Passive NFC Tag Secure Pairing Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing NFC-based secure pairing methods for host and accessory devices require an electrical connection between the processor and NFC tag, increasing costs and making it difficult to retrofit existing devices, and are vulnerable to Man-In-The-Middle attacks without additional security measures.
Innovation Solution
A method using a passive NFC tag with a private key not electrically coupled to the processor, where challenge requests and responses are computed using a one-way function with a shared secret value to authenticate devices without direct processor access, preventing tampering and Man-In-The-Middle attacks, and allowing secure pairing without physical changes to existing accessory devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an electrical connection is made between the processor and NFC tag for authentication, then device pairing security is improved, but device cost and complexity increase
Solution Approach 1:
The patent extracts the NFC tag from the electrical connection system, making it a standalone passive component that communicates wirelessly with the processor. This allows authentication to occur without requiring physical electrical connections between the processor and NFC tag, thereby maintaining security while reducing device complexity and cost.
Solution Approach 2:
The patent introduces a passive NFC tag as an intermediary component that mediates authentication between devices. The tag stores authentication data and communicates with the processor through wireless NFC signals rather than electrical connections, enabling secure authentication without direct electrical coupling.
2Reliability
If an electrical connection is made between the processor and NFC tag, then authentication functionality is improved, but ease of retrofitting existing devices deteriorates
Solution Approach 1:
By extracting the NFC tag from the electrical connection requirement, the patent enables the tag to be implemented as a separate, independently powerable component. This makes it feasible to retrofit existing devices by adding a passive NFC tag that can be powered and communicated with through wireless signals during pairing operations.
3Ease of operation
If standard NFC pairing is used without additional security measures, then ease of operation is improved, but vulnerability to Man-In-The-Middle attacks increases
Solution Approach 1:
The patent implements preliminary authentication actions during the device pairing process. Before establishing a full communication link, the system performs authentication by reading and verifying data from the passive NFC tag through wireless communication. This preliminary security check prevents Man-In-The-Middle attacks while maintaining operational simplicity for end users.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables secure, cost-effective, and retrofittable Out-of-Band authentication for NFC-based device pairing, preventing tampering and Man-In-The-Middle attacks by using a passive NFC tag with a private key and one-way function computations, ensuring secure communication links.
Implementation Method 1
a near field tag is a device designed to be read or written over an RF coupling that falls off rapidly over distance so that communication can occur only over short distance
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A methods and devices for secure pairing for devices with NFC tags equipped with authentication are provided. In one aspect a device with a passive near field communication tag including a private key for authentication is provided. The device may send a challenge request to a host device including an active NFC tag via a wireless communication protocol. The challenge request may be combined with a shared secret value known to the device and the host device to create a challenge request seed. The challenge request seed may be combined with the private key to compute a verified challenge request response. A challenge request response may be received from the host device via the wireless communication protocol. The challenge request response and verified challenge request response may be compared to authenticate the host device to the device.