Removable NFC Security Token for Mobile Transaction Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile NFC transactions raise security, privacy, and accessibility concerns as users must hand over their devices to perform transactions, especially with sensitive information at risk.

Innovation Solution

An NFC-enabled security token removably coupled to a mobile device, equipped with a transceiver, memory, and logic for secure transaction management, allowing users to control transactions with restrictions such as payment limits, timeouts, and location-based restrictions, and featuring self-destruct mechanisms for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users hand over their mobile device to perform NFC transactions, then transaction convenience is improved, but security and privacy are worsened

Engineering Contradiction:
Improvetransaction convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the transaction functionality from the main mobile device by using a separate NFC token or card that contains only the necessary transaction credentials. This allows the transaction function to be separated from the device containing sensitive personal information, enabling users to hand over just the token rather than the entire mobile device, thus improving security while maintaining transaction convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the NFC transaction capability into a standalone token or card that can be independently used for transactions. By taking out the transaction function from the main mobile device, users can perform transactions without exposing their personal information stored on the device, thereby reducing security risks while maintaining ease of operation.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If users hand over their mobile device to perform NFC transactions, then transaction convenience is improved, but privacy protection is worsened

Engineering Contradiction:
Improvetransaction convenienceVSAvoidprivacy exposure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments personal information from transaction information by storing only essential transaction credentials on the NFC token or card, while keeping detailed personal information on the secure server. This segmentation allows users to perform transactions without exposing their private information, maintaining privacy while enabling convenient transactions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts only the necessary transaction credentials from the mobile device and places them on a separate NFC token or card. This extraction ensures that when the device is handed over for transactions, no sensitive personal information is exposed, thereby protecting privacy while maintaining transaction convenience.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If mobile device is separated from user for transactions, then transaction flexibility is improved, but control over sensitive information is worsened

Engineering Contradiction:
Improvetransaction flexibilityVSAvoidinformation control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the mobile device communicates with the NFC token or card to verify transaction parameters, confirm authorization, and receive transaction status updates. This feedback loop ensures that even when the device is separated for transactions, the user maintains control through real-time verification and confirmation processes, balancing flexibility with information control.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent employs preliminary actions by pre-configuring transaction parameters, authorization levels, and restrictions on the mobile device before separation. The device prepares and transmits control instructions to the NFC token or card in advance, ensuring that transactions are conducted within predefined security boundaries, thus maintaining control over sensitive information while enabling transaction flexibility.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances user control and security in NFC transactions by allowing secure, remote authentication and transaction management while protecting sensitive information, reducing risks associated with handing over devices.

Implementation Method 1

NFC-enabled security tokens that may be removably coupled to a mobile device

Methodology Applied
Scientific EffectNear Field Communication (NFC): Electromagnetic Induction

Data Source

PatentUS8818867B2Security token for mobile near field communication transactions
Publication Date: 2014.08.26 AT&T INTELLECTUAL PROPERTY I L P
  • US8818867B2 patent drawing
  • US8818867B2 patent drawing
  • US8818867B2 patent drawing

AI summary

Devices, systems, and methods are disclosed which relate to an NFC-enabled security token that is removably coupled to a mobile device. The security token may be provisioned with the information by the mobile device, then decoupled from the mobile device and used to authenticate the user or perform a transaction at a POS terminal equipped with an NFC reader. The security token includes logic for user-controlled restrictions on allowable purchases, such as payment limits, timeouts, vendor identifiers, allowed purchases, and location-based restrictions. The security token is further equipped with “self destruct” security features, such as deactivating itself or erasing any sensitive information upon being unable to contact the mobile device for a specified duration, or being subject to an unauthorized or restricted transaction, until such time as it is re-coupled to the mobile device.