Access control for near field communication functionality
By exchanging notifications between the secure element system and the near-field communication control system of the mobile device, the NFC function is enabled or disabled based on the status of the security application, thus solving the problem of insufficient security of the mobile device and achieving effective access control and data security enhancement.
Patent Information
- Application Number
- CN202011301167.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-12-10
- Filing Date
- 2020-11-19
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2040-11-19
AI Technical Summary
Existing mobile devices equipped with near-field communication functions have security deficiencies that may lead to unauthorized data access and communication interference. It is necessary to improve the security level to prevent unauthorized access and interference.
By exchanging notifications at an interface between a secure element system of a mobile device and a near field communication control system, the NFC function is enabled or disabled based on the status of a secure application, and predefined security conditions and access control lists are used to control the enabling and disabling of the NFC function.
Effective access control to NFC functions is achieved, the security of mobile devices is improved, unauthorized data access and communication interference are prevented, and the data security level is enhanced.
Smart Images

Figure CN112954656B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data and access security for mobile devices equipped with Near Field Communication (NFC) functionality. In particular, the present invention relates to a method, a control device, and a computer program for activating / deactivating at least one NFC functionality of such a mobile device. Furthermore, the present invention relates to such a mobile device. Background Art
[0002] Mobile communication devices such as smartphones, PDAs, and tablet computers often incorporate advanced technologies for processing and using sensitive information. An example of this technology is the combination of an NFC controller and at least one secure element (SE) within a mobile (communication) device. For example, this combination can be used with payment applications that utilize sensitive information such as credit card details, bank account numbers, and passwords. While this sensitive information must be protected, the application must be able to access relevant security features to achieve its intended purpose.
[0003] In some usage scenarios of a combined NFC controller and SE, it may be necessary that certain NFC (controller) functions, even though exposed to all applications installed on the corresponding mobile device via an application programming interface (API), should only be accessible when certain security or access conditions are met. Example usage scenarios are:
[0004] (A) NFC (controller) function ensures that the smart card interface of the mobile device is enabled to read the smart card in a specific way. This reading smart card function in the NFC controller can only be used after completing a specific user authentication and activation process.
[0005] (B) An unauthorized host device / host application could potentially read unsecured data from an NFC payment smart card or an NFC-enabled mobile device hosting such a payment smart card. The information content of this read data may be identical to the so-called Line 1 and Line 2 data of a magnetic stripe card and may contain information such as a personal account number, cardholder name, expiration date, etc. This access could violate privacy and be sufficient to facilitate cloning of an NFC payment smart card or conduct unauthorized transactions without the NFC payment smart card. Transactions could involve, for example, internet payments or manual entry of card information. Clearly, such access by unauthorized host devices / host applications is necessary.
[0006] (C) A malicious host device / application may also send commands to the NFC controller to interfere with, monitor, or take over the communication between a secure application (e.g., a payment reader) on the SE and an external smart card (e.g., a payment card) via the NFC controller. Such actions may lead to harmful data mining.
[0007] There may be a need to improve the level of security for mobile devices equipped with NFC functionality. Summary of the Invention
[0008] This need may be met by the subject matter according to the independent claims. Advantageous embodiments of the invention are described by the dependent claims.
[0009] According to a first aspect, a method for enabling / disabling at least one NFC function of a mobile device having a Near Field Communication (NFC) control system and a secure element (SE) system is described. The method comprises: (a) associating the at least one NFC function to be enabled / disabled with a corresponding security application installed in the SE system; (b) checking whether the security application complies with predefined security conditions; (c) if the security application complies with the predefined security conditions, transmitting a notification from the security application to the NFC control system via an interface between the SE system and the NFC control system; and (d) enabling / disabling, by the NFC control system, the at least one NFC function based on information included in the transmitted notification.
[0010] The described method is based on the concept that the security level of the NFC functionality of a mobile device can be increased in a relatively simple yet effective manner by controlling the operation of an NFC control system based on information provided by the SE system of the corresponding mobile (communication) device. The SE system provides this information to the NFC control system along with a notification or message transmitted via an interface provided between the SE system and the NFC control system. The operational control of the NFC control system is achieved by (i) enabling or activating or (ii) disabling or deactivating at least one specific NFC functionality. This results in effective NFC access control for the corresponding mobile device. This access control depends on the status of at least one security application installed in the SE system.
[0011] Depending on the specific use case, the NFC control system may have an initial state in which the corresponding NFC function is enabled or disabled. Using the described method, the current state of the corresponding NFC function can be changed from enabled to disabled, and vice versa, the state can be changed from disabled to enabled.
[0012] In the context of this document, the term "NFC functionality" may particularly denote an NFC functionality of a mobile device that a user of the mobile device may desire. Examples of such functionality may be, for example, user authentication for entering restricted areas, the ability to perform payment procedures, etc.
[0013] In the context of this document, the term "mobile device" may specifically refer to a mobile communication device, such as a mobile phone, a smart phone, a personal digital assistant (PDA), a tablet computer, a laptop computer, or any similar device capable of communicating via a data communication network, such as a cellular communication network or a wired or wireless data network.
[0014] In the context of this document, the term "NFC control system" or "NFC controller" may specifically refer to any circuitry that controls the operation of NFC functionality. Specifically, this may include controlling the radio frequency (RF) components that drive the mobile device's RF antenna for transmitting NFC signals (over-the-air). Additionally, such circuitry may be responsible for processing the RF signal that has been captured by the RF antenna.
[0015] In the context of this document, the term "SE system" or simply "SE" may specifically refer to a secure element as specified by the GlobalPlatform standard (see https: / / globalplatform.org / ). The term "SE" may also refer to other forms of secure elements in mobile systems. Such a secure element may be implemented by a Universal Integrated Circuit Card (UICC), such as a Subscriber Identity Module (SIM) card or a Secure Digital (SD) card, which is connected to the NFC control system.
[0016] In the context of this document, the term "secure application" may specifically refer to an application that is protected from unauthorized data access, which may be attempted by a hacker. The required protection may be achieved through known keying techniques and / or digital certificates. An application may be any program for a mobile device, such as a program application commonly referred to as an "app" or a remote application located at a location external to the mobile device (e.g., in the cloud). A "secure application" in the context of this document may also be a signed application, which may include an installation file or an executable file or program that has been signed with one or more cryptographic keys.
[0017] In the context of this document, the term "security condition" may refer to any condition that, when fulfilled, indicates a certain level of data security for at least one entity of a data communication network or any other entity within a communication system. Such a communication system may be, for example, an internal communication system of a mobile device, which "carries" all internal data communications between different internal entities, in particular between an NFC control system and a secure element system.
[0018] In the context of this document, the term "notification" or "message" may specifically refer to any piece of information transmitted between the SE system and the (security application of) the NFC control system. Such information is used to enable / disable the corresponding NFC function.
[0019] According to an embodiment, the notification includes a secure application identifier. This may provide the advantage that the amount of data included in the notification can be kept small. Thus, implementing the described method does not require a significant increase in the amount of data traffic within the mobile device.
[0020] A security application identifier may be any piece of information that uniquely identifies a corresponding security application within at least a mobile device.
[0021] According to yet another embodiment, the notification further includes operation information indicating what operation the NFC control system is to take.
[0022] The described operational information can be specific instructions to the NFC control system regarding which NFC function to enable or disable. This can mean that the notification does not simply "give permission" to enable / disable a certain NFC function. In addition, the notification directly prompts the NFC control system to act accordingly.
[0023] It should be mentioned that in some embodiments the action to be taken may also be defined at least implicitly by the secure application identifier itself. This means that the secure application identifier also dictates the (future) action of the NFC control system.
[0024] According to yet another embodiment, the method further comprises: (a) comparing, by the NFC control system, the transmitted notification with at least a portion of an access control list stored in the NFC control system; and (b) identifying, by the NFC control system, that the transmitted notification corresponds to at least a portion of the access control list. The described comparison and identification processes can be considered to represent additional data security measures that further increase the security level of the described method.
[0025] The access control list may be stored in any suitable memory comprised by or accessible to the NFC control system.The externally accessible memory may be a component of a so-called trusted server.
[0026] According to another embodiment, the predefined security condition includes that the security application has been activated by a trusted entity. The trusted entity can be, for example, an accessible external trusted server. Alternatively or in combination, the trusted entity can be an internal trusted entity, such as a (separate) SE system or another security application installed in the SE system.
[0027] According to another embodiment, the predefined security condition includes that the security application has been authenticated by a trusted entity. Likewise, the trusted entity can be, for example, an accessible external trusted server and / or an internal trusted entity, such as a (further) SE system or a security application installed in the SE system.
[0028] According to another embodiment, the predefined security condition includes having previously received a security command by the SE system, wherein the security command has been forwarded to the SE system by a trusted entity via a secure channel. In this embodiment, the trusted entity may be an accessible external trusted server. The secure channel may be, for example, a VPN data connection.
[0029] According to yet another embodiment, the predefined security condition comprises the occurrence of a predefined event during execution of the security application. The predefined event may be the validity of a timer event (the timer has not expired), a predefined condition or state of the security application.
[0030] According to yet another embodiment, the step of associating at least one NFC function to be enabled / disabled with a corresponding security application installed in the SE system comprises dynamic mapping. The described dynamic mapping may be implemented by any known mapping process.
[0031] The preferred dynamic mapping process may include: (a) assigning an identifier to the NFC function; and (b) changing the state or accessibility of the NFC function while the security application is running on the SE system. Thus, the security application can use the (NFC function) identifier and (if applicable) other parameters to change accessibility. To increase the level of data security, the security application's use of the (NFC function) identifier can only be changed by a trusted external / internal entity using a secure mechanism.
[0032] According to yet another embodiment, the SE system is implemented by means of an internal data processing unit embedded in the mobile device. The data processing unit can be implemented with a physical processor or a functional block of the architecture of a larger data processing device that is part of the mobile device and is also responsible for executing other functions of the mobile device.
[0033] According to another embodiment, the SE system is implemented with the aid of an external data processing unit connected to the mobile device. The external data processing unit may be, for example, a Universal Integrated Circuit Card (UICC) or a Secure Digital (SD) card, which has at least some data processing capabilities and is communicatively connected to a suitable (additional) interface of the mobile device. The card can be inserted into a corresponding slot so that it can be geometrically placed into (the housing of) the mobile device.
[0034] According to another aspect, a control device for enabling / disabling at least one near-field communication (NFC) function of a mobile device is provided. The provided control device includes: (a) an NFC control system; (b) a secure element (SE) system connected to the NFC control system via an interface; and (c) a processor for controlling the operation of the NFC control system and / or the SE system in a manner that performs the method described above.
[0035] The described control device is based on the following idea: by dividing the known NFC and SE overall system into two subsystems, one of which is the described NFC control system and the other is the described SE system, the security level of the NFC functions can be increased if the availability of at least one NFC function depends on a successful notification exchange between the SE system and the NFC control system.
[0036] According to another aspect, a mobile device implementing a near field communication (NFC) function is provided, comprising: a control device as described above; and a radio frequency (RF) antenna arrangement connected to the control device so that RF data signals can be exchanged between an NFC control system of the control device and the RF antenna arrangement.
[0037] The RF antenna arrangement can be configured to: (a) receive RF electromagnetic radiation from an external NFC device and forward a corresponding NFC electrical receive signal to an NFC control system; and / or (b) receive an NFC electrical transmit signal from an NFC control system and convert it into RF electromagnetic radiation to be received by the external NFC device. Alternatively, the mobile device can include two RF antenna arrangements, one for receiving RF electromagnetic radiation and the other for transmitting RF electromagnetic radiation. The external NFC device can be, for example, an NFC reader, a smartphone, a smart card, etc.
[0038] The mobile device may further comprise RF matching circuitry connected between the control device and the RF antenna arrangement. By means of the RF matching circuitry, the characteristic output impedance of the control device may be at least approximately adjusted to the characteristic input impedance of the RF antenna arrangement (and vice versa).
[0039] According to an embodiment, the mobile device further comprises a second interface for connecting the mobile device to an external entity, in particular via a secure channel.
[0040] The second interface can further increase the level of data security, particularly when the external entity is a trusted server, which the mobile device can access preferably via a secure channel. The trusted server can be used, for example, to activate and / or authenticate security applications. As mentioned above, the secure channel can be, for example, a VPN data connection.
[0041] According to another aspect, a computer program for activating / deactivating at least one NFC function of a mobile device having a Near Field Communication (NFC) control system and a Secure Element (SE) system is provided. The computer program is suitable for controlling and / or executing the method as described above when executed by a data processor.
[0042] As used herein, reference to a computer program is intended to be equivalent to reference to a program element and / or to a computer-readable medium containing instructions for controlling a computer system to coordinate the performance of the above-described method.
[0043] The computer program can be implemented as computer-readable instruction code in any suitable programming language, such as JAVA, C++, and can be stored on a computer-readable medium (removable disk, volatile or non-volatile memory, embedded memory / processor, etc.). The instruction code can be used to program a computer or any other programmable device to perform a predetermined function. The computer program can be obtained from a network, such as the World Wide Web, and can be downloaded from the network.
[0044] The embodiments of the present invention may be implemented by means of a computer program or software. However, the present invention may also be implemented by means of one or more specific electronic circuits or hardware. Furthermore, the present invention may also be implemented in a hybrid form, i.e., a combination of software modules and hardware modules.
[0045] The embodiments of the invention described in this document may also be implemented in conjunction with a “cloud” network, which provides the necessary virtual memory space and the necessary virtual computing power.
[0046] It should be noted that embodiments of the present invention have been described with reference to different subject matters. Specifically, some embodiments have been described with reference to method-type claims, while other embodiments have been described with reference to apparatus-type claims. However, those skilled in the art will conclude from the foregoing and the following description that, unless otherwise indicated, any combination of features relating to different subject matters, in addition to any combination of features belonging to one type of subject matter, and in particular, combinations of features from method-type claims with features from apparatus-type claims, are also considered to be disclosed with this application.
[0047] The aspects defined above and further aspects of the invention are apparent from the examples of embodiment described hereinafter and are explained with reference to the examples of embodiment.The invention will be described in more detail hereinafter with reference to examples of embodiment but to which the invention is not limited. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1A mobile communication device is shown having NFC functionality that can be disabled / enabled according to the methods described in this document.
[0049] Figure 2 is a flow chart illustrating the exchange of notifications when performing the methods described in this document. DETAILED DESCRIPTION
[0050] The illustrations in the accompanying drawings are schematic. It should be noted that in different figures, similar or identical elements or features are provided with the same reference numerals or reference numerals that differ from the corresponding reference numerals only within the first digit. To avoid unnecessary repetition, elements or features that have already been explained with respect to previously described embodiments will not be explained again later in the description.
[0051] Figure 1 A mobile communication device MD according to an exemplary embodiment of the present invention is shown. During operation, notifications or messages are transmitted between various components of the mobile device MD along or via communication paths, signal paths, and / or interfaces, which are depicted by dashed arrows. A dashed arrow drawn with two lines depicts a communication path, signal path, and / or interface for performing the method for enabling / disabling NFC functionality disclosed herein. Communication paths, signal paths, and / or interfaces for performing known functions of mobile devices are depicted with simple dashed arrows and are not labeled with reference numerals.
[0052] If you can Figure 1 As described in the document, a mobile (communication) device MD includes an application processor AP and a system NFC / SE, which is referred to in this document as the Near Field Communication (NFC) and Secure Element (SE) system. The NFC / SE system includes an NFC control (sub)system NFCC, also referred to in this document as the NFC controller. Furthermore, the NFC / SE system includes an SE (sub)system SE. A first interface IF1a enables communication between the two (sub)systems NFCC and SE. A secure (software) application SA is executed in the (sub)system SE.
[0053] The application processor AP includes or hosts a primary host PH, such as an Android operating system, and a secondary host SH. The application processor AP also includes or is connected to a second interface IF2 that allows for communication between the mobile device MD and an external trusted server TS via a secure channel 4a. The measures for securing channel 4a are well known and are not explained in detail in this document. According to the embodiment described herein, channel 4a is secured using known virtual private network (VPN) software.
[0054] If you can Figure 1It is further understood that the mobile device MD includes several peripheral components, such as: (i) a power management unit PMU, which includes or is connected to a battery not depicted; and (ii) two slots, each of which is configured to receive a first universal integrated circuit card UICC1 and a second universal integrated circuit card UICC2, respectively.
[0055] Furthermore, the mobile device MD comprises a radio frequency (RF) component connected to the NFC controller NFCC. Specifically, the RF component comprises a radio frequency matching unit RFM and a radio frequency antenna arrangement RFA.
[0056] In the following, the basic concepts of the NFC function deactivation / activation process described in this document are explained:
[0057] The NFC / SE system is divided into two (sub)systems: the first subsystem is the non-secure NFC controller NFCC, and the second subsystem is the secure secure element subsystem SE.
[0058] During operation, the security application SA in the SE subsystem SE or an application on the PH is configured to interact with a not depicted external NFC reader via the NFC controller NFCC and / or with an external trusted server TS via the application processor AP.
[0059] If you can Figure 1 As can be seen in FIG, the primary host PH and the NFC controller NFCC are communicatively coupled via a communication path 1. By means of appropriate information transmitted via the communication path 1, all possible NFC functionalities are exposed to applications running on the application processor AP, in particular to applications running on the primary host PH.
[0060] According to the disclosed method, access to some of these NFC functions is protected by a security application SA. This security application SA is configured to activate and / or deactivate the corresponding NFC function. This activation / deactivation is performed after a notification has been forwarded from the secure element (sub)system SE to the NFC controller NFCC via communication path 3a (and via interface IF1a), communication path 3b (and via interface 1b), or communication path 3c (and via interface 1c). This notification thus indicates that the security application SA has met predefined security conditions.
[0061] In one embodiment, this condition is only met if the external trusted server TS is securely communicating with the security application SA, for example, via communication paths 4a and 5a (and via the second interface IF2) and / or via communication paths 4a and 4b (and via interface IF1b), or via communication paths 4b or 4c (and via interface IF1c). In another embodiment, this condition is only met if the security application SA itself reaches a predefined required state to prevent misuse of the NFC functionality (e.g., unauthorized reading or unauthorized interference with an ongoing external reader transaction by the security application SA). Such a predefined required state can be, for example, an unexpired timer that is still running.
[0062] After receiving a (valid) notification from the secure element (sub)system SE, the NFC controller NFCC allows the secure application to exchange signals with the radio frequency matching unit RFM or with the radio frequency antenna arrangement RFA via the communication path 2a passing through the interface IF1a. Alternatively or in combination, the secure application running on the first universal integrated circuit card UICC1 and / or on the second universal integrated circuit card UICC2 can also benefit from at least one unblocked NFC function. In this case, the two universal integrated circuit cards UICC1 and UICC2 can be connected to the external trusted server TS via the secure channel 4b and the secure channel 4c, respectively. Figure 1 In the figure, the corresponding control signal paths are marked with reference numerals 3b and 3c, respectively. The corresponding communication paths are marked with reference numerals 2b and 2c, respectively. The interfaces between the NFC controller NFCC on the one hand and the first universal integrated circuit card UICC1 and the second universal integrated circuit card UICC2 on the other hand are marked with reference numerals IF1b and IF1c, respectively.
[0063] In other embodiments, after receiving a (valid) notification from the secure element (sub)system SE, the NFC controller NFCC accepts commands from at least one application running on the primary host PH. These commands are exchanged via communication path 1. It should be noted that such command exchange via communication path 1 is not permitted or denied prior to receiving a (valid) notification. In yet another embodiment, after receiving a (valid) notification from the secure element (sub)system SE, the NFC controller NFCC accepts commands from an application running on the primary host PH via communication path 1 to exchange signals with the radio frequency matching unit RFM or the radio frequency antenna arrangement RFA via communication path 6. Communication or data transfer via communication path 6 is also not permitted or denied prior to receiving a (valid) notification from the secure element (sub)system SE.
[0064] Figure 2 is a flow chart illustrating the communication of notifications and signals when performing the methods described in this document.
[0065] The described method starts with a first step S110 in which at least one NFC function is associated with a security application SA installed on a secure element (sub) system SE. This association may include exchanging one or more notifications between an NFC controller NFCC and the secure element (sub) system SE. Figure 2 In FIG. 1 , this association is shown by a double-headed arrow S110 .
[0066] The method continues with a second step S120, in which the security application SA is checked for compliance with predefined security conditions. According to the exemplary embodiment described herein, step S120 is implemented via two sub-steps. In a first sub-step S122, the user U, initiating a use case involving secure NFC functionality, sends a notification including an activation request to the external trusted server TS. If approved by the trusted server TS, the trusted server TS responds in a second sub-step S124 with a notification including activation of the corresponding security application SA.
[0067] As mentioned above, the external trusted server TS does not necessarily need to be included in the communication flow between the various (logical) entities of the mobile device. In other scenarios, the user of the mobile device can directly forward the activation request S122 to the secure element (sub)system SE. In response to the activation of the secure application SA, the secure element (sub)system SE forwards a notification to the NFC control system NFCC in a third step S130. This notification includes information about the specific NFC functions to be enabled.
[0068] In a fourth step S140, the notification forwarded in the third step S130 is verified. According to the exemplary embodiments described herein, verification is achieved by: (i) comparing the notification with at least a portion of an access control list stored in the NFC controller NFCC; and (ii) identifying that the notification corresponds to at least a portion of the access control list. If verification is achieved in step S140, the method continues with a fifth step S150.
[0069] In this fifth step S150, the NFC controller NFCC enables the corresponding NFC function by controlling and / or configuring the radio frequency matching unit RFM and / or the radio frequency antenna arrangement RFA in a manner that enables the corresponding NFC function. Alternatively or in combination, (a) the NFC controller NFCC may only unblock access to the NFC function from the primary host PH and / or (b) an internal state in the NFC controller NFCC may be unblocked.
[0070] After enabling the corresponding NFC functionality, NFC signals are exchanged between the secure application SA or an application on the PH and the radio frequency matching unit RFM or radio frequency antenna arrangement RFA. Alternatively or in combination, access to the NFC control (sub) system NFCC from an application running on the primary host PH can be implemented. The latter allows the primary host PH (application) to exchange information with the radio frequency matching unit RFM and / or radio frequency antenna arrangement RFA via the NFC control (sub) system NFCC.
[0071] The embodiments of the invention described in this document can be descriptively summarized as follows:
[0072] The entire NFC system NFC / SE of the mobile device MD consists of the NFC control (subsystem) NFCC and the securely authenticated secure element (sub)system SE. The NFC control (sub)system NFCC manages the NFC protocol and a state machine that indicates the status of the entire NFC system NFC / SE. In contrast, the secure element (sub)system SE manages secure content and secure transactions.
[0073] The NFC controller (subsystem) NFCC is managed by the primary host PH of the application processor AP. NFC functionality is typically fully accessible to mobile applications (primary host) via the application programming interface (API) provided by the corresponding mobile platform / operating system (e.g., the Android operating system). In some use cases of the mobile device MD, it may be necessary to enable certain NFC functions only when certain security or access conditions are met, despite being available to all applications via the host API.
[0074] This document describes a mechanism for blocking (disabling) and unblocking (enabling) access to NFC functionality from host applications. This mechanism is based on security conditions implemented on the Secure Element (SE) subsystem, which notifies the NFC Control (NFCC) subsystem. If the security conditions are met, the corresponding NFC functionality is enabled. If the security conditions are not met, the corresponding NFC functionality can be disabled.
[0075] It should be noted that the term "comprising" does not exclude other elements or steps, and "a" or "an" does not exclude a plurality. Elements described in connection with different embodiments may also be combined. It should also be noted that the reference signs in the claims should not be construed as limiting the scope of the claims.
[0076] Reference numerals:
[0077] MD Mobile (communication) device
[0078] AP Application Processor
[0079] NFC / SE NFC and SE systems
[0080] PH Level 1 Host
[0081] SH Secondary Host
[0082] IF2 Second interface
[0083] NFCC NFC control (sub) system / NFC controller
[0084] SE Safety Element (Sub) System
[0085] IF1a, b, c first interface
[0086] SA Security Application
[0087] PMU Power Management Unit
[0088] UICC1 First Universal Integrated Circuit Card
[0089] UICC2 Second Universal Integrated Circuit Card
[0090] RFM RF matching unit
[0091] RFA radio frequency antenna (arrangement)
[0092] TS Trusted Server
[0093] U User
[0094] 1 Communication Path PH-NFC
[0095] 2a, 2b, 2c Communication paths
[0096] 3a, 3b, 3c Control signal path
[0097] 4a, 4b, 4c Secure Channel
[0098] 5a Communication path SH-SA
[0099] 5b Communication path SA-PH
[0100] S110 Associate NFC functionality with SA
[0101] S120 Checks whether SA meets security conditions
[0102] S122 Activation Request
[0103] S124 Activation Notification
[0104] S130 Transmit notification from SA to NFC control system
[0105] S140 Verification Notice
[0106] S150 NFC enabled
[0107] S160 exchanges signals between SA and RFM / RFA.
Claims
1. A method for activating / deactivating at least one NFC function of a mobile device (MD) having a Near Field Communication (NFC) control system (NFCC) and a Secure Element (SE) system (SE), characterized in that: The method comprises associating the at least one NFC function to be enabled / disabled with a corresponding security application (SA) installed in the SE system (SE), wherein the SE system is more secure than the NFC control system; checking whether the security application (SA) complies with a predefined security condition, wherein the predefined security condition is a predefined state of the security application, and wherein the predefined state is reached when the security application (SA) has been activated by a trusted entity (TS), wherein the predefined security condition comprises having previously received a security command by the SE system (SE), wherein the security command has been forwarded by the trusted entity (TS) to the SE system (SE) via a secure channel (4); If the security application (SA) meets the predefined security conditions, then transmitting a notification from the security application (SA) to the NFC control system (NFCC) via an interface (IF1) between the SE system (SE) and the NFC control system (NFCC) (S130); activating / deactivating, by the NFC control system (NFCC), the at least one NFC function based on the information included in the transmitted notification; and exchanging NFC signals between the security application and the radio frequency antenna via the NFC function, Wherein, the method further comprises: comparing, by the NFC control system (NFCC), the transmitted notification with at least a portion of an access control list stored in the NFC control system (NFCC), and The transmitted notification is identified by the NFC control system (NFCC) as corresponding to at least a portion of the access control list.
2. The method according to claim 1, characterized in that The notification includes a secure application identifier.
3. The method according to claim 1, characterized in that The notification further includes operation information indicating what operation the NFC control system (NFCC) is to take.
4. The method according to claim 1, wherein The predefined security conditions further include that the security application (SA) has been authenticated by the trusted entity (TS).
5. A control device for activating / deactivating at least one Near Field Communication (NFC) function of a mobile device (MD), characterized in that: The control device includes NFC Control System (NFCC); a secure element SE system (SE), the secure element SE system (SE) being connected to the NFC control system (NFCC) via an interface (IF1); as well as A processor (AP) for controlling the operation of the NFC control system (NFCC) and / or the SE system (SE) in such a way that the method according to any of the preceding method claims is performed.
6. A mobile device (MD) with near field communication (NFC) functionality enabled, characterized in that: The mobile device (MD) includes A control device according to any preceding claim, and A radio frequency, RF, antenna arrangement (RFA) is connected to the control device to enable RF data signals to be exchanged between the NFC control system (NFCC) of the control device and the RF antenna arrangement (RFA).
7. A computer program product, characterized in that The computer program product is for activating / deactivating at least one NFC function of a mobile device (MD) having a Near Field Communication (NFC) control system (NFCC) and a Secure Element (SE) system (SE), the computer program product being adapted to control and / or perform the method according to any of the preceding method claims when executed by a data processor.
Citation Information
Patent Citations
Method and mobile terminal device including smartcard module and near field communications means
EP2315170A1
Method and device for controlling access from the device to a card via a NFC interface
US9977890B2