NFC Tag Authentication via Secondary Device Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for NFC devices lack a seamless way to authenticate to remote servers when the primary device does not have or is not associated with an NFC tag, especially in scenarios where direct NFC connections are not feasible.

Innovation Solution

An apparatus comprising NFC interface circuitry, memory, and a processor that establishes an NFC connection with an NFC tag, derives a cryptographic value from a shared secret, and presents it to a secondary device for authentication to a remote server, allowing the secondary device to display or transmit this value to the primary device for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct NFC connection is used for authentication, then authentication security is improved, but device compatibility and ease of operation deteriorate when primary device lacks NFC tag

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a secondary device as an intermediary that bridges the primary device and NFC tag. The secondary device establishes NFC connection with the tag, derives cryptographic values, and transmits them to the primary device, enabling authentication without requiring direct NFC capability between primary device and tag

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct functional components: NFC interface circuitry for establishing connections, processor for deriving cryptographic values from shared secrets, and communication interface for transmitting authentication data. This segmentation allows each component to be optimized independently and enables flexible deployment scenarios

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If NFC tag is integrated into primary device, then authentication convenience is improved, but security risks increase when direct connection is always available

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The secondary device serves as a trusted intermediary that mediates between the primary device and NFC tag. It establishes the NFC connection, performs cryptographic operations, and controls information flow, thereby maintaining security while enabling convenient authentication scenarios where direct integration would be risky

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If cryptographic operations are performed on primary device, then authentication speed is improved, but device complexity increases for devices without NFC capability

Engineering Contradiction:
Improveauthentication speedVSAvoiddevice architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The secondary device acts as a cryptographic processing intermediary that performs all complex cryptographic operations including establishing NFC connections, deriving shared secrets, and generating authentication values. The primary device only needs to receive and transmit these values, significantly reducing its complexity requirements while maintaining authentication speed

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9379894B1Authentication using cryptographic value derived from a shared secret of a near field communication tag
Publication Date: 2016.06.28 RSA SECURITY USA LLC
  • US9379894B1 patent drawing
  • US9379894B1 patent drawing
  • US9379894B1 patent drawing

AI summary

An apparatus comprises a first processing device comprising near field communication (NFC) interface circuitry, a memory and a processor coupled to the memory. The first processing device is configured to establish an NFC connection with an NFC tag using the NFC interface circuitry, receive a shared secret established between the NFC tag and an authentication server in an authentication protocol, and present a cryptographic value derived from the shared secret to a second processing device. The cryptographic value is utilizable by the second processing device for authenticating to the authentication server.