NFC service

By using keys provided by secure elements to encrypt and decrypt data in electronic devices, and controlling data access permissions through interface software, the security and anonymity issues of data exchange between electronic device modules are resolved, ensuring that only authorized applications can decrypt critical data.

CN116264681BActive Publication Date: 2026-01-02STMICROELECTRONICS (ROUSSET) SAS +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211608339.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-12-13
Filing Date
2022-12-14
Publication Date
2026-01-02
Estimated Expiration
2042-12-14

AI Technical Summary

Technical Problem

When exchanging confidential and/or critical data between different modules of the same electronic device, existing technologies lack effective protection measures, resulting in insufficient data security and anonymity.

Method used

Data is encrypted and decrypted using keys provided by the security element, and data access permissions are controlled through interface software to ensure that only authorized applications can decrypt critical data.

Benefits of technology

It improves the security and anonymity of exchanging confidential and critical data between different modules of electronic devices, and prevents unauthorized applications from accessing sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116264681B_ABST
    Figure CN116264681B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to NFC services. In one embodiment, a method for implementing NFC services between a mobile terminal and a remote module is disclosed. The terminal comprises a processor hosting an application configured to establish NFC services and an interface software configured to execute instructions of the application, a near field communication module and a secure element distinct from the processor. The method comprises requesting, by the application, implementation of an authorization of NFC services from the secure element via the interface software, the interface software verifying whether the application is authorized to communicate with the secure element, sending, by the secure element, a first temporary authorization to the interface software, determining, at least the first time, whether the interface software has received the first temporary authorization when the near field communication module receives first data from the remote module, and sending, by the interface software, the first data to the application when the interface software has received the first temporary authorization.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross Reference to Related Applications

[0002] This application claims the benefit of French Patent Application No. 2113471, filed December 14, 2021, which is hereby incorporated by reference herein. TECHNICAL FIELD

[0003] The present disclosure relates generally to electronic devices, and more particularly to electronic devices suitable for handling secret data. More specifically, the present disclosure relates to electronic devices adapted to implement near field communication (NFC), and in particular NFC transactions, in which at least a part of the exchanged data is secret data and / or a part of the exchanged data is critical data, which allows for example a method of identifying or authenticating a user. BACKGROUND

[0004] Complex electronic devices, such as telephones, tablet computers, computers, etc., integrate over time more and more functions and are able to implement digital services in order to implement the best integration in everyday life. For example, certain telephones, and in particular smartphones, integrate digital services such as banking payment services, or use services of public transport tickets, event tickets, and authentication of users by remote systems (banks, public administration, etc.). To implement these functions, the devices can integrate electronic components specific to these functions, such as security components, which are able to hold / store identification, reference and authentication information (often called “credentials”) and assets of digital service providers, motion sensors, near field communication modules (NFC), etc.

[0005] One difficulty brought by the addition of new functions is the exchange of secret data and / or critical data between different modules of the same electronic device, without protection. SUMMARY

[0006] Various embodiments provide more reliable near field communications.

[0007] Various embodiments provide near field communications regarding the secrecy and / or anonymity of the users of these communications.

[0008] Various embodiments provide more reliable NFC transactions.

[0009] Various embodiments provide NFC transactions regarding the secrecy and / or anonymity of the users of these transactions.

[0010] Various embodiments overcome all or part of the drawbacks of known near field communications.

[0011] Various embodiments overcome all or part of the drawbacks of known NFC transactions.

[0012] Some embodiments provide a method for implementing an NFC service between a mobile terminal and a remote module, the terminal comprising a processor hosting an application establishing an NFC service, a near field communication module and a secure element distinct from the processor, the method comprising at least the following successive steps:

[0013] (a) said near field communication module encrypts first data sent by said remote module by using a first key provided by said secure element; and

[0014] (b) said first application decrypts said first data by using a second key provided by said secure element.

[0015] Another embodiment provides a mobile terminal adapted to implement an NFC service with a remote module, the terminal comprising a processor hosting an application establishing an NFC service, a near field communication module and a secure element distinct from the processor, the method for implementing an NFC service comprising at least the following successive steps:

[0016] (a) said near field communication module encrypts first data sent by said remote module by using a first key provided by said secure element; and

[0017] (b) said first application decrypts said first data by using said first key provided by said secure element.

[0018] According to one embodiment, the application is authorized to implement the NFC service through interface software hosted by the processor and executing instructions sent by said application.

[0019] According to one embodiment, the application is a system application.

[0020] According to one embodiment, the application is a trusted application having received a permanent authorization to implement the NFC service.

[0021] According to one embodiment, the application has received a temporary authorization to implement the NFC service.

[0022] According to one embodiment, the secure element communicates to said interface software the temporary authorization regarding the application.

[0023] According to one embodiment, if the interface software does not comprise an authorization regarding said application, the interface software prohibits the application to request a key to the secure element during step (b).

[0024] According to one embodiment, the secure element obtains the temporary authorization from an external server.

[0025] According to one embodiment, the secure element comprises a list of rules indicating the authorizations regarding said application and other applications if the device implements other applications.

[0026] According to one embodiment, the first and second keys are identical.

[0027] According to one embodiment, if the application is not authorized to implement the NFC service, during step (b), the secure element refuses to provide the second key to the application and the application is unable to decrypt the first data.

[0028] According to one embodiment, the NFC service is a service implemented through a near field communication method.

[0029] According to one embodiment, the NFC service is a service for which the terminal and the remote module can exchange third key data.

[0030] According to one embodiment, the NFC service is a banking service.

[0031] According to one embodiment, step (a) is preceded by step (c) during which the near field communication module is able to detect that the data is key data.

[0032] According to one embodiment, step (a) is preceded by step (c) during which the near field communication module detects that the first data comprises key data.

[0033] Another embodiment provides a system comprising the terminal and the remote module described previously.

[0034] Some embodiments provide a method for implementing an NFC service between a mobile terminal and a remote module, the terminal comprising a processor hosting an application establishing an NFC service, a near field communication module and a secure element distinct from the processor, the method comprising at least the following successive steps:

[0035] (a) the near field communication module sending to the first application first data sent by the remote module and encrypted by the secure element; and

[0036] (b) the first application requesting the secure element to decrypt the first data.

[0037] Another embodiment provides a mobile terminal adapted to implement an NFC service with a remote module, the terminal comprising a processor hosting an application establishing an NFC service, a near field communication module and a secure element distinct from the processor, the method for implementing an NFC service comprising at least the following successive steps:

[0038] (a) the near field communication module sending to the first application first data sent by the remote module and encrypted by the secure element; and

[0039] (b) the first application requesting the secure element to decrypt the first data.

[0040] According to one embodiment, the application is authorized to implement the NFC service through the interface software, the interface software being hosted by the processor and executing instructions sent by the application.

[0041] According to one embodiment, the application is a system application.

[0042] According to one embodiment, the application is a trusted application that has received a permanent authorization to implement the NFC service.

[0043] According to one embodiment, the application has received a temporary authorization to implement the NFC service.

[0044] According to one embodiment, the secure element communicates to the interface software a temporary authorization regarding the application.

[0045] According to one embodiment, if the interface software does not include an authorization regarding the application, the interface software prohibits the application from requesting a key from the secure element during step (b).

[0046] According to one embodiment, the secure element obtains the temporary authorization from an external server.

[0047] According to one embodiment, the secure element includes a list of rules indicating authorizations regarding the application and other applications, if the device implements other applications.

[0048] According to one embodiment, if the application is not authorized to implement the NFC service, the secure element refuses to decrypt the first data and to send it to the application during step (b).

[0049] According to one embodiment, the NFC service is a service implemented through a near field communication method.

[0050] According to one embodiment, the NFC service is a service for which the terminal and the remote module can exchange third critical data.

[0051] According to one embodiment, the NFC service is a banking service.

[0052] According to one embodiment, step (a) is preceded by step (c) during which the near field communication module is able to detect that the data is critical data.

[0053] According to one embodiment, step (a) is preceded by step (c) during which the near field communication module detects that the first data includes critical data.

[0054] Another embodiment provides a system comprising the terminal and the remote module previously described.

[0055] Other embodiments provide a method for implementing an NFC service between a mobile terminal and a remote module, said terminal comprising a processor hosting an application establishing an NFC service, a near field communication module and a secure element distinct from the processor, said method comprising at least the following successive steps:

[0056] (a) storing, by said near field communication module, first data transmitted by said remote module in said secure element;

[0057] (b) sending, by said near field communication module, second data to said first application to alert that said first data has been stored in said secure element; and

[0058] (c) requesting, by said first application, said secure element to provide it with said first data.

[0059] Another embodiment provides a mobile terminal adapted to implement an NFC service with a remote module, the terminal comprising a processor hosting an application establishing an NFC service, a near field communication module and a secure element distinct from the processor, the method for implementing an NFC service comprising at least the following successive steps:

[0060] (a) storing, by said near field communication module, first data transmitted by said remote module in said secure element;

[0061] (b) sending, by said near field communication module, second data to said first application to alert that said first data has been stored in said secure element; and

[0062] (c) requesting, by said first application, said secure element to provide it with said first data.

[0063] According to one embodiment, the application is authorized to implement the NFC service through an interface software hosted by the processor and executing instructions transmitted by said application.

[0064] According to one embodiment, if the interface software does not comprise an authorization regarding said application, the interface software prohibits the application to request a key to the secure element during step (b).

[0065] According to one embodiment, the application is a system application, or

[0066] the application is a trusted application having received a permanent authorization to implement the NFC service, or

[0067] said application has received a temporary authorization to implement the NFC service, wherein said secure element communicates to the interface software a temporary authorization related to said application, said secure element having obtained this temporary authorization from an external server.

[0068] According to one embodiment, said second data represents said first data.

[0069] According to one embodiment, said second data is random data.

[0070] According to one embodiment, said secure element encrypts said first data.

[0071] According to one embodiment, said first data is encrypted using an asymmetric cryptographic algorithm.

[0072] According to one embodiment, if the application is not authorized to implement the NFC service, during step (b), the secure element refuses to send the first data to said application.

[0073] According to one embodiment, the NFC service is a service implemented by a near field communication method.

[0074] According to one embodiment, the NFC service is a service for which the terminal and the remote module can exchange third secret data.

[0075] According to one embodiment, the NFC service is a banking service.

[0076] According to one embodiment, step (a) is preceded by a step (d) during which the near field communication module is able to detect that the data is critical data.

[0077] According to one embodiment, step (a) is preceded by a step (d) during which the near field communication module detects that the first data comprises critical data.

[0078] Another embodiment provides a system comprising the terminal and the remote module previously described.

[0079] According to a fourth aspect, there is provided a method for implementing a NFC service between a mobile terminal and a remote module, said terminal comprising a processor hosting an application of an interface software that establishes a NFC service and executes instructions of said application, a near field communication module and a secure element distinct from said processor, the method comprising the following successive steps:

[0080] (a) said application requests authorization to the secure element to implement a NFC service and the interface software verifies whether said application is authorized to communicate with the secure element;

[0081] (b) said secure element sends to said interface software a first temporary authorization; and

[0082] (c) upon reception by said near field communication module of first data from said remote module, said interface software verifies at least once that it has received said first temporary authorization and, if so, said interface sends said first data to said application.

[0083] Another embodiment provides a mobile terminal adapted to implement an NFC service with a remote module, the terminal comprising a processor hosting an application of interface software that establishes the NFC service and executes instructions of said application, a near field communication module and a secure element distinct from the processor, the method of implementing the NFC service comprising the following successive steps:

[0084] (a) the application requests to the secure element an authorization to implement the NFC service;

[0085] (b) the secure element sends to the interface software a first temporary authorization; and

[0086] (c) at least a first time when the near field communication module receives first data from the remote module, the interface software verifies whether it has received the first temporary authorization.

[0087] According to one embodiment, the interface software is a main interface layer, which is a software interface that receives instructions directly from the application and converts these instructions into a series of instructions adapted to drive different software of the circuits and components of the terminal.

[0088] According to one embodiment, the interface software is a software control layer, comprising software that drives the circuits and components of the terminal.

[0089] According to one embodiment, the application is authorized to implement the NFC service through a filter interface software, which forms part of the interface software.

[0090] According to one embodiment, the application is a system application.

[0091] According to one embodiment, the application is a trusted application that has received a permanent authorization to implement the NFC service.

[0092] According to one embodiment, the application has received a second temporary authorization to implement the NFC service.

[0093] According to one embodiment, the secure element communicates to a filter interface software, which forms part of the interface software, a second temporary authorization relating to the application, which the secure element has obtained from an external server.

[0094] According to one embodiment, if the secure element does not give the first authorization to the interface software, the interface software does not send first data to the application during step (c).

[0095] According to one embodiment, the NFC service is a service implemented by a near field communication method.

[0096] According to one embodiment, the NFC service is a service in which third secret data can be exchanged between the terminal and the remote module.

[0097] According to one embodiment, the NFC service is a banking service.

[0098] Another embodiment provides a system comprising the terminal and the remote module described above. BRIEF DESCRIPTION OF DRAWINGS

[0099] The above features and advantages and other features and advantages are described in the detailed description which follows in reference to the drawings, in which:

[0100] Figure 1 Embodiments of the NFC service are shown very schematically in block form;

[0101] Figure 2 Embodiments of a mobile terminal capable of implementing the NFC service embodiments are shown very schematically in block form;

[0102] Figure 3 A block diagram showing the NFC service embodiment is shown;

[0103] Figure 4 A block diagram showing another embodiment of the NFC service is shown;

[0104] Figure 5 A block diagram showing another embodiment of the NFC service is shown;

[0105] Figure 6 A block diagram showing another embodiment of the NFC service is shown; and

[0106] Figure 7 A block diagram showing another embodiment of the NFC service is shown. DETAILED DESCRIPTION

[0107] In the different figures, similar features are denoted by similar reference signs. In particular, structural and / or functional features common to the various embodiments can have the same reference and can have the same structural, dimensional and material properties.

[0108] For the sake of clarity, only steps and elements useful for an understanding of the embodiments described herein are described and detailed. In particular, details of data exchanged during the NFC service of the type described below are not described. Different NFC communication protocols specific to the type of NFC service described are within the capabilities of the skilled person and are compatible with the embodiments described below.

[0109] Unless otherwise stated, when reference is made to two elements being connected together, it means a direct connection between the conductors, without any intermediate element, and when reference is made to two elements being connected together, it means that the two elements can be connected, or can be connected through one or more other elements.

[0110] In the following disclosure, unless otherwise specified, when reference is made to absolute position qualifiers, such as the terms "front", "back", "upper", "lower", "left", "right", etc., or to relative position qualifiers, such as "above", "below", "upper" and "lower", etc., or to direction qualifiers, such as "horizontal", "vertical", etc., reference is made to the orientation shown in the figures.

[0111] Unless otherwise specified, "around", "approximately", "substantially" and "of the order of" mean within 10%, preferably within 5%.

[0112] Figure 1 The NFC transaction between the electronic device 101 (TERM) acting as a mobile terminal or mobile terminal 101 and the electronic device 103 (CARD) acting as a remote module or remote module 103 is very schematically illustrated in the form of blocks.

[0113] The transaction is referred to here as a specific communication intended to carry out a commercial and / or monetary operation, in which one device (terminal 101) is the "paying" terminal that implements the transaction, and the other device, i.e. the remote module 103, is the device that accepts or does not accept the transaction. An example of a transaction to which the embodiments described below relate is a banking transaction. Another example of a related transaction is the purchase of a transport ticket. Other types of transactions can be envisaged, the two examples mentioned above not being limiting. The NFC transaction referred to here is in particular a transaction in which the two devices exchange critical and / or secret data.

[0114] The NFC transaction is a wireless and contactless communication implemented using near field technology (hereinafter NFC communication). Near field communication (NFC) technology enables short-range high frequency communication. Such a system uses a radio frequency electromagnetic field emitted by a device (terminal or reader) to communicate with another device (remote module, transponder or card).

[0115] The case of two electronic devices (for example terminal 101 and remote module 103) is assumed, however, all the cases that will be described more generally apply to any system that detects the electromagnetic field radiated by a reader or terminal. In this type of communication, the electronic devices 101 and 103 are positioned within range of each other, i.e. at a distance usually shorter than 10 cm. According to another example, the devices 101 and 103 are in mechanical contact with each other.

[0116] According to the application, for NFC communication, one of the devices (terminal 101) operates in a so-called reader mode, while the other remote module 103 operates in a so-called card mode, or both devices communicate in peer-to-peer mode (P2P). Each device comprises various electronic circuits 105 (NFC) adapted to emit radio frequency (RF) signals emitted by means of an antenna of an oscillation / resonance circuit. The radio frequency field generated by one of the devices (for example, terminal 101) is detected by the other device (for example, remote module 103) which is within its range and also comprises an antenna. When the terminal 101 emits an electromagnetic field to initiate communication with the remote module 103, it is captured by the remote module 103 as soon as the field is within its range. The field is detected by the circuits 105 of the remote module 103, which are reactivated if they are in a standby state. This results in a change in the load formed by the circuits 105 of the remote module 103 on the resonance circuit used to generate the field of the terminal 101. In practice, the terminal 101 detects a corresponding phase or amplitude change in the emitted field and then initiates a protocol for NFC communication with the remote module 103. On the side of the terminal 101, in practice, it is detected whether the amplitude of the voltage across the resonance circuit is reduced below a threshold value, or whether the voltage across the resonance circuit exhibits a phase shift greater than a threshold value. Once the terminal 101 detects the presence of the remote module 103 in its field, it begins the process of establishing communication, implementing a request transmission by the terminal 101 and a response transmission by the remote module 103. The request transmission and the response transmission will be described in further detail in Figures 3 to 7

[0117] The terminal 101 is an electronic device, for example, which can be fixed or mobile. The terminal 101 is responsible for initiating communication. By way of example, the terminal 101 is an electronic device adapted to implement a business application as a business. According to a more detailed example, the terminal 101 is a cellular telephone, for example a smartphone, implementing a point-of-sale (POS) application, i.e. an application which enables it to implement a business as a terminal. According to another example, the terminal 101 can be a connected device, for example a smartwatch, adapted to implement near field communication, more specifically NFC communication.

[0118] The remote module 103 is generally a mobile device. According to a preferred embodiment, the remote module 103 is a microcircuit card (or chip card), for example a bank card or a transport card. By way of variant, the remote module 103 can be a cellular telephone. The remote module 103 comprises different electronic circuits adapted to implement various instructions sent by the terminal 101, for example authentication circuits, cryptographic circuits, etc.

[0119] ​In the existing systems, the same NFC device can operate in card mode or reader mode (for example, in the case of near field communication between two cellular telephones) and can choose whether it operates in card mode or in reader mode depending on the case. According to one example, the module 101 can be used as a reader or terminal implementing a payment service and, in another case, as a card, for example, for validating a transport ticket.

[0120] Figure 2 An embodiment of an NFC service between the terminal device 201 (terminal) or the terminal 201 and the remote module 203 (CARD) is further shown in block form, this NFC service type being the same as the one described in Figure 1 Figure 2 The hardware (solid lines) and software (dashed lines) structure of the terminal 201 is further detailed, the remote module 203 being the same as the remote module 103 described in Figure 1

[0121] The terminal 201 comprises at least:

[0122] - a processor 2011 (APP PROC);

[0123] - a secure element (SE) 2012; and

[0124] - a near field communication module (NFC) 2013.

[0125] The processor 2011 is a processor, in particular adapted to implement the software architecture of the terminal 201, which will be described hereafter.

[0126] The secure element 2012 is a secure circuit or component, for example, a processor or a computing unit, adapted to manipulate secret or confidential data. The secure element is distinct from the processor 2011. The secure element 2012 can for example implement algorithms of authentication, data encryption and / or decryption, encryption and / or decryption key generation, etc. According to one example, the secure element 2012 is an embedded secure element in the terminal 201, but according to a variant, the secure element 12 can be an integrated secure element to the terminal 203. The advantage of having an embedded or integrated secure element is that it makes it possible to have a high level of protection since the secure element forms part of the device 100. According to another variant, the secure element 2012 can form part of a secure platform, or the secure element 2012 can be combined with the processor 2011 while benefiting from a hardware part physically isolating it from the processor 2011, for example, by using a TrustZone type technology. The level of protection of the latter two variants is lower than the former two variants. According to one embodiment, the secure element 2012 is able to know whether the NFC service is a service in which critical information and data can be exchanged. ​​

[0127] The NFC module 2013, or NFC module 2013, is a component of circuitry and one or more antennas that enables the terminal 201 to implement near field communication, in particular Figure 1 NFC transactions of the type described. Thus, the NFC module is able to send and receive data, as described with respect to Figure 1 the circuitry 105. According to one embodiment, the NFC module is able to detect that the data is critical data, for example, by verifying the type of instruction sent and the type of response subsequently received, for example, based on a lookup table stored in the NFC module 2013, or, for example, by counting the number of instructions according to the selection of the application (or selection of the response). The NFC module can combine both methods.

[0128] The three elements are adapted to communicate by different communication means. According to one example, the processor 2011 is adapted to communicate with the NFC module 2013, for example, via a bus of the I2C (Inter-Integrated Circuit) type, of the SPI (Serial Peripheral Interface) type or of the UART (Universal Asynchronous Receiver Transmitter) type. According to one example, the processor 2011 is adapted to communicate with the secure element 2012, for example, via a bus of the I2C (Inter-Integrated Circuit) type or of the SPI (Serial Peripheral Interface) type. According to one example, the secure element 2012 is adapted to communicate with the NFC module 2013, for example, by using a communication protocol of the HCI (Host Controller Interface) type or of the CLT (Contactless) type, by using a communication mechanism of the IPC (Inter-Process Communication) type, via a shared data memory. To communicate together, the secure element 2012 and the NFC module 2013 can for example use a communication protocol of the VNP (VPP Network Protocol, VPP standing for Virtual Primary Platform) type, such a protocol can be used with a bus of the I2C type or of the SPI type.

[0129] In addition, the terminal 201, in particular the processor 2011, is adapted to implement different types of software enabling it to perform different functions, including, more particularly, different applications and a plurality of interface software layers 2016 (platforms) enabling a user to implement different functions, or an interface software 2016 enabling the instructions sent by an application to be converted into instructions interpretable by different circuitry and components of the terminal 201, such as the secure element 2012 and the NFC module 2013.

[0130] In Figure 1 , the terminal 201 is adapted to implement at least one application 2014 (mPOS App) having as a terminal implementation Figure 1The functionalities of the NFC services of the type. The application 2014 can be a point-of-sale type application. According to an example, the terminal 201 can implement one or more other applications 2015 (application 2). In this specification, an "application" means a software whose operation is accessible to a user of the terminal 201. To implement different functionalities of the terminal 201, the applications are adapted to use the various circuits and components of the terminal 201 by sending instructions to the interface software layer 2016.

[0131] The interface software layer 2016 comprises:

[0132] - a main interface layer 2017 (API);

[0133] - a filter layer 2018 (OMAPI); and

[0134] - a layer for controlling 2019 (DRIVERS) the circuits and components of the terminal 201.

[0135] The main interface layer 2017 is a software interface that receives directly from the applications 2014 and 2015 the operation commands to be executed and that converts these operations into a series of instructions suitable for the different circuits and components of the terminal 201. In other words, if an application sends a command to execute an operation that requests the use of several of the circuits or components of the terminal 201, the interface 2017 converts that command into a set of instructions. The operation can be executed by implementing one or more of the instructions intended for one or more circuits or components of the terminal 201.

[0136] The filter layer 2018 is a software filter interface adapted to authorize, limit or prohibit the use of all or part of one or more circuits or components of the terminal 201 by an application, such as the applications 2014 and 2015. In other words, the filter layer 2018 receives the instructions sent by the interface 2017 and decides whether to send them or not, depending on the application that formulated the initial instructions. The filter layer 2018 can authorize or not authorize access to the circuits and components of the terminal 201 for an application based on different criteria. According to an example, the filter layer 2018 can authorize access to one or a part of the circuits or components of the terminal 201 for a first application and deny access for a second application.

[0137] According to a first example, if the application is a system application, i.e. an application generated by the manufacturer of the terminal 201 or of the interface software layer 2016 or of the designer, this application can have a permanent authorization to access all the circuits or components, or only the circuits and components chosen by the manufacturer, and at least an authorization to implement an NFC service. Moreover, conversely, a system application can have limited permanent or non-permanent access rights to all or part of one or more circuits or components of the terminal 201. Thus, certain parts of circuits or components, or certain circuits or components of the terminal 201 can be accessible only to system applications, and an application not meeting this criterion will systematically receive a refusal each time it attempts to send an instruction to these circuit parts or components or circuits or components.

[0138] According to a second example, the application can be a reliable application that has passed different reliability tests than the manufacturer of the terminal 201 or of the interface software layer 2016 or of the designer, and thus this manufacturer or designer authorizes it permanently to access all or part of the circuits or components of the terminal 201. According to one example, the application has at least an authorization to implement an NFC service. This type of reliable application can be considered as a system application and thus has the same characteristics.

[0139] According to a third example, the application can periodically authenticate with a server external to the terminal 201 to obtain a temporary authorization to access all or part of the circuits and components of the terminal 201. According to one example, the application has at least a temporary authorization to implement an NFC service. In the following description, it can be said that the application is authorized to access such a circuit or such a component of the terminal 201, the filter layer 2018 authorizing it. According to one example, the authorization for temporary access to the circuits and components of the terminal 201 can be held by the interface software 2016, for example by the filter interface 2018, the interface software 2016 being for example adapted to implement the authentication of the application with the external server.

[0140] According to a fourth example, a circuit or component of the terminal 201, for example the secure element 2012, can be adapted to determine which applications have an authorization to implement one or more of its functions. The circuit or component of the terminal 201 can for example provide the filter layer 2018 with a list indicating which application is authorized to implement one or more of its functions. According to one variant, this circuit or component can communicate temporary authorizations to all or part of the applications, for example by authorizing a number of uses of one or more of its functions. The filter layer 2018 applies these authorizations when an application sends a command to use one function or more functions of one or more circuits or components of the terminal 201. According to a preferred example, the secure element 2012 comprises a list of rules, for example stored in a memory, indicating the authorizations of the different applications implemented by the terminal 201.

[0141] The control layer 2019 of the circuits and components of the terminal 201 is the general software for controlling the circuits and components 201, i.e. the software that drives the lines and components of the terminal 201. In other words, the control layer 2019 is simply the set of programs capable of implementing the instructions delivered by the interface 2017. Each circuit or component is associated with the control software adapted to implement it. This control software is generally called driver software or "driver".

[0142] Figure 3 is a block diagram illustrating Figure 1 the implementation method of the NFC service of the type of NFC service or the implementation mode steps of the implementation method. These steps are performed by Figure 2 the terminal 201 and the remote module 203.

[0143] At the initial step 301 (application -> NFC cmd1), the application 2014 of the terminal 201 decides to carry out an NFC service with the remote module 203. To do this, the application 2014, once the communication has been established (for example, according to the anti-collision standard defined by the NFC Forum or ISO 14443 or any other protocol defined by the NFC module 2013), needs to send a first instruction cmd1 to the remote module 203 by using the NFC module 2013. The application 2014 then sends a request to the interface software layer 2016 to send the instruction cmd1 to the remote module 203 using the NFC component 2013, since this operation is not a critical operation a priori, the filtering layer 2018 authorizes this operation.

[0144] At step 302 (NFC -> CARD cmd1), following step 301, the NFC module has received the instruction cmd1 to be sent to the remote module 203 and sends this instruction by using a near field communication protocol of the type described above.

[0145] At step 303 (CARD -> NFC ans1), following step 302, the remote module 203 has received and processed the instruction cmd1 and sends a response ans1 to the NFC module 2013 of the terminal 201. This response ans1 can contain critical data. According to one example, if the NFC service is a banking service, critical banking data can form part of the response ans1, for example identification data or data capable of identifying the user. According to the embodiment, the NFC module 2013 is capable of determining whether the data included in the response ans1 is critical data or not, according to the type of NFC service implemented. For example, when the NFC module detects that the NFC service is a banking service, it is capable of understanding that the data exchanged is critical data.

[0146] In step 304 (NFC -> SE key 1) implemented in parallel with operation 301, 302 or 303, the NFC module 2013 asks the secure element 2012 to deliver to it an encryption key. The NFC module can for example send a specific instruction to request the key from the secure element. The NFC module 2013 and the secure element 2012 having a direct communication line, the secure element 2012 delivers the cryptographic key keyl to the NFC module 2012 as previously described. According to one example, the NFC module 13 is able to allocate a communication channel as defined in the HCI standard.

[0147] In step 305 (NFC encrypt), following step 303, the NFC module 2013 having received the answer ans 1 from the remote module 203 and the cryptographic key keyl from the secure element can encrypt the answer ans 1 using the cryptographic key key2 to obtain an encrypted answer e(ansl). Thus, the critical data of the answer ans 1 is cryptographically protected.

[0148] In step 306 (NFC -> App e(ansl)), following step 305, the NFC module 2013 sends the encrypted answer e(ansl) to the application 2014.

[0149] In step 307 (App -> SE key?), following step 306, the application 2014 receives the encrypted answer e(ansl) and cannot read it nor interpret it without decrypting it. Thus, the application 2014 sends to the secure element 2012 a decryption key. This operation is a critical operation, the filter interface 2018 verifies whether the application 2014 is authorized to send this request to the secure element 2012. If the application 2014 is authorized (output Y), the next step is step 308 (App decrypt), otherwise (output N), the next step is step 309 (App error).

[0150] In step 308, the application 2014 is authorized, the secure element 2012 provides to it a decryption key, for example the key keyl if it is a cryptographic and decryption key, or a decryption key different from the key keyl. The application 2014 can then decrypt the answer ans 1.

[0151] At step 310 (continuation of the service), following step 308, the application 2014 can continue to send instructions and receive answers from the remote module 203 by using the same previously described mechanism, by using a different password and / or decryption key for each answer received from the remote module 203, the same password key being usable for each answer received from the remote module 203 to speed up the service. In this case, at the end of the service, the password key can become inefficient, for example, by being suppressed or invalidated. The end of the service can be considered when there is no new instruction for a determined period of time, for example, a period of time of the order of 500 ms or 1 s, or, for example, when the remote module is no longer in the range of the terminal, or if an application different from the application 2014 is launched. According to a variant, the NFC module can also determine that the NFC service no longer comprises critical data according to a given period of time or a particular instruction, so as to stop encrypting the exchanged data.

[0152] At step 309, the application 2014 has been identified as not being authorized by the filter interface 2018, the secure element 2012 not delivering to it the decryption key. Thus, the application 2014 is unable to decrypt the answer. By being identified as not authorized, the application 2014 will not have access to the critical data of the NFC service.

[0153] At step 311 (stop of the service), following step 309, the application 2014 is unable to execute the NFC service since it has no access to the critical and / or secret data, the NFC service stopping itself.

[0154] One advantage of this embodiment is that an application not authorized by the filter interface 2018 cannot access the critical data sent by the remote module, since these data remain encrypted using a key that the application has no access to.

[0155] Figure 4 is a description Figure 1 of the implementation method of the NFC service of the said NFC service type or of the implementation mode steps of the implementation method. These steps are performed by Figure 2 the terminal 201 and the remote module 203 described.

[0156] In an initial step 401 (App -> NFC cmd2), the application 2014 of the terminal 201 decides to perform an NFC service with the remote module 203. To this end, the application 2014 needs to send a first instruction cmd2 to the remote module 203 using the NFC module 2013 once the communication is established (for example according to the anti-collision standard defined by the NFC Forum or ISO 14443 or any other protocol defined by the NFC module 2013 implementation). Then, the application 2014 sends a request to the interface software layer 2016 to send the instruction cmd2 to the remote module 204 using the NFC component, since this operation is not a critical operation beforehand, the filtering layer 2018 authorizes this operation.

[0157] In a step 402 (NFC -> CARD cmd2), following step 401, the NFC module 2013 has received the instruction cmd2 to send to the remote module 203 and sends this instruction by using a near field communication protocol of the type described above.

[0158] In a step 403 (CARD -> NFC ans2), following step 402, the remote module 203 has received and processed the instruction cmd2 and sends a response ans2 to the NFC module 2013 of the terminal 201. This response ans2 can contain critical data, like the response ansl described in the Figure 3

[0159] In a step 404 (NFC -> SE ans2), following step 403, the NFC module 2013 sends the response ans2 to the secure element 2012 in order for the secure element to encrypt it. For example, step 404 can be optimized if the NFC module 2013 is able to detect critical data in the data of the response ans2, the NFC module can then require the secure element to encrypt only the critical information in the response ans2. According to a variant, the NFC module sends the response ans2 to the secure element and the secure element selects the critical information to encrypt from the response ans2 data.

[0160] In a step 405 (SE encryption), following step 404, the secure element 2012 encrypts the response ans2 by using a secret cryptographic key known only to it, to obtain an encrypted response e(ans2). Thus, the critical data of the response ans2 is protected by encryption.

[0161] In a step 406 (SE -> NFC -> Appe(ans2)), following step 405, the secure element 2012 returns the encrypted response e(ansl) to the NFC module 2013. Then, the NFC module 2013 sends the encrypted response e(ans2) to the application 2014.

[0162] ​At step 407 (App -> SE decryption?), after step 406, the application 2014 receives the encrypted answer e(ans2) and cannot read it without decrypting it. Therefore, the application 2014 sends a decryption request to the secure element 2012. This operation is a critical operation, the filter interface 2018 verifies whether the application 2014 is authorized to send this request to the secure element 2014. If the application 2014 is authorized (output Y), the next step is step 408 (SE -> App decryption), otherwise (output N), the next step is step 409 (App error).

[0163] At step 408, the application 2014 is authorized to communicate with the secure element, it requests the secure element 2012 to decrypt the answer e(ans2). The latter performs this decryption and sends the answer ans2 to the application 2014. According to another embodiment, the application 2014 can request the decryption key from the secure element and decrypt the data itself.

[0164] At step 410 (Business continues), after step 408, the application 2014 can continue to send instructions and receive answers from the remote module 202 by using the same mechanism previously described, i.e. by having each answer received from the remote module 203 encrypted by the secure element 2012, a single encryption can be performed on the first answer received from the remote module 203 to speed up the business.

[0165] At step 409, the application 2014 is identified as unauthorized. Therefore, the application 2014 cannot decrypt the answer e(ans2). By being identified as unauthorized, the application 2014 will not have access to the critical data of the NFC business.

[0166] At step 411 (Business stops) after step 409, the NFC business stops itself since the application 2014 cannot access the critical and / or secret data, the application 2014 cannot perform the NFC business.

[0167] The advantage of this embodiment is that an application that has not been authorized by the filter interface 2018 cannot access the critical data sent by the remote module.

[0168] Another advantage of this embodiment is that the management of the decryption key is the responsibility of the secure element 2012. Therefore, the secure element can choose the decryption key to use, use only the same key, or change the key frequently as needed.

[0169] Figure 5 is a description Figure 1 of the implementation method of the NFC business of the said NFC business type or of the implementation mode steps of the implementation method. These steps are performed by Figure 2 the terminal 201 and the remote module 203 described.

[0170] At an initial step 501 (App -> NFC cmd3), the application 2014 of the terminal 201 decides to implement an NFC service with the remote module 203. To do so, the application 2014 needs to send a first instruction cmd3 to the remote module 203 by using the NFC module 2013, once the communication is established (for example according to the anti-collision standard defined by the NFC Forum or ISO 14443 or any other protocol defined by the NFC module 2013). The application 2014 then sends a request to the interface software layer 2016 to send the instruction cmd3 to the remote module 204 using the NFC component, since this operation is not a critical operation beforehand, the filtering layer 2018 authorizes this operation.

[0171] At a step 502 (NFC -> CARD cmd3), following step 501, the NFC module 2013 has received the instruction cmd3 to send to the remote module 203 and sends this instruction by using a near field communication protocol of the type described above.

[0172] At a step 503 (CARD -> NFC ans3), following step 502, the remote module 203 has received and processed the instruction cmd3 and provides a reply ans3 to the NFC module 2013 of the terminal 201. This reply ans3 can contain critical data, like the reply ansl described in the method of the application. Figure 3

[0173] At a step 504 (NFC -> SE ans3), following step 503, the NFC module 2013 sends the reply ans3 to the secure element 2012 so that the secure element stores the reply ans3. According to a variant, the secure element 2012 can store the reply ans3 and apply a cryptographic method to it, for example an asymmetric cryptographic method. According to another variant, the NFC module 2013 sends the reply ans3 to the secure element 2012 and if the secure element 2012 detects that some data of the reply ans3 are critical data, the secure element 2012 can store these data and remove them from the reply ans3 or replace them with other data before returning the reply ans3 to the NFC module 2012.

[0174] At a step 505 (NFC Subs), following step 503, the NFC module prepares data s(ans3) to send to the application 2014 so that it is aware that the remote module 203 has sent a reply ans3. These data s(ans3) can be data depending on the reply ans3, for example a truncated reply ans3, or a ciphered or signed reply ans3, or data independent of the reply ans3, for example random or typical data indicating to the application 2014 that a reply has been received.

[0175] ​At step 506 (NFC -> application (ans3)), following step 505, the NFC module 2013 sends the data s (ans2) to the application 2014.

[0176] At step 507 (application -> SE ans3?), following step 506, the application 2014 receives the data s (ans3) and understands that it must request the answer ans3 from the secure element 2012. Thus, the application 14 sends a decryption request to the secure element 12. This operation is a critical operation, the filter interface 2018 verifies whether the application 2014 is authorized to send this request to the secure element 2012. If the application 2014 is authorized (output Y), the next step is step 508 (SE -> application decryption), otherwise (output N), the next step is step 509 (application error).

[0177] At step 508, the application 2014 being authorized to communicate with the secure element 2012, it requests the answer ans3 from the secure element 2012. The latter sends the answer ans3 to the application 2014, according to a variant, if the answer ans3 has been encrypted by the secure element 2012, the application 2014 can request the decryption of the answer ans3 from the secure element 2012 or decrypt it itself. In the second case, it is considered that a password and / or a decryption key has been exchanged before implementing the NFC service to establish a common secret. A technique of the Diffie-Hellman type technique type can also be used here.

[0178] At step 510 (service continues), following step 508, the application 2014 can continue to send instructions and receive answers from the remote module 202 by storing each answer received from the remote module 203 in the secure element 2012, using the same mechanism previously described. According to a variant, a single storage can be performed on the first answer received from the remote module 203 to speed up the service.

[0179] At step 509, the application 2014 is identified as unauthorized. Thus, the application 2014 cannot receive the answer ans3, whether it is encrypted or not. By being identified as unauthorized, the application 2014 will not have access to the critical data of the NFC service.

[0180] At step 511 (service stops), following step 509, since the application 2014 cannot access the critical and / or secret data, the application 2014 cannot perform the NFC service, which stops itself.

[0181] The advantage of this embodiment is that an application that has not been authorized by the filter interface 2018 cannot access the critical data sent by the remote module.

[0182] Figure 6 is a description Figure 1a block diagram of the implementation method or of the implementation mode steps of the NFC service of said NFC service type. These steps are performed by Figure 2 Said terminal 201 and remote module 203 are implemented.

[0183] At initial step 601 (App -> API Req Trans), the application 2014 of the terminal 201 decides to implement an NFC service with the remote module 203. To this end, the application 2014 sends an authorization request to the host interface layer 2017. This request can for example be a request comprising an authentication of the application 2014 to the secure element 2012. This request can for example comprise data related to the type of NFC service authorized to be implemented by the application, which enables the secure element to filter the type of NFC service implemented by the application.

[0184] At step 602 (API -> SE Service?), following step 601, the host interface layer 2017 sends the request to the filter interface which verifies whether the application is authorized to send to the secure element 2012. If the application 2014 is authorized (output Y), the next step is step 603 (SE -> API evt4), otherwise (output N), the next step is step 604 (application error).

[0185] At step 604, the application 2014 has been identified as unauthorized and will therefore not be able to implement a service. The host interface layer 2017 can for example prevent any service initiation request originating from the application 2014, or can for example detect the presence of critical data, as described below.

[0186] At step 603, following step 602, the secure element 2012 sends an instruction evt4 or a temporary authorization evt4 to the host interface layer 2017, according to which the application 2014 can implement an NFC service. This instruction evt4 can for example relate to a single NFC service of the application 2014, to a plurality of successive NFC services or to all the NFC services of the application 2014. In practice, the instruction evt4 can be a software event.

[0187] At step 605 (App -> NFC cmd4), in succession with step 603, but possibly in direct succession with step 601, the application 2014 decides to implement an NFC service with the remote module 203. The application 2014 then sends a request to the interface software layer 2016 to send an instruction cmd4 to the remote module 203 using the NFC module 2013. Since this operation is not a critical operation a priori, the host interface layer 2017 authorizes this operation.

[0188] At step 606 (NFC->CARD cmd4), following step 605, the NFC module 2013 has received the instruction cmd4 to be sent to the remote module 203 and sends this instruction by using the type of near field communication protocol described above.

[0189] At step 607 (CARD->NFC ans4), following step 606, the remote module 203 has received and processed the instruction cmd4 and sends the answer ans4 to the NFC module 2013 of the terminal 201. This answer ans4 can contain critical data, like the answer ans1 described in the Figure 3

[0190] At step 608 (NFC->API ans4), following step 607, the NFC module 2013 sends the answer ans4 to the application 2014, but this sending is intercepted by the host interface layer 2017.

[0191] At step 609 (API->evt4?), following step 608, the instruction evt4 received by the host interface layer 2017 is implemented. If the instruction evt4 authorizes the application to implement an NFC service (output Y), the next step is step 610 (API->App ans4), otherwise (output N), the next step is step 611 (App error). The sending of the instruction evt4 can be for example the sending of a software event of the type of service, for example defined by the HCI standard, which is performed by a dedicated communication channel coupling the secure element 2012 and the processor 2011

[0192] - the application is authorized to perform an NFC service;

[0193] - the type of the relevant NFC service; and / or

[0194] - the number of NFC services the application is authorized to implement.

[0195] According to one example, the application 2014 can be authorized to implement two NFC services of the bank type.

[0196] At step 610, the application 2014 is authorized to communicate with the secure element, to which the host interface layer 2017 sends the answer ans4.

[0197] ​At step 612 (service continues), following step 610, the application 2014 can continue to send instructions and receive answers from the remote module 203 by using the same mechanisms previously described. According to a variant, the host interface layer 2017 can verify for each exchange whether the application 2014 is authorized to implement the NFC service, or the host interface layer 17 can consider that the authorization of the instruction evt4 is valid until the end of the ongoing NFC service or for a predetermined period of time, or also according to parameters included in the instruction evt4.

[0198] At step 611, the application 2014 has been identified as unauthorized and therefore not authorized to receive the answer ans4. By being identified as non-authorized, the application 14 will not have access to the critical data of the NFC service.

[0199] At step 613 (service stops), following step 611, since the application 2014 cannot access the critical and / or secret data, the application 2014 cannot execute the NFC service, which stops by itself.

[0200] The advantage of this embodiment is that an application that has not been authorized by the filter interface 2018 cannot access the critical data sent by the remote module.

[0201] Figure 7 is a description Figure 1 of the implementation method of the NFC service of the type of NFC service or of the implementation mode steps of the implementation method. These steps are performed by Figure 2 the terminal 201 and the remote module 203 described.

[0202] Figure 7 the implementation mode of Figure 6 is similar to the implementation mode described in Figure 7 . The difference between these two implementations is that, in , it is not the host interface layer 2017 that verifies whether the application is authorized to implement the NFC service, but the control layer 2019 of the circuits and components of the terminal 201 that performs this verification. In this case, the method is as follows.

[0203] At initial step 701 (App->DRIVERS ReqTrans), the application 2014 of the terminal 201 decides to implement a NFC service with the remote module 203. To do this, the application 2014 sends a request to the control layer 2019. This request can for example be an authentication request with the secure element 2012. This request can for example include data related to the type of NFC service authorized to be implemented by the application.

[0204] At step 702 (NFC->CARD cmd5), following step 701, the control layer 2019 sends a request to the secure element 2012. If the application 2014 is authorized (output Y), the next step is step 703 (SE->DRIVER Sevt5), else (output N), the next step is step 704 (application error). According to an alternative embodiment, the verification of the authorization of the application 2014 is not performed at step 702 and the next step is directly step 703.

[0205] At step 704, the application 2014 has been identified as unauthorized and therefore cannot implement the service. For example, the control layer 2019 can prevent any request for the start of a service originating from the application 2014.

[0206] At step 703, following step 702, the secure element 2012 sends an instruction evt5 or a temporary authorization evt5 to the control layer 2019, according to which the application 2014 can implement the NFC service. For example, the instruction evt5 can relate to a single NFC service, to a plurality of successive NFC services or to all the NFC services of the application 2014. Indeed, the instruction evt5 can be a software event. The sending of the instruction evt4 can for example be the sending of a type of service software event, as defined by the HCI standard, which is performed through a dedicated communication channel coupling the secure element 2012 and the processor 2011. In this case, the instruction evt4 can comprise different parameter indications, for example:

[0207] - the application is authorized to perform the NFC service;

[0208] - the type of the related NFC service; and / or

[0209] - the number of NFC services the application is authorized to implement.

[0210] According to one example, the application 2014 can be authorized to implement two NFC services of the banking type.

[0211] At step 705 (application->NFC cmd5), in succession with step 703, but possibly in direct succession with step 701, the application 2014 decides to implement a NFC service with the remote module 203. The application 14 then sends a request to the interface software layer 2016 to send an instruction cmd5 to the remote module 203 using the NFC module 2013. Since this operation is not a critical operation a priori, the control layer 2019 authorizes this operation.

[0212] At step 706 (NFC->CARD cmd5), following step 705, the NFC module 2013 has received the instruction cmd5 to be sent to the remote module 203 and sends this instruction by using a near field communication protocol of the type described above.

[0213] At step 707 (CARD->NFCans5), following step 706, the remote module 203 has received and processed the instruction cmd5 and sends the answer ans5 to the NFC module 2013 of the terminal 201. This answer ans5 can contain critical data, as the answer ans1 described in the section Figure 3

[0214] At step 708 (NFC->DRIVERSans5), following step 707, the NFC module 2013 sends the answer ans5 to the application 2014, but this sending is intercepted by the control layer 2019 (DRIVERS).

[0215] At step 709 (DRIVERS->evt5?), following step 708, the instruction evt5 received by the control layer 2019 (DRIVERS) is executed. If the instruction evt5 authorizes the application to implement the NFC service (output Y), the next step is step 710 (DRIVERS->Appans5), otherwise (output N), the next step is step 711 (application error).

[0216] At step 710, the application 2014 is authorized to communicate with the secure element 2012 and the control layer 2018 sends it the answer ans5.

[0217] At step 712 (service continues), following step 710, the application 2014 can continue to send instructions and receive answers from the remote module 203 by using the same mechanisms previously described. According to a variant, the control layer 2019 can verify for each service that the application 2014 is authorized to implement the NFC service, or the control layer 2019 can consider that the authorization of the instruction evt5 is valid until the end of the NFC service in progress or for a predetermined period of time. The control layer 2019 (DRIVERS) can further use the parameters passed by the instruction evt4.

[0218] At step 711, the application 2014 has been identified as unauthorized and is therefore not authorized to receive the answer ans5. By being identified as unauthorized, the application 14 will not have access to the critical data of the NFC service.

[0219] At step 713 (service stops), following step 711, the NFC service stops itself since the application 2014 cannot access the critical and / or secret data and the application 2014 cannot therefore execute the NFC service.

[0220] One advantage of this embodiment is that an application that is not authorized by the control layer 2019 cannot access the critical data sent by the remote module, the authorization of the application initially coming from the secure element 2012. ​

[0221] Various embodiments and variants have been described. The person skilled in the art will understand that certain features of these different embodiments and variants can be combined, and that other variants will occur to the person skilled in the art. In particular, the terminal and the NFC module can implement these methods only for critical NFC services, i.e. services exchanging critical and / or secret data. The NFC module, the interface layer 2018 and the control layer 2019 can for example be able to distinguish whether a NFC service is critical or not. This distinction can be performed based on the context in which the service is implemented, based on instructions, based on a selection of a particular application or other.

[0222] Finally, the actual implementation of the embodiments and variants based on the functional indications given above is within the capabilities of the person skilled in the art.

[0223] While the application has been described with reference to illustrative embodiments, the description is not intended to be construed in a limiting sense. Various modifications and combinations of the illustrative embodiments, as well as other embodiments of the application, will be apparent to persons skilled in the art upon reference to the description. It is therefore intended that the appended claims encompass any such modifications or embodiments.

Claims

1. A method for implementing NFC services between a mobile terminal and a remote module, the terminal comprising: a processor hosting an application configured to establish the NFC service; a near field communication module; and a secure element distinct from the processor, the method comprising: storing, by the near field communication module, first data from the remote module in the secure element; detecting, by the secure element, a first part of the first data; replacing, by the secure element, the first part of the first data with other data to generate second data based on the detection before returning the first data to the near field communication module; sending, by the near field communication module, the second data to the application, thereby informing the application that the first data has been stored in the secure element; and requesting, by the application, the first data from the secure element.

2. The method of claim 1, further comprising: the application is authorized by an interface software to implement the NFC service, the interface software being a software hosted by the processor and executing instructions sent by the application.

3. The method of claim 2, wherein the application is a system application, or wherein the application is a trusted application having received a permanent authorization to implement the NFC service, or wherein the application has received a temporary authorization to implement the NFC service, wherein the secure element communicates the temporary authorization for the application to the interface software, the secure element having obtained this temporary authorization from an external server.

4. The method of claim 1, wherein the second data represents the first data.

5. The method of claim 1, wherein the second data is random data.

6. The method of claim 1, further comprising: the first data is encrypted by the secure element.

7. The method of claim 6, wherein the first data is encrypted with an asymmetric cryptography algorithm.

8. The method of claim 1, wherein the NFC service is a service during which the terminal and the remote module are likely to exchange secret data.

9. The method of claim 1, further comprising: detecting, by the near field communication module, that the first data is critical data before storing the first data by the near field communication module.

10. A mobile terminal comprising: a processor hosting an application configured to establish an NFC service with a remote module; a near field communication module; and a secure element distinct from the processor, wherein the near field communication module is configured to: store first data from the remote module in the secure element, and send second data to the application to inform the application that the first data has been stored in the secure element, wherein the secure element is configured to: detect a first part of the first data; and replace the first part of the first data with other data to generate second data based on the detection before returning the first data to the near field communication module; and wherein the application is configured to request the first data from the secure element.

11. The terminal of claim 10, further comprising an interface software hosted by the processor and configured to execute instructions from the application, wherein the interface software is configured to authorize the application to implement the NFC service. ​ ​ 12. The terminal according to claim 11, wherein the application is a system application, or wherein the application is a trusted application that has received a permanent authorization to implement the NFC service, or wherein the application has received a temporary authorization to implement the NFC service, wherein the secure element is configured to pass the temporary authorization for the application to the interface software, the secure element having obtained this temporary authorization from an external server.

13. The terminal according to claim 10, wherein the second data represents the first data.

14. The terminal according to claim 10, wherein the second data is random data.

15. The terminal according to claim 10, wherein the secure element is configured to encrypt the first data with an asymmetric cryptographic algorithm.

16. The terminal according to claim 10, wherein the NFC service is a service during which the terminal and the remote module are likely to exchange secret data.

17. The terminal according to claim 10, wherein the near field communication module is configured to detect that the first data is critical data before storing the first data.

18. A method for implementing NFC services between a mobile terminal and a remote module, the terminal comprising: a processor hosting an application and an interface software configured to establish the NFC service; a near field communication module; and a secure element distinct from the processor, the method comprising: storing, by the near field communication module, first data from the remote module in the secure element; detecting, by the secure element, a first part of the first data; replacing, by the secure element, the first part of the first data with other data to generate second data based on the detection before returning the first data to the near field communication module; sending, by the near field communication module, the second data to the application, thereby informing the application that the first data has been stored in the secure element; when the interface software does not have an authorization to the application, inhibiting, by the interface software, the application from requesting a key from the secure element; or requesting, by the application, the first data from the secure element; and when the interface software does not have an authorization to the application, denying, by the secure element, sending the first data to the application.

Citation Information

Patent Citations

  • werkwijze VOOR HET AFSCHEIDEN VAN ORGANIC FOSFORVERBINDINGEN EN / OF METAALCOMPLEXEN DAARVAN UIT EEN OPLOSSING ERVAN IN EEN ORGANIC DINITRILE.

    FR2113471A5

  • Method to send payment data through various air interfaces without compromising user data

    CN104603810A

  • Communications techniques for secure near field communication architecture

    CN105379171A