RFID Chip NFC Authentication for Secure VPN Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user equipment (UE) systems lack robust authentication mechanisms for secure communication, particularly in scenarios requiring privileged access, and face challenges in securely establishing virtual private network (VPN) tunnels for secure data exchange between devices and cloud services.

Innovation Solution

Incorporating a radio frequency identity (RFID) chip with near field communication (NFC) capabilities into UE systems, which enables the establishment of VPN tunnels by providing an additional authentication factor linked to the device's location, using NFC messages to authenticate and authorize access to cloud services, and ensuring secure data exchange through dual-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication mechanisms are used for VPN tunnel establishment, then device complexity is reduced, but security and reliability are insufficient

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds an RFID chip within the UE device, creating a nested structure where the RFID chip (containing NFC transceiver, internal processor, and internal memory) is integrated into the larger UE system. This nesting allows the RFID chip to provide additional authentication factors without requiring a completely separate authentication system, thereby improving security while managing complexity through hierarchical integration.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The RFID chip acts as an intermediary component between the UE's main processor and external authentication systems. It receives NFC messages from external devices, processes authentication requests, and communicates with the application on the processor, thereby mediating the authentication process and enhancing security without directly complicating the main UE architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dual-factor authentication with RFID chip is implemented, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidcomponent complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication factors (traditional device authentication and location-based NFC authentication) into a unified dual-factor authentication process. The RFID chip integrates the NFC transceiver, internal processor, and internal memory into a single component that works seamlessly with the UE's existing authentication mechanisms, providing enhanced security through merging rather than adding separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The RFID chip is designed with multi-functionality, serving as both an identification device and an authentication credential. It can store multiple identities in its internal memory and respond to different authentication scenarios, thereby providing universal authentication capabilities that reduce the need for multiple specialized components and mitigate complexity increases.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If location-based authentication is added, then security against data loss is improved, but ease of operation is reduced

Engineering Contradiction:
Improvedata securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The RFID chip autonomously handles the authentication process by receiving NFC messages, comparing stored identities with received identities, and automatically determining location-based authentication credentials. This self-service capability eliminates the need for user intervention in complex authentication steps, thereby improving data security while maintaining ease of operation through automatic authentication.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authentication actions by storing multiple identities and authentication credentials in the RFID chip's internal memory before actual authentication is needed. When an authentication request occurs, the pre-stored credentials are readily available for immediate verification, thereby enhancing security without requiring complex real-time processing that would reduce operational ease.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances security by providing an additional authentication factor based on location, reducing the risk of data loss or expropriation, and enabling secure communication between UE devices and cloud services through robust authentication and authorization processes.

Implementation Method 1

The RFID chip comprises an RFID near field communication (NFC) transceiver

Methodology Applied
Scientific EffectNear field communication (NFC): Electromagnetic Induction

Data Source

PatentUS9591434B1Virtual private network (VPN) tunneling in a user equipment (UE) brokered by a radio frequency identity (RFID) chip communicatively coupled to the user equipment
Publication Date: 2017.03.07 T MOBILE INNOVATIONS LLC
  • US9591434B1 patent drawing
  • US9591434B1 patent drawing
  • US9591434B1 patent drawing

AI summary

A user equipment (UE). The UE comprises a motherboard comprising a communication bus, a cellular radio frequency transceiver, a processor, a radio frequency identity (RFID) chip, and a memory storing an application. The RFID chip is connected to the communication bus and comprises an RFID near field communication (NFC) transceiver, an RFID internal processor, an RFID internal memory, and an RFID application. When executed by the processor, the application receives a request from the RFID chip to establish a virtual private network (VPN) tunnel via the cellular radio frequency transceiver based on information encapsulated in the request. The RFID application, when executed by the RFID internal processor, receives a message from an NFC device comprising a command to open the VPN tunnel and sends the request to establish the VPN tunnel to the application executed on the processor.