NFC Service Operation Management Using Localized Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security and authorization techniques for electronic devices are complex, costly, and inadequate for enabling sensitive service operations, often relying on external tools and backend infrastructure, which can compromise security and incur legal risks, especially during device manufacturing and research and development phases.
Innovation Solution
The use of near-field communication (NFC) techniques for authorizing service operations, allowing for context-aware and automated transfer of credentials and commands between NFC endpoints, eliminating the need for backend infrastructure and reducing reliance on non-volatile storage, thereby enhancing security and simplifying the infrastructure and steps involved in controlling service operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If complex external tools and infrastructure are used to enable service operations, then service operations can be enabled, but device complexity and cost increase
Solution Approach 1:
The patent extracts the authorization data from external backend infrastructure and stores it directly in local storage on the device. This eliminates the need for complex external authorization systems while maintaining service operation enablement capabilities.
Solution Approach 2:
The device performs self-authorization by using locally stored authorization data to enable service operations without requiring continuous connection to external authorization servers. The device autonomously verifies and enables operations based on pre-stored credentials.
2Ease of operation
If service operations are always enabled on consumer devices, then service operations are accessible, but security is compromised
Solution Approach 1:
Authorization data is pre-configured and stored in local storage before the device is put into service. This preliminary action enables fast authentication and service operation enablement without requiring real-time backend verification, while maintaining security through pre-validated credentials.
Solution Approach 2:
The patent implements location-specific authorization by storing device-specific authorization data in local storage. Each device has its own localized authorization credentials, allowing secure service operation enablement without exposing security mechanisms to external systems.
3Reliability
If backend infrastructure is used for authorization, then authorization can be verified, but cost and infrastructure complexity increase
Solution Approach 1:
The patent extracts the authorization verification function from external backend infrastructure and implements it locally on the device. The authorization data is stored in local storage and verified device-side, eliminating dependency on complex backend systems.
Solution Approach 2:
The device receives and stores a copy of the authorization data from the backend system during initial setup. This copy enables independent verification of service operations without requiring continuous connection to the original authorization server.
4Duration of action of stationary object
If authorization data is stored in non-volatile storage, then authorization is persistent, but security risk increases
Solution Approach 1:
The authorization data is discarded from local storage after being used to enable service operations. The system recovers the authorization purpose by enabling the operations without retaining the sensitive credentials, thus maintaining persistence while reducing security risk.
Solution Approach 2:
The patent treats authorization data as disposable - it is stored temporarily in local storage just long enough to enable service operations, then discarded. This approach uses inexpensive, short-lived storage to maintain authorization persistence without creating long-term security vulnerabilities.
Data Source
AI summary
Various techniques for the management and control of service operations using near-field communication (NFC) technologies are disclosed. In an example, a master computing system operates to identify a device configuration that enables a service operation upon a remote client device, identify an authentication value to authenticate permission to enable the service operation with the remote client device, and generate an NFC data payload including the authentication value and device configuration. This data payload is then provided to a client computing device that operates an NFC reader. In response, the client computing device processes and authenticates the payload, and enables the indicated service operation(s) within the client computing device. Further examples to conduct the NFC data transaction and perform the service operation(s) using active and passive NFC tags are also disclosed.


