NFC Tag Verification Using Dynamic One-Time Passwords

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identification and presence verification systems are vulnerable to data copying, physical manipulation, and alteration, lacking robustness in ensuring the authenticity of location and object verification.

Innovation Solution

A system utilizing an identification tag with an embedded integrated circuit for generating one-time-passwords and a Near Field Communication (NFC) sub-system, combined with a Global Navigation Satellite System (GNSS) and network connection, verifies the unique identifier, location, and time stamp through a server, preventing unauthorized use and manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If location beacons emit data unique to their location for verification, then identification and presence verification is enabled, but the system becomes vulnerable to data copying and manipulation

Engineering Contradiction:
Improveverification reliabilityVSAvoiddata copying and manipulation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the parameter of verification data from static location-based data to dynamic time-based one-time passwords (OTPs). Each beacon generates a unique OTP that changes with time, making copied data invalid for verification. This resolves the contradiction by maintaining verification reliability while preventing data copying attacks.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic elements to the verification system by implementing time-varying OTPs that are valid only for specific time windows. The verification process becomes dynamic rather than static, where the validity of verification data depends on temporal parameters. This prevents manipulation by ensuring that even if data is copied, it cannot be reused outside its valid time window.

Inventive Principle:
Principle #15Dynamics

2Productivity

If location beacons are physically moved to reduce travel distance, then verification efficiency improves, but the system becomes vulnerable to unauthorized relocation

Engineering Contradiction:
Improveverification efficiencyVSAvoidunauthorized relocation
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where beacons continuously verify their authorized location against a central database before generating OTPs. The system provides feedback to the beacon about its verification status, and only beacons with valid location authorization can generate verification codes. This prevents unauthorized relocation while maintaining verification efficiency through automated location validation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary location verification before allowing a beacon to generate verification data. The system pre-authorizes beacon locations and stores this information in a database. Before a beacon can be used for verification, it must first prove it is at an authorized location, preventing unauthorized relocation attempts.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If identification tags store unique identifiers and location data, then verification capability is provided, but security against theft and unauthorized use is compromised

Engineering Contradiction:
Improveverification capabilityVSAvoidtheft and unauthorized use
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent changes the verification parameter from static stored data to dynamically generated OTPs that depend on time, location, and beacon identity. The identification tag stores minimal static data (beacon ID) while the verification data is generated on-demand based on multiple parameters. This maintains ease of operation while preventing theft because stolen tags cannot generate valid OTPs without the proper time, location, and authorization parameters.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the verification system into multiple independent components: beacon identification, location verification, time synchronization, and OTP generation. Each component operates independently and contributes to the final verification. This segmentation prevents unauthorized use because compromising one component (e.g., stealing a tag) does not provide access to the other security-critical components like time synchronization and location verification.

Inventive Principle:
Principle #1Segmentation

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enhances the security and authenticity of identification and presence verification by preventing data theft, copying, and alteration, ensuring the actual location of the tag is verified, thus reducing opportunities for unauthorized access.

Implementation Method 1

a Near Field Communication (NFC) sub-system that reads data from the identification tag using radio frequency signals

Methodology Applied
Scientific EffectNear Field Communication (NFC): Electromagnetic Induction

Implementation Method 2

a global navigation satellite system (GNSS) sub-system; reading a current geographical location from the GNSS sub-system

Methodology Applied
Scientific EffectGlobal Navigation Satellite System (GNSS): Time of Flight

Data Source

PatentUS10462128B2Verification of both identification and presence of objects over a network
Publication Date: 2019.10.29 MYTAG LTD
  • US10462128B2 patent drawing
  • US10462128B2 patent drawing
  • US10462128B2 patent drawing

AI summary

A method and system for verifying both identification and presence of an object is provided. The system includes an identification tag containing data associated with an object, a reader for reading said data from the identification tag, communicating data received from the identification tag to the server, and a server configured for receiving the data sent by the reader, accessing an object record that corresponds to the object, determining whether the data it received is verified against data in the object record, and if said data is verified, then generating a URL and transmitting said URL to the reader over the communications network, wherein said URL includes a verification message.