Network-Based Remote Control for Contactless Secure Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current contactless smart card technologies face challenges in remote management and security, particularly in verifying the validity of information and preventing unauthorized use, especially in applications like micro-payments and identification, where online verification is costly and risks are high.

Innovation Solution

A terminal device with a secure storage subsystem and interconnectivity component that enables network-based remote control over contactless smartcards, allowing messages to be processed by a secure memory controller for secure storage and communication, ensuring secure data exchange and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If online validity verification is performed for contactless smart card transactions, then security and authenticity are improved, but transaction costs increase significantly

Engineering Contradiction:
Improvevalidity verificationVSAvoidtransaction cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system performs preliminary validity verification and authentication during card issuance and initial setup phases. Validity information is pre-configured in the contactless smart card and reader device, eliminating the need for continuous online verification during transactions. This preliminary action ensures security while reducing operational costs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation mechanism where a cryptographic signature or security element embedded in the smart card serves as a trusted intermediary. This intermediary contains pre-validated security credentials that allow the reader to verify authenticity locally without contacting the service provider's server, thus maintaining security while avoiding online verification costs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If contactless smart chip technology is integrated into mobile computing devices, then convenience and usability are improved, but security risks from loss or unauthorized use increase

Engineering Contradiction:
ImproveconvenienceVSAvoidunauthorized use
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments security control into multiple independent components: the contactless smart card contains security credentials, the reader device contains validation logic, and the mobile computing device provides an additional authentication layer. This segmentation ensures that loss of one component does not compromise the entire system, as each segment can independently control access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary security setup by embedding cryptographic keys and security policies in the smart card before issuance. Additionally, the system requires preliminary authentication through the mobile device's security credentials (such as biometric verification or device PIN) before enabling contactless transactions, preventing unauthorized use even if the physical card is lost.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If remote control capability is added to secure storage subsystem, then management flexibility is improved, but system complexity increases

Engineering Contradiction:
Improveremote managementVSAvoidsystem architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a message intermediary component that handles all remote control communications. This intermediary receives control messages from external systems, validates them against security policies stored in the secure storage subsystem, and executes approved commands. This intermediary layer provides remote management capability while isolating the complex validation logic from both the user interface and the core storage operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The secure storage subsystem performs self-validation of remote control messages using pre-configured security credentials and policies stored within its own memory. The subsystem autonomously determines whether to execute received commands based on embedded security rules, eliminating the need for continuous external validation infrastructure and reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables active and passive remote control over secure storage systems, enhancing security and reducing costs by allowing secure data management and verification without the need for constant online validation, thus mitigating risks of unauthorized use.

Implementation Method 1

Contactless technology is typically implemented on contactless smart chip technology, a specific form of smart card technology, which uses electromagnetic and/or electrostatic coupling technologies for low-power (LP), short-range (SR) radio frequency (RF) data communication services

Methodology Applied
Scientific EffectElectromagnetic coupling: Electromagnetic Induction

Implementation Method 2

a local RF communication subsystem, and an interconnectivity component which is adapted to enable communication of the secure storage subsystem through the network connectivity subsystem with the network

Methodology Applied
Scientific EffectRadio frequency communication: Electromagnetic Induction

Data Source

PatentUS9294917B2Method, device, and system for network-based remote control over contactless secure storages
Publication Date: 2016.03.22 NOKIA TECHNOLOGIES OY
  • US9294917B2 patent drawing
  • US9294917B2 patent drawing
  • US9294917B2 patent drawing

AI summary

A typical system environment comprises a terminal device, a secure storage subsystem, and an interconnectivity component. The terminal device has a network connectivity subsystem enabled for data connectivity with a wireless communications network. The secure storage subsystem has a secure storage memory for securely storing contents and is enabled for local RF connectivity through a local RF communication subsystem. The secure storage subsystem is operable as a contactless smartcard in accordance with any contactless technology. The interconnectivity component is adapted to enable communication of the secure storage subsystem through the network connectivity subsystem with the network. The interconnectivity component is further configured to detect that messages received from the network are destined for the secure storage subsystem and is configured to supply that identified messages to the secure storage subsystem. The messages enable exercising control over the secure storage subsystem in that the messages comprise one or more instructions to be processed by a secure memory controller of the secure storage subsystem.