NFC services

By using a key provided by a secure element to encrypt and decrypt the near-field communication module in electronic devices, combined with interface software control, the security problem of data exchange in complex electronic devices is solved, achieving more reliable confidentiality and anonymity.

CN116264697BActive Publication Date: 2026-03-13STMICROELECTRONICS (ROUSSET) SAS +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-13
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

In complex electronic devices, the lack of effective protection measures when different modules of the same device exchange confidential and critical data leads to increased information security risks.

Method used

The near-field communication module is encrypted and decrypted using a key provided by a secure element, and data exchange is controlled through interface software to ensure that only authorized applications can access sensitive data.

Benefits of technology

It improves the confidentiality and anonymity of near-field communication, prevents unauthorized applications from accessing critical data, and enhances information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116264697B_ABST
    Figure CN116264697B_ABST
Patent Text Reader

Abstract

Embodiments of this disclosure relate to NFC services. In one embodiment, a method for implementing NFC services between a mobile terminal and a remote module is disclosed. The terminal includes a processor hosting an application configured to establish NFC services and interface software configured to execute instructions of the application, a near-field communication module, and a secure element distinct from the processor. The method includes the application requesting authorization to implement NFC services from the secure element via the interface software, the interface software verifying whether the application is authorized to communicate with the secure element, the secure element sending a first temporary authorization to the interface software, the near-field communication module determining, at least for the first time, whether the interface software has received the first temporary authorization when it receives first data from the remote module, and the interface software sending the first data to the application when it has received the first temporary authorization.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-references to related applications

[0002] This application claims the benefit of French patent application No. 2113476, filed on December 14, 2021, which is incorporated herein by reference. Technical Field

[0003] This disclosure generally relates to electronic devices, and more particularly to electronic devices suitable for processing confidential data. More specifically, this disclosure relates to electronic devices suitable for implementing Near Field Communication (NFC), particularly NFC services, wherein at least a portion of the data exchanged is confidential data and / or a portion of the exchanged data is critical data that allows, for example, methods of identifying or authenticating users. Background Technology

[0004] Complex electronic devices, such as telephones, tablets, and computers, have integrated increasingly more functions and are capable of implementing digital services for optimal integration into daily life over time. For example, some telephones, especially smartphones, integrate digital services such as banking payment services, or the use of public transportation tickets, event tickets, and authentication of users by remote systems (banks, public administration, etc.). To implement these functions, devices can integrate function-specific electronic components, such as security components that can maintain / store identification, reference, and authentication information (often referred to as "credentials") as well as digital service provider assets, motion sensors, near-field communication (NFC) modules, etc.

[0005] One challenge that comes with adding new features is the unprotected exchange of confidential and / or critical data between different modules of the same electronic device. Summary of the Invention

[0006] Various implementations provide more reliable near-field communication.

[0007] Various embodiments provide near-field communication with confidentiality and / or anonymity for users regarding these communications.

[0008] Various implementations provide more reliable NFC services.

[0009] Various embodiments provide NFC services that offer confidentiality and / or anonymity for users of these services.

[0010] Various embodiments overcome all or some of the drawbacks of known near-field communication.

[0011] Various implementations overcome all or some of the drawbacks of known NFC services.

[0012] Some embodiments provide a method for implementing NFC services between a mobile terminal and a remote module, the terminal including a processor hosting the establishment of an NFC service application, a near-field communication module, and a secure element different from the processor, the method comprising at least the following sequential steps:

[0013] (a) The near-field communication module encrypts the first data sent by the remote module using a first key provided by the security element; and

[0014] (b) The first application decrypts the first data by using a second key provided by the security element.

[0015] Another embodiment provides a mobile terminal suitable for implementing NFC services with a remote module. The terminal includes a processor hosting the establishment of NFC service applications, a near-field communication module, and a secure element distinct from the processor. The method for implementing NFC services includes at least the following sequential steps:

[0016] (a) The near-field communication module encrypts the first data sent by the remote module using a first key provided by the security element; and

[0017] (b) The first application decrypts the first data by using the first key provided by the security element.

[0018] According to one embodiment, the application is authorized to implement NFC services through interface software, which is hosted by a processor and executes instructions sent by the application.

[0019] According to one embodiment, the application is a system application.

[0020] According to one embodiment, the application is a reliable application that has received a perpetual license to implement NFC services.

[0021] According to one embodiment, the application has received a temporary authorization to implement NFC services.

[0022] According to one embodiment, the security element transmits a temporary authorization for the application to the interface software.

[0023] According to one embodiment, if the interface software does not include authorization for the application, then during step (b), the interface software prevents the application from requesting a key from the security element.

[0024] According to one embodiment, the secure element obtains temporary authorization from an external server.

[0025] According to one embodiment, the security element includes a list of rules that indicate the implementation of authorizations related to the application (if the device implements other applications) and other applications.

[0026] According to one embodiment, the first and second keys are the same.

[0027] According to one embodiment, if the application is not authorized to perform NFC services, during step (b), the secure element refuses to provide the second key to the application, and the application is unable to decrypt the first data.

[0028] According to one embodiment, NFC services are services implemented through near-field communication methods.

[0029] According to one embodiment, NFC service is a service in which a terminal and a remote module may exchange third key data.

[0030] According to one embodiment, NFC services are banking services.

[0031] According to one embodiment, step (c) precedes step (a), during which the near-field communication module is able to detect that the data is critical data.

[0032] According to one embodiment, step (c) precedes step (a), during which the near-field communication module detects that the first data includes key data.

[0033] Another embodiment provides a system including the terminal and remote module described above.

[0034] Some embodiments provide a method for implementing NFC services between a mobile terminal and a remote module, the terminal including a processor hosting the establishment of an NFC service application, a near-field communication module, and a secure element different from the processor, the method comprising at least the following sequential steps:

[0035] (a) The near-field communication module sends first data, which is sent by the remote module and encrypted by the security element, to the first application; and

[0036] (b) The first application requests the security element to decrypt the first data.

[0037] Another embodiment provides a mobile terminal suitable for implementing NFC services with a remote module. The terminal includes a processor hosting the establishment of NFC service applications, a near-field communication module, and a secure element different from the processor. The method for implementing NFC services includes at least the following sequential steps:

[0038] (a) The near-field communication module sends first data, which is sent by the remote module and encrypted by the security element, to the first application; and

[0039] (b) The first application requests the security element to decrypt the first data.

[0040] According to one embodiment, the application is authorized to implement NFC services through interface software, which is hosted by a processor and executes instructions sent by the application.

[0041] According to one embodiment, the application is a system application.

[0042] According to one embodiment, the application is a reliable application that has received a perpetual license to implement NFC services.

[0043] According to one embodiment, the application has received a temporary authorization to implement NFC services.

[0044] According to one embodiment, the security element transmits a temporary authorization for the application to the interface software.

[0045] According to one embodiment, if the interface software does not include authorization for the application, then during step (b), the interface software prevents the application from requesting a key from the security element.

[0046] According to one embodiment, the secure element obtains temporary authorization from an external server.

[0047] According to one embodiment, the security element includes a list of rules that indicate the implementation of authorizations related to the application and other applications (if the device implements other applications).

[0048] According to one embodiment, if the application is not authorized to perform NFC services, during step (b), the secure element refuses to decrypt the first data and send it to the application.

[0049] According to one embodiment, NFC services are services implemented through near-field communication methods.

[0050] According to one embodiment, NFC service is a service in which a terminal and a remote module may exchange third key data.

[0051] According to one embodiment, NFC services are banking services.

[0052] According to one embodiment, step (c) precedes step (a), during which the near-field communication module is able to detect that the data is critical data.

[0053] According to one embodiment, step (c) precedes step (a), during which the near-field communication module detects that the first data includes key data.

[0054] Another embodiment provides a system including the previously described terminal and remote module.

[0055] Other embodiments provide a method for implementing NFC services between a mobile terminal and a remote module, the terminal including a processor hosting the establishment of an NFC service application, a near-field communication module, and a secure element different from the processor, the method comprising at least the following sequential steps:

[0056] (a) The near-field communication module stores the first data sent by the remote module in the security element;

[0057] (b) The near-field communication module sends second data to the first application to warn that the first data has already been stored in the secure element; and

[0058] (c) The first application requests the security element to provide it with the first data.

[0059] Another embodiment provides a mobile terminal suitable for implementing NFC services with a remote module. The terminal includes a processor hosting the establishment of NFC service applications, a near-field communication module, and a secure element distinct from the processor. The method for implementing NFC services includes at least the following sequential steps:

[0060] (a) The near-field communication module stores the first data sent by the remote module in the security element;

[0061] (b) The near-field communication module sends second data to the first application to warn that the first data has already been stored in the secure element; and

[0062] (c) The first application requests the security element to provide it with the first data.

[0063] According to one embodiment, the application is authorized to implement NFC services through interface software, which is hosted by a processor and executes instructions sent by the application.

[0064] According to one embodiment, if the interface software does not include authorization for the application, then during step (b), the interface software prevents the application from requesting a key from the security element.

[0065] According to one embodiment, the application is a system application, or

[0066] This application is a reliable application that has received a perpetual license to implement NFC services, or

[0067] The application has received a temporary authorization to implement NFC services, wherein the secure element passes the temporary authorization related to the application to the interface software, and the secure element has obtained the temporary authorization from an external server.

[0068] According to one embodiment, the second data represents the first data.

[0069] According to one embodiment, the second data is random data.

[0070] According to one embodiment, the security element encrypts the first data.

[0071] According to one embodiment, the first data is encrypted using an asymmetric cryptographic algorithm.

[0072] According to one embodiment, if the application is not authorized to perform NFC services, the secure element refuses to send the first data to the application during step (b).

[0073] According to one embodiment, NFC services are services implemented through near-field communication methods.

[0074] According to one embodiment, NFC service is a service in which a terminal and a remote module may exchange third-party secret data.

[0075] According to one embodiment, NFC services are banking services.

[0076] According to one embodiment, step (d) precedes step (a), during which the near-field communication module is able to detect that the data is critical data.

[0077] According to one embodiment, step (d) precedes step (a), during which the near-field communication module detects that the first data includes key data.

[0078] Another embodiment provides a system including the previously described terminal and remote module.

[0079] Other embodiments provide a method for implementing NFC services between a mobile terminal and a remote module, the terminal including a processor for an application hosting interface software for establishing NFC services and executing instructions of the application, a near-field communication module, and a security element different from the processor, the method comprising the following sequential steps:

[0080] (a) The application requests authorization from the secure element to perform NFC services, and the interface software verifies whether the application is authorized to communicate with the secure element;

[0081] (b) The security element sends a first temporary authorization to the interface software; and

[0082] (c) When the near-field communication module receives the first data from the remote module, the interface software verifies at least once whether it has received the first temporary authorization. If it has received it, the interface sends the first data to the application.

[0083] Another embodiment provides a mobile terminal suitable for implementing NFC services with a remote module. The terminal includes an application processor hosting interface software that establishes NFC services and executes instructions from the application, a near-field communication module, and a secure element distinct from the processor. The method for implementing NFC services includes the following sequential steps:

[0084] (a) The application requests authorization from the secure element to implement NFC services;

[0085] (b) The security element sends a first temporary authorization to the interface software; and

[0086] (c) At least when the near-field communication module receives the first data from the remote module, the interface software first verifies whether it has received the first temporary authorization.

[0087] According to one embodiment, the interface software is a main interface layer, which is a software interface that directly receives instructions from the application and converts these instructions into a series of instructions suitable for different software that drive the circuits and components of the terminal.

[0088] According to one embodiment, the interface software is a software control layer that includes software that drives the circuitry and components of the terminal.

[0089] According to one embodiment, the application is authorized to implement NFC services through filter interface software, which constitutes part of the interface software.

[0090] According to one embodiment, the application is a system application.

[0091] According to one embodiment, the application is a reliable application that has received a perpetual license to implement NFC services.

[0092] According to one embodiment, the application has received a second temporary authorization to implement NFC services.

[0093] According to one embodiment, the security element passes a second temporary authorization regarding the application to the filtering interface software that forms part of the interface software, the security element having obtained the temporary authorization from an external server.

[0094] According to one embodiment, if the security element does not grant the first authorization to the interface software, the interface software does not send the first data to the application during step (c).

[0095] According to one embodiment, NFC services are services implemented through near-field communication methods.

[0096] According to one embodiment, NFC service is a service in which a terminal and a remote module may exchange third-party secret data.

[0097] According to one embodiment, NFC services are banking services.

[0098] Another embodiment provides a system including the terminal and remote module described above. Attached Figure Description

[0099] The above-described features and advantages, as well as other features and advantages, will be described in detail in the following specific embodiment, which is described by way of illustration rather than limitation, with reference to the accompanying drawings, wherein:

[0100] Figure 1 The implementation of NFC services is illustrated very schematically in the form of boxes;

[0101] Figure 2 An example of a mobile terminal capable of implementing NFC service implementation mode is shown schematically in the form of a box;

[0102] Figure 3 A block diagram showing the implementation model of NFC services is displayed;

[0103] Figure 4 A block diagram showing another implementation mode of NFC services;

[0104] Figure 5 A block diagram showing another implementation mode of NFC services;

[0105] Figure 6 A block diagram showing another implementation mode of NFC services; and

[0106] Figure 7 A block diagram showing another implementation mode of NFC services is displayed. Detailed Implementation

[0107] In different figures, similar features are represented by similar reference numerals. In particular, structural and / or functional features common in various embodiments may have the same reference and may have the same structure, dimensions, and material properties.

[0108] For clarity, only the steps and elements useful for understanding the embodiments described herein are described in detail. Specifically, details of the data exchanged during NFC services of the type described below are not described. Different NFC communication protocols specific to the type of NFC service are within the capabilities of those skilled in the art and are compatible with the implementation modes described below.

[0109] Unless otherwise stated, when two elements are referenced together, it means that there is no direct connection of any intermediate element other than the conductor, and when two elements are referenced together, it means that the two elements can be connected, or can be connected by one or more other elements.

[0110] In the following disclosure, unless otherwise specified, when referring to absolute position qualifiers, such as the terms "front," "back," "up," "down," "left," "right," etc., or relative position qualifiers, such as "above," "below," "above," and "below," etc., or direction qualifiers, such as "horizontal," "vertical," etc., refer to the orientation shown in the figure.

[0111] Unless otherwise specified, “around,” “approximately,” “roughly,” and “on the order of…” mean within 10%, preferably within 5%.

[0112] Figure 1 The NFC service between an electronic device 101 (TERM) used as a mobile terminal or mobile terminal 101 and an electronic device 103 (CARD) used as a remote module or remote module 103 is illustrated in a block-like manner.

[0113] Here, a service is referred to as a specific communication intended for commercial and / or monetary operations, in which one device (terminal 101) is the "payment" terminal implementing the service, and the other device, namely remote module 103, is the device that accepts or does not accept the service. An example of a service described in the embodiments below is a banking service. Another related example is the purchase of a transportation ticket. Other types of services are conceivable, and the two examples mentioned above are not limiting. The NFC service involved here specifically refers to the exchange of critical and / or confidential data between two devices.

[0114] NFC (Near Field Communication) is a wireless and contactless communication technology implemented using near field technology (hereinafter referred to as NFC communication). Near Field Communication (NFC) technology enables short-range, high-frequency communication. Such systems use radio frequency electromagnetic fields emitted by a device (terminal or reader) to communicate with another device (remote module, repeater, or card).

[0115] This assumes the case of two electronic devices (e.g., terminal 101 and remote module 103); however, all cases described more generally apply to any system where the transponder detects the electromagnetic field radiated by the reader or terminal. In this type of communication, electronic devices 101 and 103 are positioned within range of each other, i.e., at a distance typically less than 10 cm. According to another example, devices 101 and 103 are in mechanical contact with each other.

[0116] Depending on the application, for NFC communication, one device (terminal 101) operates in a so-called reader mode, while another remote module 103 operates in a so-called card mode, or the two devices communicate in a peer-to-peer (P2P) mode. Each device includes various electronic circuits 105 (NFC) adapted to transmit radio frequency (RF) signals via an antenna oscillating / resonant circuit. The RF field generated by one of the devices (e.g., terminal 101) is detected by the other device (e.g., remote module 103), which is within its range and also includes an antenna. When terminal 101 emits an electromagnetic field to initiate communication with remote module 103, the field is captured by remote module 103 once it is within its range. The field is detected by circuits 105 of remote module 103 and reactivated if they are in standby mode. This results in a change in the load formed by circuits 105 of remote module 103 on a resonant circuit used to generate the field of terminal 101. In effect, terminal 101 detects a corresponding phase or amplitude change in the emitted field and then initiates the protocol for NFC communication with remote module 103. On the terminal 101 side, it detects whether the voltage amplitude across the resonant circuit drops below a threshold, or whether the voltage across the resonant circuit exhibits a phase shift greater than a threshold. Once the terminal 101 detects the presence of the remote module 103 in its field, it begins the communication establishment process, implementing request transmissions from the terminal 101 and response transmissions from the remote module 103. The request and response transmissions will... Figures 3 to 7 The details are described further in the text.

[0117] Terminal 101 is an electronic device, which may be fixed or mobile. Terminal 101 is responsible for initiating communication. As an example, terminal 101 is an electronic device suitable for implementing business applications as a terminal for business. According to a more detailed example, terminal 101 is a cellular phone, such as a smartphone, that implements point-of-sale (POS) applications, i.e., enabling it to implement business applications as a terminal. According to another example, terminal 101 may be a connected device suitable for implementing near-field communication, more specifically NFC communication, such as a smartwatch.

[0118] The remote module 103 is typically a mobile device. According to a preferred embodiment, the remote module 103 is a microcircuit card (or chip card), such as a bank card or data transfer card. As a variation, the remote module 103 may be a cellular phone. The remote module 103 includes various electronic circuits adapted to implement various instructions sent by the terminal 101, such as authentication circuits, cryptographic circuits, etc.

[0119] In existing systems, the same NFC device can operate in card mode or reader mode (e.g., in the case of near-field communication between two cellular phones), and can choose whether to operate in card mode or reader mode depending on the situation. According to one example, module 101 can be used as a reader or terminal to implement payment transactions, and in another case, it can be used as a card, for example, for verifying transportation tickets.

[0120] Figure 2 An embodiment of an NFC service between terminal device 201 (terminal) or terminal 201 and remote module 203 (CARD) is illustrated in further detail using boxes. This NFC service type is similar to... Figure 1 The types described in the text are the same. Figure 2 The hardware (solid line) and software (dashed line) structure of terminal 201 are further described in detail, along with the remote module 203. Figure 1 The remote module 103 described herein is the same.

[0121] Terminal 201 includes at least:

[0122] - Processor 2011 (APP PROC);

[0123] - Safety Components (SE) 2012; and

[0124] - Near Field Communication Module (NFC) 2013.

[0125] Processor 2011 is a processor, particularly suitable for implementing the software architecture of terminal 201, which will be described below.

[0126] Secure element 2012 is a secure circuit or component, such as a processor or computing unit, suitable for manipulating secret or confidential data. Secure element 2012 differs from processor 2011. Secure element 2012 may, for example, implement algorithms such as authentication, data encryption and / or decryption, and encryption and / or decryption key generation. According to one example, secure element 2012 is a secure element embedded in terminal 201, but according to a variation, secure element 2012 may be a secure element integrated into terminal 203. The advantage of having an embedded or integrated secure element is that it allows for a high level of protection because the secure element forms part of device 100. According to another variation, secure element 2012 may form part of a secure platform, or secure element 2012 may be combined with processor 2011 while benefiting from hardware portions that are physically isolated from processor 2011, for example, by using TrustZone-type technology. The latter two variations offer a lower level of protection than the former two. According to one embodiment, secure element 2012 is able to determine whether an NFC transaction is one where critical information and data can be exchanged.

[0127] The near-field communication module 2013 or NFC module 2013 is a component of circuitry and one or more antennas that enables the terminal 201 to perform near-field communication, especially... Figure 1 The type of NFC service described above. Therefore, the NFC module is capable of sending and receiving data, such as regarding... Figure 1 The circuit 105 is described. According to one embodiment, the NFC module is capable of detecting whether the data is critical data, for example, by verifying the type of the sent instruction and the type of the subsequently received response, for example, based on a lookup table stored in the NFC module 2013, or, for example, by counting the number of instructions based on the application's selection (or selection response). The NFC module may combine both methods.

[0128] These three components are adapted to communicate via different communication methods. According to one example, processor 2011 is adapted to communicate with NFC module 2013, for example, via an I2C (Internal Integrated Circuit) type bus, an SPI (Serial Peripheral Interface) type bus, or a UART (Universal Asynchronous Receiver / Transmitter) type bus. According to one example, processor 2011 is adapted to communicate with secure element 2012, for example, via an I2C (Internal Integrated Circuit) type bus or an SPI (Serial Peripheral Interface) type bus. According to one example, secure element 2012 is adapted to communicate with NFC module 2013 via shared data memory, for example, using an IPC (Inter-Process Communication) type communication mechanism, for example, by using a communication protocol of type HCI (Host Controller Interface) or CLT (Contactless Communication). For joint communication, secure element 2012 and NFC module 2013 can, for example, use a VNP (VPP Network Protocol, VPP stands for Virtual Host Platform) type communication protocol, which can be used with I2C or SPI type buses.

[0129] Furthermore, terminal 201, especially processor 2011, is suitable for implementing different types of software to enable it to perform different functions, including, more specifically, conducting NFC business with another electronic device (such as remote module 203), including enabling users to implement different applications and multiple interface software layers 2016 (platforms) with different functions, or enabling interface software 2016 to translate instructions sent by applications into instructions that can be interpreted by different circuits and components of terminal 201 (such as secure element 2012 and NFC module 2013).

[0130] exist Figure 1 In this context, terminal 201 is adapted to implement at least one application 2014 (mPOS App), which has the function of being implemented as a terminal. Figure 1The NFC service functionality of this type. Application 2014 can be a point-of-sale type application. According to the example, terminal 201 can implement one or more other applications 2015 (application 2). In this specification, "application" refers to software that a user of terminal 201 can access and operate. To implement different functions of terminal 201, applications are adapted to various circuits and components using terminal 201 by sending instructions to the interface software layer 2016.

[0131] The interface software layer 2016 includes:

[0132] - Main Interface Layer 2017 (API);

[0133] - Filter layer 2018 (OMAPI); and

[0134] - A layer for the circuitry and components used to control terminal 201 of DRIVERS 201.

[0135] The main interface layer 2017 is a software interface that directly receives operation commands to be executed from applications 2014 and 2015, and translates these operations into a series of instructions suitable for different circuits and components of terminal 201. In other words, if an application sends a command to perform an operation requesting the use of multiple circuits or components of terminal 201, interface 2017 translates that command into a set of instructions. Operations can be performed by implementing one or more instructions intended for use with one or more circuits or components of terminal 201.

[0136] Filter layer 2018 is a software filter interface suitable for authorizing, restricting, or prohibiting applications, such as applications 2014 and 2015, from using all or part of one or more circuits or components of terminal 201. In other words, filter layer 2018 receives instructions sent by interface 2017 and determines whether to send those instructions based on the application that specified the initial instructions. Filter layer 2018 can authorize or deny access to the circuits and components of terminal 201 of applications based on different criteria. According to one example, filter layer 2018 can authorize a first application to access one or a portion of the circuits or components of terminal 201 and deny access to a second application.

[0137] According to the first example, if the application is a system application—that is, an application generated by the manufacturer of terminal 201 or the manufacturer or designer of interface software layer 2016—then the application may have permanent authorization to access all circuits or components, or only circuits and components selected by the manufacturer, and at least authorization to implement NFC services. Conversely, a system application may have limited permanent or non-permanent access to all or part of one or more circuits or components of terminal 201. Therefore, certain parts of a circuit or component, or certain circuits or components of terminal 201, may be accessible only to the system application, and applications that do not meet this standard will systematically receive rejection each time they attempt to send instructions to these parts or components of the circuit or component.

[0138] According to the second example, the application may be a reliable application that has passed different reliability tests than the manufacturer of terminal 201 or the manufacturer or designer of interface software layer 2016, and therefore, the manufacturer or designer has permanently authorized it to access all or part of the circuitry or components of terminal 201. According to one example, the application at least has authorization to implement NFC services. This type of reliable application can be considered a system application and therefore has the same characteristics.

[0139] According to the third example, the application can periodically authenticate with a server external to terminal 201 to obtain temporary access authorization to all or part of the circuitry and components of terminal 201. According to one example, the application has at least temporary authorization to implement NFC services. In the following description, it can be stated that the application is authorized to access such circuitry or such components of terminal 201, and the filter layer 2018 authorizes its access. According to one example, the authorization for temporary access to the circuitry and components of terminal 201 can be maintained by interface software 2016, for example, by the filter interface 2018, which is adapted, for example, to implement application authentication with an external server.

[0140] According to the fourth example, the circuitry or components of terminal 201 (e.g., security element 2012) may be adapted to determine which applications are authorized to implement one or more of their functions. The circuitry or components of terminal 201 may, for example, provide a list to filter layer 2018 indicating which applications are authorized to implement one or more of their functions. According to a variation, the circuitry or components may pass temporary authorizations to all or part of an application, for example, by authorizing multiple uses of one or more of its functions. Filter layer 2018 applies these authorizations when an application sends a command to use one or more functions of one or more circuitry or components of terminal 201. According to a preferred example, security element 2012 includes, for example, a list of rules stored in memory indicating the authorizations of different applications implemented by terminal 201.

[0141] The control layer 2019 of the terminal 201's circuits and components is general-purpose software used to control the circuits and components 201, that is, software that drives the lines and components of the terminal 201. In other words, the control layer 2019 is a collection of programs capable of implementing the instructions delivered by the interface 2017. Each circuit or component is associated with control software suitable for implementing it. This control software is often called driver software or "driver".

[0142] Figure 3 This is an explanation Figure 1 A flowchart illustrating the implementation method or implementation mode steps of the NFC service of the aforementioned NFC service type. These steps are comprised of... Figure 2 The terminal 201 and remote module 203 are executed.

[0143] In the initial step 301 (Application -> NFC cmd1), application 2014 of terminal 201 decides to conduct NFC business with remote module 203. To this end, once communication is established (e.g., according to the anti-collision standard defined by the NFC Forum or ISO 14443, or any other protocol implemented by NFC module 2013), application 2014 needs to send the first command cmd1 to remote module 203 using NFC module 2013. Then, application 2014 sends a request to interface software layer 2016 to send command cmd1 to remote component 203 using NFC component 2013. Because this operation is not critical beforehand, filtering layer 2018 authorizes the operation.

[0144] In step 302 (NFC->CARD cmd1), following step 301, the NFC module has received the instruction cmd1 to be sent to the remote module 203, and sends the instruction using the near field communication protocol of the type described above.

[0145] In step 303 (CARD->NFC ans1), following step 302, the remote module 203 has received and processed the instruction cmd1 and sent a response ans1 to the NFC module 2013 of the terminal 201. This response ans1 may contain critical data. According to one example, if the NFC transaction is a banking transaction, critical banking data may form part of the response ans1, such as identification data or data capable of identifying the user. According to embodiments, the NFC module 2013 can determine whether the data included in the response ans1 is critical data based on the type of NFC transaction being implemented. For example, when the NFC module detects that the NFC transaction is a banking transaction, it can understand that the exchanged data is critical data.

[0146] In step 304 (NFC -> SE key 1), which is performed concurrently with operations 301, 302, or 303, the NFC module 2013 requests the secure element 2012 to pass it an encryption key. The NFC module can, for example, send a specific instruction to request the key from the secure element. The NFC module 2013 and the secure element 2012, which have a direct communication line, will have the secure element 2012 pass the cryptographic key key1 to the NFC module 2012, as previously described. According to one example, the NFC module 13 is capable of allocating a communication channel as defined in the HCI standard.

[0147] In step 305 (NFC encryption), following step 303, the NFC module 2013, which receives the response ans1 from the remote module 203 and the password key key1 from the secure element, can encrypt the response ans1 using the password key key2 to obtain the encrypted response e(ans1). Therefore, the critical data of the response ans1 is protected by encryption.

[0148] In step 306 (NFC->App e(ans1)), following step 305, the NFC module 2013 sends an encrypted response e(ans2) to the application 2014.

[0149] In step 307 (Application -> SE Key?), after step 306, application 2014 receives the encrypted response e(ans1) and cannot read or interpret it without decrypting it. Therefore, application 2014 sends the decryption key to secure element 2012. This operation is critical; filter interface 2018 verifies whether application 2014 is authorized to send this request to secure element 2012. If application 2014 is authorized (output Y), the next step is step 308 (Application Decryption); otherwise (output N), the next step is step 309 (Application Error).

[0150] In step 308, application 2014 is authorized, and secure element 2012 provides it with a decryption key, for example, if key1 is both the password and the decryption key, then it is key1; otherwise, it is a decryption key different from key1. Application 2014 can then decrypt the response ans1.

[0151] In step 310 (Service Continues), following step 308, application 2014 can continue sending instructions and receiving responses from remote module 203 by using the same previously described mechanism, by using a different cipher and / or decryption key for each response received from remote module 203. The same cipher key can be used for each response received from remote module 203 to accelerate the service. In this case, the cipher key may become ineffective at the end of the service, for example, by being suppressed or invalidated. It can be considered that the service ends when there are no new instructions within a defined time period, such as a time period on the order of 500ms or 1s, or, for example, when the remote module is no longer within range of the terminal, or if an application different from application 2014 is launched. According to a variant, the NFC module can also determine, based on a given time period or specific instruction, that the NFC service no longer includes critical data, thereby ceasing encryption of the exchanged data.

[0152] In step 309, application 2014 has been identified as unauthorized by filter interface 2018, and secure element 2012 has not passed it the decryption key. Therefore, application 2014 cannot decrypt the response. By being identified as unauthorized, application 2014 will be unable to access critical data for NFC services.

[0153] In step 311 (service stop), following step 309, because application 2014 cannot access critical and / or secret data, application 2014 cannot perform NFC services, and the NFC service stops automatically.

[0154] One advantage of this embodiment is that applications not authorized by the Filter Interface 2018 cannot access critical data sent by the remote module because this data is still encrypted using a key that the application cannot access.

[0155] Figure 4 This is an explanation Figure 1 A flowchart illustrating the implementation method or implementation mode steps of the NFC service of the aforementioned NFC service type. These steps are comprised of... Figure 2 The terminal 201 and remote module 203 are executed.

[0156] In the initial step 401 (Application -> NFC cmd2), application 2014 of terminal 201 decides to perform NF service with remote module 203. To this end, once communication is established (e.g., according to the anti-collision standard defined by the NFC Forum or ISO 14443, or any other protocol implemented by NFC module 2013), application 2014 needs to send the first command cmd2 to remote module 203 using NFC module 2013. Then, application 2014 sends a request to interface software layer 2016 to send command cmd2 to remote module 204 using the NFC component. Because this operation is not critical beforehand, filtering layer 2018 authorizes the operation.

[0157] In step 402 (NFC->CARD cmd2), following step 401, the NFC module 2013 has received the instruction cmd2 to be sent to the remote module 203, and sends the instruction using the near field communication protocol of the type described above.

[0158] In step 403 (CARD->NFC ans2), following step 402, the remote module 203 has received and processed the instruction cmd2, and sent a response ans2 to the NFC module 2013 of the terminal 201. This response ans2... Figure 3 Similar to the response ans1 described in the text, it may contain key data.

[0159] In step 404 (NFC->SE ans2), following step 403, the NFC module 2013 sends a response ans2 to the secure element 2012 so that the secure element can encrypt it. For example, step 404 can be optimized so that if the NFC module 2013 can detect key data in the data of the response ans2, the NFC module can request the secure element to encrypt only the key information in the response ans2. According to a variant, the NFC module sends the response ans2 to the secure element, and the secure element selects the key information to be encrypted from the data of the response ans2.

[0160] In step 405 (SE encryption), following step 404, the secure element 2012 encrypts the response ans2 using a uniquely known cryptographic key to obtain the encrypted response e(ans2). Therefore, the critical data of the response ans2 is protected by encryption.

[0161] In step 406 (SE->NFC->App e(ans2)), following step 405, the secure element 2012 returns an encrypted response e(ans1) to the NFC module 2013. Then, the NFC module 2013 sends an encrypted response e(ans2) to the application 2014.

[0162] In step 407 (App->SE Decryption?), after step 406, application 2014 receives the encrypted response e (ans2) and cannot read it without decrypting it. Therefore, application 2014 sends a decryption request to secure element 2012. This operation is critical; filter interface 2018 verifies whether application 2014 is authorized to send the request to secure element 2012. If application 2014 is authorized (output Y), the next step is step 408 (SE->Application Decryption); otherwise (output N), the next step is step 409 (Application Error).

[0163] In step 408, application 2014 is authorized to communicate with the secure element, requesting the secure element 2012 to decrypt the response e(ans2). The latter performs the decryption and sends the response ans2 back to application 2014. According to another embodiment, application 2014 may request a decryption key from the secure element and decrypt the data itself.

[0164] In step 410 (service continues), following step 408, application 2014 can continue to send instructions and receive responses from remote module 202 by using the same mechanism described previously, namely by encrypting each response received from remote module 203 by security element 2012. A single encryption can be performed on the first response received from remote module 203 to accelerate the service.

[0165] In step 409, application 2014 is identified as unauthorized. Therefore, application 2014 is unable to decrypt response e(ans2). By being identified as unauthorized, application 2014 will be unable to access the critical data of the NFC service.

[0166] In step 411 (service stop) following step 409, since application 2014 cannot access critical and / or secret data, application 2014 cannot perform NFC services, and the NFC service stops automatically.

[0167] The advantage of this embodiment is that applications not authorized by the Filter Interface 2018 cannot access critical data sent by the remote module.

[0168] Another advantage of this embodiment is that the management of the decryption key is the responsibility of the secure element 2012. Therefore, the secure element can choose which decryption key to use, use only the same key, or change the key frequently as needed.

[0169] Figure 5 This is an explanation Figure 1 A flowchart illustrating the implementation method or implementation mode steps of the NFC service of the aforementioned NFC service type. These steps are comprised of... Figure 2 The terminal 201 and remote module 203 are executed.

[0170] In the initial step 501 (Application -> NFC cmd3), application 2014 of terminal 201 decides to implement NFC services with remote module 203. To this end, once communication is established (e.g., according to the anti-collision standard defined by the NFC Forum or ISO 14443, or any other protocol implemented by NFC module 2013), application 2014 needs to send a first command cmd3 to remote module 203 using NFC module 2013. Then, application 2014 sends a request to interface software layer 2016 to send command cmd3 to remote module 204 using the NFC component. Because this operation is not critical beforehand, filtering layer 2018 authorizes the operation.

[0171] In step 502 (NFC->CARD cmd3), following step 501, the NFC module 2013 has received the instruction cmd3 to be sent to the remote module 203, and sends the instruction using the near field communication protocol of the type described above.

[0172] In step 503 (CARD->NFC ans3), following step 502, the remote module 203 has received and processed the instruction cmd3 and provided a response ans3 to the NFC module 2013 of the terminal 201. This response ans3... Figure 3 Similar to the response ans1 described in the text, it may contain key data.

[0173] In step 504 (NFC->SE ans3), following step 503, the NFC module 2013 sends ans3 to the secure element 2012 so that the secure element stores the ans3. According to a variant, the secure element 2021 can store the ans3 and apply a cryptographic method, such as an asymmetric cryptography, to it. According to another variant, the NFC module 2013 sends the ans3 to the secure element 2012, and if the secure element 2012 detects that some data in the ans3 is critical data, the secure element 2012 can store this data and remove it from the ans3 or replace it with other data before returning the ans3 to the NFC module 2012.

[0174] In step 505 (NFC Subs), following step 503, the NFC module prepares data s (ans3) to send to the application 2014 so that it knows that the remote module 203 has sent a response ans3. This data s (ans3) can be data dependent on the response ans3, such as a truncated response ans3, or an encrypted or signed response ans3, or data independent of the response ans3, such as random or typical data indicating to the application 2014 that a response has been received.

[0175] In step 506 (NFC->Application (ans3)), following step 505, NFC module 2013 sends data s (ans2) to application 2014.

[0176] In step 507 (Application -> SE ans3?), after step 506, application 2014 receives data s (ans3) and understands that it must request an acknowledgment ans3 from security element 2012. Therefore, application 2014 sends a decryption request to security element 2012. This operation is critical; filter interface 2018 verifies whether application 2014 is authorized to send this request to security element 2012. If application 2014 is authorized (output Y), the next step is step 508 (SE -> Application Decryption); otherwise (output N), the next step is step 509 (Application Error).

[0177] In step 508, application 2014 is authorized to communicate with secure element 2012, requesting a response ans3 from secure element 2012. The latter sends response ans3 to application 2014. According to one variation, if response ans3 has been encrypted by secure element 2012, application 2014 can request decryption of response ans3 from secure element 2012 or decrypt it itself. In the second case, it is assumed that a password and / or decryption key have been exchanged to establish a public secret before implementing NFC transactions. A Diffie-Hellman type of technique can also be used here.

[0178] In step 510 (service continues), following step 508, application 2014 can continue sending instructions and receiving responses from remote module 202 by using the same previously described mechanism, by storing each response received from remote module 203 in secure element 2012. According to a variant, a single storage can be performed on the first response received from remote module 203 to accelerate service.

[0179] In step 509, application 2014 is identified as unauthorized. Therefore, application 2014 cannot receive the response ans3, regardless of whether it is encrypted. By being identified as unauthorized, application 2014 will be unable to access critical data for NFC services.

[0180] In step 511 (service stop), following step 509, since application 2014 cannot access critical and / or secret data, application 2014 cannot perform NFC services, and the NFC services stop automatically.

[0181] The advantage of this embodiment is that applications not authorized by the Filter Interface 2018 cannot access critical data sent by the remote module.

[0182] Figure 6 This is an explanation Figure 1A flowchart illustrating the implementation method or implementation mode steps of the NFC service of the aforementioned NFC service type. These steps are comprised of... Figure 2 The terminal 201 and remote module 203 are executed.

[0183] In initial step 601 (App->API Request Trans), application 2014 of terminal 201 decides to implement NFC services with remote module 203. To this end, application 2014 sends an authorization request to main interface layer 2017. This request may, for example, include a request for authentication of secure element 2012 by application 2014. For example, the request may include data related to the type of NFC service authorized to be implemented by the application, which allows the secure element to filter the type of NFC service implemented by the application.

[0184] In step 602 (API->SE service?), following step 601, the main interface layer 2017 sends a request to the filter interface, which verifies whether the application is authorized to be sent to the secure element 2012. If the application 2014 is authorized (output Y), the next step is step 603 (SE->API evt4); otherwise (output N), the next step is step 604 (application error).

[0185] In step 604, application 2014 has been identified as unauthorized and therefore cannot perform business operations. The main interface layer 2017 can, for example, prevent any business requests originating from application 2014 from initiating, or can, for example, detect the presence of critical data, as described below.

[0186] In step 603, following step 602, the secure element 2012 sends instruction evt4 or temporary authorization evt4 to the main interface layer 2017. Based on this instruction, application 2014 can implement NFC services. For example, instruction evt4 could involve a single NFC service of application 2014, multiple consecutive NFC services, or all NFC services of application 2014. In practice, instruction evt44 can be a software event.

[0187] In step 605 (Application -> NFC cmd4), which is continuous with step 603 but may be directly continuous with step 601, application 2014 decides to implement NFC service with remote module 203. Then, application 2014 sends a request to interface software layer 2016 to send instruction cmd4 to remote module 203 using NFC module 2013. Since this operation is not critical beforehand, main interface layer 2017 authorizes the operation.

[0188] In step 606 (NFC->CARD cmd4), following step 605, the NFC module 2013 has received the instruction cmd4 to be sent to the remote module 203, and sends the instruction using the near field communication protocol of the type described above.

[0189] In step 607 (CARD->NFC ans4), following step 606, the remote module 203 has received and processed the instruction cmd4 and sent a response ans4 to the NFC module 2013 of the terminal 201. This response ans4... Figure 3 Similar to the response ans1 described in the text, it may contain key data.

[0190] In step 608 (NFC->API ans4), following step 607, the NFC module 2013 sends ans4 to the application 2014, but this sending is intercepted by the main interface layer 2017.

[0191] In step 609 (API->evt4?), following step 608, the instruction evt4 received by the main interface layer 2017 is executed. If instruction evt4 authorizes the application to implement NFC services (output Y), the next step is step 610 (API->App ans4); otherwise (output N), the next step is step 611 (App error). The transmission of instruction evt4 can be, for example, the transmission of a software event of a service type, such as a service type defined by the HCI standard, which is performed through a dedicated communication channel coupling the secure element 2012 and the processor 2011.

[0192] -The application is authorized to perform NFC services;

[0193] - The type of relevant NFC service; and / or

[0194] - The number of NFC services that the application is authorized to implement.

[0195] According to one example, Application 2014 can be authorized to implement NFC transactions for two types of banks.

[0196] In step 610, application 2014 is authorized to communicate with the security element, and the main interface layer 2017 sends a response ans4 to it.

[0197] In step 612 (Service Continues), following step 610, application 2014 can continue to send instructions and receive responses from remote module 203 using the same mechanism described previously. According to a variation, main interface layer 2017 can verify for each exchange whether application 2014 is authorized to perform NFC services, or main interface layer 17 can consider the authorization of instruction eft4 valid until the ongoing NFC service ends or is valid for a predetermined time period, or it can be based on parameters included in instruction eft4.

[0198] In step 611, application 2014 has been identified as unauthorized and is therefore not authorized to receive response ans4. By being identified as unauthorized, application 14 will be unable to access critical data for the NFC service.

[0199] In step 613 (service stop), following step 611, since application 2014 cannot access critical and / or secret data, application 2014 cannot perform NFC services, and the NFC service stops automatically.

[0200] The advantage of this embodiment is that applications not authorized by the Filter Interface 2018 cannot access critical data sent by the remote module.

[0201] Figure 7 This is an explanation Figure 1 A flowchart illustrating the implementation method or implementation mode steps of the NFC service of the aforementioned NFC service type. These steps are comprised of... Figure 2 The terminal 201 and remote module 203 are executed.

[0202] Figure 7 Implementation model and Figure 6 The implementation models described are similar. The difference between these two implementations lies in the fact that... Figure 7 In this case, the verification of whether an application is authorized to implement NFC services is not done by the main interface layer 2017, but by the control layer 2019 of the circuitry and components of the terminal 201 that performs the verification. The method is as follows.

[0203] In initial step 701 (App->DRIVERS Request Trans), application 2014 of terminal 201 decides to perform NFC services with remote module 203. To this end, application 2014 sends a request to control layer 2019. This request may, for example, be an authentication request with secure element 2012. This request may, for example, include data related to the type of NFC service authorized to be performed by the application.

[0204] In step 702 (NFC->CARD cmd5), following step 701, the control layer 2019 sends a request to the secure element 2012. If application 2014 is authorized (output Y), the next step is step 703 (SE->DRIVERS evt5); otherwise (output N), the next step is step 704 (application error). According to an alternative embodiment, authorization verification for application 2014 is not performed in step 702, and the next step is directly step 703.

[0205] In step 704, application 2014 has been identified as unauthorized and therefore cannot perform business operations. For example, control layer 2019 can prevent any requests to initiate business operations originating from application 2014.

[0206] In step 703, following step 702, the secure element 2012 sends instruction evt5 or temporary authorization evt5 to the control layer 2019. According to this instruction, application 2014 can implement NFC services. For example, instruction evt5 could involve a single NFC service, multiple consecutive NFC services, or all NFC services of application 2014. In practice, instruction evt55 can be a software event. The sending of instruction evt4 can be, for example, the sending of a service-type software event, as defined by the HCI standard, performed through a dedicated communication channel coupling the secure element 2012 and the processor 2011. In this case, instruction evt4 may include different parameter indications, such as:

[0207] -The application is authorized to perform NFC services;

[0208] - The type of relevant NFC service; and / or

[0209] - The number of NFC services that the application is authorized to implement.

[0210] According to one example, Application 2014 can be authorized to implement NFC transactions for two types of banks.

[0211] In step 705 (Application -> NFC cmd5), which is continuous with step 703 but may be directly continuous with step 701, application 2014 decides to implement NFC service with remote module 203. Then, application 14 sends a request to interface software layer 2016 to send instruction cmd5 to remote module 203 using NFC module 2013. Since this operation is not critical beforehand, control layer 2019 authorizes the operation.

[0212] In step 706 (NFC->CARD cmd5), following step 705, the NFC module 2013 has received the instruction cmd5 to be sent to the remote module 203, and sends the instruction using the near field communication protocol of the type described above.

[0213] In step 707 (CARD->NFC ans5), following step 706, the remote module 203 has received and processed the instruction cmd5 and sent a response ans5 to the NFC module 2013 of the terminal 201. This response ans5... Figure 3 Similar to the response ans1 described in the text, it may contain key data.

[0214] In step 708 (NFC->DRIVERS ans5), following step 707, the NFC module 2013 sends ans5 to the application 2014, but this transmission is intercepted by the control layer 2019 (DRIVERS).

[0215] In step 709 (DRIVERS->evt5?), the instruction evt5 received by the control layer 2019 (DRIVERS) is executed after step 708. If instruction evt5 authorizes the application to implement NFC services (output Y), the next step is step 710 (DRIVERS->App ans5); otherwise (output N), the next step is step 711 (application error).

[0216] In step 710, application 2014 is authorized to communicate with security element 2012, and control layer 2018 sends a response ans5 to it.

[0217] In step 712 (Service Continues), following step 710, application 2014 can continue to send instructions and receive responses from remote module 203 using the same mechanism described previously. According to a variation, control layer 2019 can verify for each service whether application 2014 is authorized to perform the NFC service, or control layer 2019 can consider the authorization of instruction evt5 to be valid before the end of the ongoing NFC service or within a predetermined time period. Control layer 2019 (DRIVERS) can further use the parameters passed by instruction evt4.

[0218] In step 711, application 2014 has been identified as unauthorized and therefore is not authorized to receive response ans5. By being identified as unauthorized, application 14 will be unable to access critical data for the NFC service.

[0219] In step 713 (service stop), following step 711, since application 2014 cannot access critical and / or secret data, application 2014 cannot perform NFC services, and the NFC service stops automatically.

[0220] One advantage of this embodiment is that applications not authorized by the control layer 2019 cannot access critical data sent by the remote module, and the authorization of the application originally stemmed from the secure element 2012.

[0221] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these different embodiments and variations can be combined, and other variations will conceive of by those skilled in the art. In particular, the terminal and NFC module can implement these methods only for critical NFC services (i.e., services that exchange critical and / or confidential data). The NFC module, interface layer 2018, and control layer 2019 can, for example, be able to distinguish whether an NFC service is critical. This distinction can be based on the context of the service being implemented, on instructions, on application-specific selection, or otherwise.

[0222] Finally, based on the functional indications given above, the actual implementation of the embodiments and variations is within the capabilities of those skilled in the art.

Claims

1. A method for implementing NFC services between a mobile terminal and a remote module, the terminal including a processor, a near-field communication module, and a secure element different from the processor, the processor hosting an application configured to establish the NFC service and interface software configured to execute instructions of the application, the method comprising: The application requests authorization to implement the NFC service from the secure element via the interface software, and the interface software verifies whether the application is authorized to communicate with the secure element; The security element sends a first temporary authorization to the interface software; When the near-field communication module receives the first data from the remote module, the interface software shall at least verify for the first time whether the interface software has received the first temporary authorization. as well as When the interface software has received the first temporary authorization, the interface software transmits the first data to the application.

2. The method according to claim 1, wherein the interface software includes a main interface layer, the main interface layer receiving the instructions directly from the application and converting the instructions into a series of instructions for driving the circuits and components of the terminal.

3. The method according to claim 1, wherein the interface software includes a software control layer for driving the circuits and components of the terminal.

4. The method of claim 1, wherein the interface software includes filter interface software, and wherein the filter interface software verifies whether the application is authorized to communicate with the security element.

5. The method according to claim 1, wherein the application is a system application.

6. The method of claim 1, wherein the application is a reliable application that has received a permanent license to implement the NFC service.

7. The method of claim 1, wherein the application has received a second temporary authorization to implement the NFC service.

8. The method of claim 7, further comprising delivering the second temporary authorization by the security element to filter interface software that is part of the interface software, the security element having obtained the second temporary authorization from an external server.

9. The method of claim 1, wherein the first data includes secret data.

10. A mobile terminal, comprising: The processor hosts the application configured to establish NFC services and the interface software configured to execute the instructions of the application; Near-field communication module; as well as A security element different from the processor, The application is configured to request authorization to perform the NFC service from the secure element via the interface software, and the interface software is configured to verify whether the application is authorized to communicate with the secure element. The security element is configured to send a first temporary authorization to the interface software, and The interface software is configured as follows: When the near-field communication module receives the first data from the remote module, it verifies at least once whether the interface software has received the first temporary authorization, and When the interface software has received the first temporary authorization, it transmits the first data to the application.

11. The terminal according to claim 10, wherein the interface software includes a main interface layer, the main interface layer being configured to: Receive the instructions directly from the application, and The instructions are converted into a series of instructions for driving the circuits and components of the terminal.

12. The terminal of claim 10, wherein the interface software includes a software control layer configured to drive the circuitry and components of the terminal.

13. The terminal of claim 10, wherein the interface software includes filter interface software, and wherein the filter interface software is configured to verify whether the application is authorized to communicate with the security element.

14. The terminal according to claim 10, wherein the application is a system application.

15. The terminal of claim 10, wherein the application is a reliable application that has received a permanent license to implement the NFC service.

16. The terminal of claim 10, wherein the application has received a second temporary authorization to implement the NFC service.

17. The terminal of claim 16, wherein the security element is configured to deliver the second temporary authorization to filter interface software that is part of the interface software, the security element having obtained the second temporary authorization from an external server.

18. The terminal according to claim 10, wherein the first data includes secret data.

19. A method for implementing an NFC service between a mobile terminal and a remote module, the terminal including a processor, a near-field communication module, and a secure element different from the processor, the processor hosting an application configured to establish the NFC service and interface software configured to execute instructions of the application, the method comprising: The application requests authorization to implement the NFC service from the secure element via the interface software, and the interface software verifies whether the application is authorized to communicate with the secure element; The security element sends a first temporary authorization to the interface software; When the near-field communication module receives the first data from the remote module, the interface software shall at least verify for the first time whether the interface software has received the first temporary authorization. as well as When the interface software has not yet received the first temporary authorization, the interface software shall not transmit the first data to the application.

Citation Information

Patent Citations

  • FR2113476A5

  • Method for visiting terminal security component, device thereof and system thereof

    CN104348616A