IP Library Granted Patent US 10,999,737
Granted Patent B2
US 10,999,737 · App. 16/860,827 · Granted May 4, 2021

Detection of a rerouting of a communication channel of a telecommunication device connected to an NFC circuit

Inventors: Thierry Huque (Ramillies, BE); Olivier Van Nieuwenhuyze (Wezembeek-Oppem, BE)
Assignee: PROTON WORLD INTERNATIONAL N.V.
H04W12/06H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,999,737
App. No.
16/860,827
Granted
May 4, 2021
Kind
B2
Abstract

The invention relates to a method for detecting an attempt to reroute a communication channel between a port of a security module and a port of a near-field communication router, which are in a telecommunication device, wherein, upon receiving a message in a near-field communication format, the security module verifies from which port of the communication router said message originates.

Claims (56)

1. A method, comprising:

using one or more communication pipes within a near field communication (NFC) router of a telecommunication device to implement NFC transactions of one or more authorized applications executed by an applications processor of the telecommunication device, the one or more communication pipes being coupled between radio-frequency gates of the NFC router and physical gates of the NFC router assigned to a circuit of the telecommunication device;

detecting, by the telecommunication device, an attempt to modify a communication pipe of the one or more communication pipes to implement an NFC transaction, the detecting including:

receiving a message in a near field communication format via one or more gates of the NFC router;

comparing a first set of bits associated with the message with a second set of bits specified in a routing table of the NFC router, the second set of bits corresponding to one or more gate identifiers respectively for one or more gates of the NFC router;

determining that the first set of bits does not match the second set of bits; and

preventing, as a result of determination that the first set of bits does not match the second set of bits, implementation of the NFC transaction.

2. The method of claim 1 , comprising:

comparing a first portion of the first set of bits with a second portion of the second set of bits.

3. The method of claim 2 , wherein the second portion of the second set of bits identifies a pair of gates of the telecommunication device.

4. The method of claim 2 , comprising:

comparing a third portion of the first set of bits with a fourth portion of the second set of bits.

5. The method of claim 4 , comprising:

dynamically generating the fourth portion according to a pipe identifier creation rule.

6. The method of claim 1 , comprising:

generating one or more pipe identifiers corresponding to the one or more communication pipes of the telecommunication device; and

storing the one or more pipe identifiers in the NFC router table.

7. The method of claim 6 , wherein the one or more pipe identifiers are generated according to a pipe identifier creation rule involving an injective function.

8. The method of claim 6 , comprising:

creating the one or more communication pipes between circuits of the telecommunication device, the one or more pipe identifiers identifying respective communication pipes of the one or more communication pipes.

9. A telecommunication device, comprising:

a security circuit; and

a near field communication (NFC) router having a processor, a plurality of gates, and logic through which the processor manages the plurality of gates, the NFC router, in operation:

receives a message in an NFC format via one or more gates of the plurality of gates;

compares a first set of bits of the message with a second set of bits specified in a routing table of the NFC router, the second set of bits corresponding to one or more gate identifiers of the plurality of gates;

determines that the message includes an unauthorized transaction based on a mismatch between the first set of bits and the second set of bits; and

prevents, as a result of determination that the message includes the unauthorized transaction, implementation of the unauthorized transaction.

10. The telecommunication device of claim 9 , wherein the NFC router, in operation:

compares a first portion of the first set of bits with a second portion of the second set of bits.

11. The telecommunication device of claim 10 , wherein the second portion of the second set of bits identifies a pair of gates of the telecommunication device.

12. The telecommunication device of claim 10 , wherein the NFC router, in operation:

compares a third portion of the first set of bits with a fourth portion of the second set of bits.

13. The telecommunication device of claim 12 , wherein the NFC router, in operation:

dynamically generates the fourth portion of the second set of bits according to a pipe identifier creation rule.

14. The telecommunication device of claim 9 , wherein the NFC router, in operation:

generates one or more pipe identifiers corresponding to the one or more communication pipes of the telecommunication device; and

stores the one or more pipe identifiers in the NFC router table.

15. The telecommunication device of claim 14 , wherein the one or more pipe identifiers are generated according to a pipe identifier creation rule involving an injective function.

16. The telecommunication device of claim 14 , wherein the NFC router, in operation:

creates the one or more communication pipes between circuits of the telecommunication device, the one or more pipe identifiers identifying respective communication pipes of the one or more communication pipes.

17. A telecommunication device, comprising:

a security circuit; and

a router having a processor, a plurality of physical gates, and logic through which the processor manages the plurality of physical gates, wherein the security circuit, in operation,

forms a plurality of communication pipes between respective gates of the plurality of physical gates; and

responds to transmission, via one of the plurality of communication pipes, of a message in a NFC format requesting validation of an NFC transaction, by transmitting, to the security circuit, a first set of bits of the message; and

the security circuit, in operation:

compares the first set of bits of the message with a second set of bits specified in a routing table, the second set of bits corresponding to one or more gate identifiers of the plurality of gates;

determines that the message includes an unauthorized transaction based on a mismatch between the first set of bits and the second set of bits; and

responds to receipt of the message by refusing to validate the NFC transaction.

18. The telecommunication device of claim 17 , wherein the security circuit, in operation:

compares a first portion of the first set of bits with a second portion of the second set of bits.

19. The telecommunication device of claim 18 , wherein the security circuit, in operation:

compares a third portion of the first set of bits with a fourth portion of the second set of bits.

20. The telecommunication device of claim 18 , wherein the security circuit, in operation:

generates one or more pipe identifiers corresponding to the one or more communication pipes of the telecommunication device; and

stores the one or more pipe identifiers in the NFC router table.

Assignments (1)
CHANGE OF NAME Recorded Sep 26, 2024
From: PROTON WORLD INTERNATIONAL
To: STMICROELECTRONICS BELGIUM
Reel/Frame 069057/0620 →
Priority Claims (1)
FR 10/51694 · Mar 9, 2010 · national
Continuity (2)
Continuation 13583166
Related Publication 20200260281A1 · Aug 13, 2020