconvenient manual interaction
Solution Approach 1:
The security token automatically performs cryptographic operations and generates authentication codes without requiring manual user interaction for code entry. The mobile device's display and input interfaces are used automatically by the application, eliminating the need for users to manually transcribe codes while maintaining security through the trusted hardware element.
3Reliability
If a traditional security token is used with desktop PC, then security is improved through direct connection, but ease of operation deteriorates when accessing services on mobile devices
Solution Approach 1:
The security token is designed with universal functionality to work with both desktop PCs and mobile devices. The trusted security element can perform cryptographic operations through multiple communication interfaces (USB, Bluetooth, NFC, or other wireless protocols), allowing the same device to provide secure authentication across different platforms and device types without sacrificing security or requiring manual code entry.
4Ease of operation
If Bluetooth is used for communication between security token and mobile device, then ease of operation is improved by wireless connection, but reliability deteriorates because Bluetooth is not designed for security tokens
Solution Approach 1:
The trusted security element acts as an intermediary that provides secure cryptographic operations over wireless communication channels. While Bluetooth or other wireless protocols provide ease of operation for communication, all security-critical operations are performed within the protected environment of the security element, which validates and secures the communication process.
Data Source
Figure 1~2
Figure 3
AI summary
According to an aspect of the invention, a security token for facilitating access to a remote computing service via a mobile device is conceived, said security token comprising an NFC interface, a smart card integrated circuit and a smart card applet stored in and executable by said smart card integrated circuit, wherein the smart card applet is arranged to support a cryptographic challenge-response protocol executable by the mobile device.