Near field communication device and method

By realizing identity authentication and encryption transmission in the NFC controller, combined with the middleware's transparent transmission of encrypted card data, the problem of existing NFC systems requiring the addition of security modules in card simulation mode is solved, and NFC equipment security and cost reduction without eSE and SWP SIM are achieved.

CN120128903APending Publication Date: 2025-06-10SHENZHEN GOODIX TECH CO LTD

Patent Information

Application Number
CN202510272541.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing NFC system needs to add security modules such as eSE, SWP SIM in card simulation mode, resulting in high hardware costs and high application thresholds.

Method used

By realizing identity authentication and encryption transmission functions in the NFC controller, combined with the middleware to transmit encrypted card data through transparent transmission, the security of NFC devices is realized without eSE and SWP SIM.

Benefits of technology

It reduces the hardware cost of NFC equipment, reduces development time and technical thresholds, and at the same time realizes the security of the CE model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128903A_ABST
    Figure CN120128903A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a near field communication (NFC) device and method, the near field communication (NFC) device part comprises an NFC controller and middleware, the middleware is used for processing transmission logic between the NFC controller and an application program, and the application program is communicated with trusted service management (TSM); the NFC controller is used for identity authentication and encryption transmission with the TSM, and the middleware is used for transparent transmission of encrypted card data. According to the embodiment of the invention, the hardware cost and development cost of the NFC equipment can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of near field communication technology, and particularly to a near field communication device and method. Background Art

[0002] Near field communication (NFC) is a short-range high-frequency radio technology that operates within a 10-centimeter distance at a working frequency of 13.56 MHz. In real life, there are a large number of NFC card emulation / NFC card emulation devices operating in the Card emulation (CE) mode. In the card emulation mode, the NFC system can be emulated as an NFC card, that is, the NFC system can emulate a contactless radio frequency card that complies with NFC-related standards for data interaction with an NFC reader.

[0003] In the card emulation mode, most current NFC systems request from the Trusted Service Manager (TSM) and store the card data downloaded from the TSM in security modules such as an Embedded Secure Element (eSE) and a Single Wire Protocol SIM (SWP SIM). That is, if the card emulation mode is to be used and security is to be ensured, security modules such as eSE and SWP SIM must be added to the NFC system, which greatly increases the application threshold of the NFC system's card emulation function and also greatly increases the cost of the chip. Summary of the Invention

[0004] In view of the above problems, embodiments of this application provide a near field communication device and method to solve the above technical problems.

[0005] In a first aspect, an embodiment of this application provides a near field communication device, including: an NFC controller and middleware, where: the middleware is used to process the transmission logic between the NFC controller and the application program, and the application program communicates with the Trusted Service Manager (TSM); the NFC controller is used to perform authentication and encrypted transmission with the TSM, and the middleware is used to transparently transmit the encrypted card data.

[0006] In some embodiments, the NFC controller and the TSM perform authentication and encrypted transmission based on a root key, and the root key is used to derive a session key, where: in the case that the NFC controller includes a permanent storage area, the root key is preset in the permanent storage area; in the case that the NFC controller has no permanent storage area, the NFC controller obtains the encrypted root key from the TSM and decrypts it using a fixed key value in the program code, and temporarily stores the decrypted root key.

[0007] In some embodiments, the NFC controller is used to perform authentication with the TSM during card opening; the middleware is used to, after the application program receives the encrypted card data sent by the TSM after successful authentication: pass through the encrypted card data to the NFC controller when distributing the card data; the NFC controller is used to: store the encrypted card data and decrypt the encrypted card data when swiping the card; or decrypt the encrypted card data and store the decrypted card data.

[0008] In some embodiments, the NFC controller is used to: generate a random number during card opening, where the random number is sent to the TSM via the middleware and the application program; receive a response message sent by the TSM via the application program and the middleware, where the response message carries an authentication token and a message authentication code, the authentication token is generated based on the root key on the TSM side and the random number, and the message authentication code is used to verify the legality of the response message; verify the message authentication code of the response message based on the root key on the NFC side; in the case that the message authentication code is verified successfully, verify the authentication token based on the root key on the NFC side; in the case that the authentication token is verified successfully, destroy the random number and generate a message authentication code for preset data based on the root key on the NFC side, where the generated message authentication code is sent to the TSM via the middleware and the application program so that the TSM verifies the NFC controller based on the root key on the TSM side and the message authentication code of the preset data.

[0009] In some embodiments, the NFC controller is further used to return a verification result to the middleware in the case that the authentication token is verified successfully; the middleware is further used to: receive the verification result, perform a card opening operation, and request a message authentication code for preset data from the NFC controller.

[0010] In some embodiments, the NFC controller is further used to: in response to a data migration request sent by the application program via the middleware, send the encrypted card data to the application program via the middleware, where the application program sends the encrypted card data to the TSM.

[0011] In some embodiments, the NFC controller is further configured to send a card data update notification to the middleware or the application after the card data on the NFC side is updated; the middleware or the application is further configured to update the card data on the middleware side or the application side based on the card data update notification from the NFC controller.

[0012] In a second aspect, an embodiment of the present application provides a near field communication method applied to an NFC device including an NFC controller and middleware, where the middleware processes the transmission logic between the NFC controller and the application, and the application communicates with the TSM. The method includes: performing authentication and encrypted transmission between the NFC controller and the TSM, and the middleware transparently transmits the encrypted card data.

[0013] In some embodiments, authentication and encrypted transmission are performed between the NFC controller and the TSM based on a root key, and the root key is used to derive a session key, where: when the NFC controller includes a permanent storage area, the root key is preset in the permanent storage area; when the NFC controller has no permanent storage area, the NFC controller obtains the encrypted root key from the TSM and decrypts it using a fixed key value in the program code, and temporarily stores the decrypted root key.

[0014] In some embodiments, performing authentication and encrypted transmission between the NFC controller and the TSM includes: the NFC controller performs authentication with the TSM during card opening; after the application receives the encrypted card data sent by the TSM after successful authentication, the middleware transparently transmits the encrypted card data to the NFC controller when distributing the card data; the NFC controller stores the encrypted card data and decrypts the encrypted card data when swiping the card; or decrypts the encrypted card data and stores the decrypted card data.

[0015] In some embodiments, the NFC controller performs authentication with the TSM during card opening, including: generating a random number during card opening, where the random number is sent to the TSM via the middleware and the application; receiving a response message sent by the TSM via the application and the middleware, where the response message carries an authentication token and a message authentication code, the authentication token is generated based on the root key on the TSM side and the random number, and the message authentication code is used to verify the legality of the response message; verifying the message authentication code of the response message based on the root key on the NFC side; verifying the authentication token based on the root key on the NFC side when the message authentication code is verified; destroying the random number when the authentication token is verified, and generating a message authentication code for preset data based on the root key on the NFC side, where the generated message authentication code is sent to the TSM via the middleware and the application, so that the TSM verifies the NFC controller based on the message authentication code of the preset data on the TSM side.

[0016] In some embodiments, when the NFC controller performs identity authentication with the TSM during card opening, it further includes: when the identity authentication token passes the verification, the NFC controller returns the verification result to the middleware; the middleware receives the verification result, performs the card opening operation, and requests the message authentication code of the preset data from the NFC controller.

[0017] The near-field communication device and method provided by the embodiments of the present application can also make the CE mode have a certain degree of security and reduce the hardware cost of the NFC device in the case where the NFC device does not have security modules such as eSE and SWP SIM. Based on the identity authentication and encrypted transmission functions provided by the NFC controller, it is possible to implement a custom security solution for NFC device manufacturers. During the process of docking the implementation solution, NFC device manufacturers do not need to have a development foundation for security modules such as eSE and SWP SIM, and the process of docking eSE, SWP SIM and other security modules with NFC is omitted, which can reduce the development time cost and technical threshold.

[0018] These aspects or other aspects of the present application will be more clearly understood in the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0020] Figure 1 The structural schematic diagram of an electronic device capable of applying the technical solution of the embodiment of the present application is shown.

[0021] Figure 2 The schematic block diagram of an NFC device in the prior art is shown.

[0022] Figure 3 The schematic block diagram of the NFC device of the embodiment of the present application is shown.

[0023] Figure 4 The schematic block diagram of identity authentication and encrypted transmission of the embodiment of the present application is shown.

[0024] Figure 5 The schematic block diagram of identity authentication of the embodiment of the present application is shown.

[0025] Figure 6 The schematic diagram of an exemplary card opening interaction process of the embodiment of the present application is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] The embodiments of the present application will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the accompanying drawings are exemplary only for explaining the present application and should not be construed as limiting the present application.

[0027] To enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the scope of protection of the present application.

[0028] In the embodiments of the present application, it should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0029] Moreover, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0030] In the description of the embodiments of the present application, words such as "example" or "for example" are used to indicate examples, explanations or descriptions. Any embodiment or design described as "example" or "for example" in the embodiments of the present application is not construed as being more preferred or having more advantages than another embodiment or design. The use of words such as "example" or "for example" is intended to present relative concepts in a clear manner.

[0031] In addition, "a plurality" in the embodiments of the present application means two or more. In view of this, "a plurality" in the embodiments of the present application can also be understood as "at least two". "At least one" can be understood as one or more, for example, understood as one, two or more. For example, including at least one means including one, two or more, and does not limit which ones are included. For example, including at least one of A, B, and C, then what can be included are A, B, C, A and B, A and C, B and C, or A, B, and C.

[0032] It should be noted that in the embodiments of the present application, "and / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / ", unless otherwise specified, generally represents an "or" relationship between the preceding and following associated objects.

[0033] It should be pointed out that in the embodiments of the present application, "connection" can be understood as electrical connection, and the connection of two electrical components can be a direct or indirect connection between the two electrical components. For example, the connection between A and B can be either a direct connection between A and B or an indirect connection between A and B through one or more other electrical components.

[0034] Figure 1 The structural schematic diagram of an electronic device capable of applying the technical solutions of the embodiments of the present application is shown. Please refer to Figure 1 As shown, the typical hardware structure of the electronic device 100 may include: a processor 101, a memory 102, a radio device 103, an audio output unit 104, an A / V input unit 105, a display unit 106, a user input unit 107, an interface unit 108, and a power supply 109. It should be understood that Figure 1 This is only an exemplary illustration of the embodiments of the present application and does not limit the electronic device 100.

[0035] The display unit 106 includes various types of display panels and can display visible graphics, such as a graphical user interface (GUI). The user input unit 107 may include a touch panel, and the touch panel may cover the display panel. The audio output unit 104 includes a speaker, etc. The A / V input unit 105 includes an image processor 1051 and a microphone 1052.

[0036] The memory 102 can store data and instructions that can run on the processor 101. The instructions include an operating system 111, etc. Refer to Figure 1 As shown, the memory 102 stores one or more application programs 110. The one or more application programs 110 include weather, instant messaging, phone, text message, email, or stock, etc.

[0037] Please continue to refer to Figure 1As shown, in the embodiment of the present application, the electronic device 100 further includes an NFC device 200. The processor 101 can communicate with the NFC device 200. Specifically, the processor 101 can communicate with the NFC device 200. The processor 101 and the NFC device 200 can be connected through a bus interface such as an I2C (Inter-Integrated Circuit) interface or a UART (Universal Asynchronous Receiver / Transmitter) interface. The communication between the processor 101 and the NFC device 200 can be carried out through the NCI (NFC Controller Interface) protocol. The aforementioned operating system 111 and / or application program 110 can control the NFC device 200 to implement NFC functions such as mobile payment, identity recognition, access control, obtaining electronic tag information, data exchange, device connection, electronic wallet, and electronic bus card.

[0038] The electronic device 100 can operate in an active mode or a passive mode. The active mode can include a peer-to-peer mode (Peer-to-Peer mode, abbreviated as P2P mode) and a reader / writer mode (Reader / Writer mode, abbreviated as RW mode). In the peer-to-peer mode, two electronic devices 100 with NFC functions are paired and connected to enable point-to-point data transmission, such as quickly transferring files between two electronic devices 100. In the reader / writer mode, the electronic device 100 with NFC function reads and writes information from media such as tags, stickers, and business cards with NFC chips. The passive mode includes a card emulation mode (Card Emulation mode, abbreviated as CE mode), and the card emulation mode is also called NFC card emulation mode, card mode, card emulation mode, etc. In the card emulation mode, the NFC device works similar to a standard contactless smart card. This allows the electronic device 100 to be used in the existing contactless smart card infrastructure to implement operations such as access control, contactless payment, firmware replacement, or data transmission. The NFC device emulating the smart card usually works in the passive NFC mode, and the data transmission is secure at this time. In the card emulation mode, the electronic device 100 can be used as a credit card, transportation card, access control card, train ticket, etc.

[0039] In some specific implementations, refer to Figure 2 As shown, the NFC device 200 can include an NFC controller 201, an NFC antenna interface 202, and an NFC antenna 203. The NFC controller 201 can implement the processing of analog and digital protocols defined by NFC card emulation, reader / writer, and peer-to-peer modes. The NFC antenna 203 can perform electromagnetic coupling with the antenna of the NFC reader 300 to transmit electromagnetic signals through near-field coupling.

[0040] Continue to refer toFigure 2 , the NFC antenna 203 can adopt a dedicated NFC antenna and / or reuse components of the electronic device. For example, the frame of the electronic device 100 is reused as the NFC antenna 203. In the electronic device 100 with a wireless charging coil, the wireless charging coil of the electronic device 100 can be reused as the NFC antenna 203. Based on the product application scenario and functional requirements, the NFC device 200 can include one or more NFC antennas 201. In a specific implementation, for example, in a smart phone, NFC antennas can be set at positions such as the top and the middle of the back to facilitate communication between the smart phone and an NFC reader or reading NFC cards and NFC tags. The NFC antenna interface 202 can include a receiving matching circuit, a filtering circuit, a receiving circuit, etc. The matching circuit can be used to match the operating frequency and input impedance, and the filtering circuit can be used to filter out the high-order harmonics of the crystal oscillator.

[0041] In the prior art, continue to refer to Figure 2 , the NFC device 200 further includes a Secure Element (SE) 204. The secure unit 204 is a tamper-proof hardware module for securely storing and processing sensitive information such as payment information and identity credentials. The secure unit 204 can run one or more card applications (Applets), which are also called smart card applications or applets. A card application is a small program unit running inside the secure unit 204, and it can be regarded as a software module that executes specific functions in the secure space of the secure unit 204. The secure unit 204 can have various integration methods in the electronic device 100. In some specific implementations, the secure unit 204 is used as a secure chip in the electronic device 100. In this case, the secure unit 204 is also called an Embedded Secure Element (eSE) or a built-in secure unit. When the secure unit 204 is an embedded secure unit, the secure unit 204 is generally only connected to the NFC controller 201, and the secure unit 204 can communicate with the processor 101 of the electronic device 100 through the NFC controller 201 and perform near-field communication through the NFC controller 201. For other integration methods of the secure unit 204, please refer to the prior art, and this specification will not elaborate on this.

[0042] In the electronic device 100, when the application 110 (such as the wallet 110a) needs to perform operations such as payment and authentication, it generally first accesses the card application in the secure element 204, and the card application implements functions such as transaction processing and authentication. In the NFC card emulation mode, when an external NFC reader 300 initiates a communication request, the NFC controller 201 can transfer the signal of the NFC reader 300 to the secure element 204. After receiving the request, the card application in the secure element 204 performs corresponding processing according to the type of the request (such as authentication request, payment request, etc.). After the processing is completed, the card application returns the result to the NFC reader 300 through the secure element 204 and the NFC controller 201.

[0043] In the prior art, in the CE mode, most NFC systems request the TSM and store the card data downloaded from the TSM in the secure element 204. That is, if the CE mode is to be used and security is to be ensured, a secure element 204 or a similar security module must be added to the NFC system, which greatly increases the application threshold of the card emulation function of the NFC system and also greatly increases the cost of the chip.

[0044] For this reason, the embodiments of the present application provide an NFC device, which may include, but is not limited to, the Figure 1 electronic device 100 as shown. In the embodiments of the present application, as Figure 3 shown, the NFC device 400 may include an application 401, middleware 402, and an NFC controller 403. The application 401 and the middleware 402 run on the application processor. The application processor may include, but is not limited to, the Figure 1 processor 101 as shown.

[0045] The application 401 may include a wallet, a client of a bus company, a client of an access card company, etc. The application 401 communicates with the TSM 500 to implement downloading from the TSM 500 and uploading user data to be stored to the TSM 500.

[0046] The NFC controller 403 can implement the processing of analog and digital protocols defined by NFC card emulation, reader / writer, and peer-to-peer mode. The middleware 402 processes the transmission logic between the NFC controller 403 and the application 401. The middleware 402 and the NFC controller 403 can communicate based on the communication commands of the NFC Controller Interface (NCI) specification, including but not limited to Application Protocol Data Unit Transfer (APDU Transfer), Card Info Update, and Get Card Info, etc. The middleware 402 can provide an Application Programming Interface (API) to the application 401, and the application 401 interacts with the middleware 402 by calling the API of the middleware 401.

[0047] In the embodiment of the present application, in the CE mode, the NFC controller 403 forwards the commands that need to be processed and responded to by the application 401 during the interaction with the NFC reader to the middleware 402, and the middleware 402 forwards the command to the application 401, and the application 401 processes the command corresponding to the command. Correspondingly, the application 401 forwards the response to the middleware 402, and the middleware 402 forwards the response to the NFC controller 403, and the NFC controller 403 processes the response, such as sending a response to the NFC reader, etc.

[0048] In order to enable the NFC device to dispense with security units and similar hardware, and at the same time make the CE mode have a certain degree of security, in the embodiment of the present application, identity authentication and encrypted transmission are implemented through the NFC controller 403. As Figure 3 shown, identity authentication and encrypted transmission are carried out between the NFC controller 403 and the TSM 500, and the middleware 402 transparently transmits the encrypted card data. Continuing to refer to Figure 3 , the transmission nodes of the card data include the TSM 500, the application 401, the middleware 402, and the NFC controller 403. The card data is encrypted and transmitted between the TSM 500 and the NFC controller 403. The application 401 and the middleware 402 cannot obtain the ciphertext, and other programs cannot steal the card data, ensuring the security of the card data.

[0049] In some embodiments, authentication and encrypted transmission are performed between the NFC controller 403 and the TSM 500 based on a root key, which is used to derive a session key. The session key can be used to generate an authentication token and encrypt data. In some implementations, the NFC controller 403 includes permanent storage areas such as flash memory (FLASH), read-only memory (ROM), and one-time programmable (OTP) memory. The root key on the NFC side can be pre-set in the permanent storage area of the NFC controller 403. In a specific implementation, the production line equipment can write the root key into the permanent storage area of the NFC controller 403 before the NFC device leaves the factory. In some implementations, when the NFC controller 403 has no permanent storage area, the NFC controller 403 can obtain the encrypted root key from the TSM 500 and decrypt it using the fixed key value in the program code, and temporarily store the decrypted root key.

[0050] In some embodiments, refer to Figure 4 As shown, the NFC controller 403 performs authentication with the TSM 500 when opening a card. After the authentication between the TSM 500 and the NFC controller 403 is passed, the encrypted card data is sent to the application program 401. The application program 401 receives the encrypted card data sent by the TSM 500 and sends the encrypted card data to the middleware 402. The middleware 402 receives the request from the application program 401 to issue card data, and in response to this request, transparently transmits the encrypted card data to the NFC controller 403 when issuing the card data. The NFC controller 403 can store the encrypted card data and decrypt the encrypted card data when swiping the card; or decrypt the encrypted card data and store the decrypted card data.

[0051] The authentication between the NFC controller 403 and the TSM 500 based on the root key can adopt a challenge-response authentication mechanism. In some embodiments, the authentication between the NFC controller 403 and the TSM 500 based on the root key, refer to Figure 5 As shown, includes:

[0052] The NFC controller 403 generates a random number during card opening. This challenge is sent to the TSM 500 via the middleware 402 and the application 401. Specifically, the application 401 can initiate the card opening process based on user operations to generate an NFC card. When the application 401 initiates the card opening process, it requests the random number of the NFC controller 403 from the middleware 402. The middleware 402 requests the NFC controller 403 to generate a random number. The NFC controller 403 generates a random number in response to the request of the middleware 402, and this random number is sent to the application 401 via the middleware 402. The application 401 requests card opening from the TSM 500, and this request carries the random number generated by the NFC controller 403.

[0053] The TSM 500 receives the request sent by the application 401, obtains the random number generated by the NFC controller 403 from the request, and generates an authentication token and a message authentication code based on the root key on the TSM side and this random number. The TSM 500 carries the authentication token and the message authentication code in the response message and sends this response message to the application 401. The message authentication code is used to verify the legality of the response message. The application 401 sends this response message to the NFC controller 403 via the middleware 402.

[0054] The NFC controller 403 verifies the message authentication code of the response message based on the root key on the NFC side. When the message authentication code is verified successfully, the NFC controller 403 verifies the authentication token based on the root key on the NFC side. When the authentication token is verified successfully, the NFC controller 403 confirms that the TSM 500 is legal, destroys the random number, and generates a message authentication code for the preset data based on the root key on the NFC side. The message authentication code generated by the NFC controller 403 is sent to the TSM 500 via the middleware 402 and the application 401. The TSM 500 verifies the NFC controller based on the root key on the TSM side and the message authentication code of the preset data. In some implementations, when the authentication token is verified successfully, the NFC controller 403 returns the verification result to the middleware 401; the middleware 402 receives the verification result, performs the card opening operation, and requests the message authentication code for the preset data from the NFC controller 403. The NFC controller 403 generates a message authentication code for the preset data based on the root key on the NFC side in response to the request of the middleware 402. If the NFC controller passes the verification, the NFC controller 403 and the TSM 500 complete mutual authentication.

[0055] After the NFC controller 403 and the TSM 500 complete mutual authentication, the TSM 500 encrypts the card data based on the root key and sends the encrypted card data to the application 401. The application 401 receives the encrypted card data sent by the TSM 500 and requests the middleware 402 to send the card data to the NFC controller 403. When sending the card data, the middleware 402 transparently transmits the encrypted card data to the NFC controller 403. The NFC controller 403 receives and stores the card data. In one implementation, the NFC controller 403 stores the encrypted card data and decrypts the encrypted card data during card swiping. In this implementation, the NFC controller 403 storing the encrypted card data can ensure the security of the card data. In other implementations, the NFC controller 403 decrypts the encrypted card data, stores the decrypted card data, and uses the stored decrypted card data for card swiping during card swiping, which can avoid decrypting during card swiping and reducing the card swiping speed. In addition, the NFC controller 403 storing the card data can enable offline and shutdown card swiping.

[0056] In some embodiments, the NFC controller 403 can store the card data in the NFC controller 403. The NFC controller 403 can use the card data stored by itself for card swiping to achieve offline and shutdown card swiping. The NFC controller 403 can include storage modules such as a random access memory (RAM) and a flash memory (FLASH), or the NFC controller 403 can be externally connected with storage modules such as an E2PROM, a RAM, and a FLASH. The external storage has a slower read and storage speed compared to the internal storage, and the card data can be stored in these storage modules. In a specific implementation, the card data can be temporarily stored in the RAM of the NFC controller 403. In a specific implementation, the NFC controller 403 can store the encrypted card data and decrypt the encrypted card data during card swiping, which can ensure the security of the card data. In other implementations, the NFC controller 403 decrypts the encrypted card data, stores the decrypted card data, and uses the stored decrypted card data for card swiping during card swiping, which can avoid decrypting during card swiping and reducing the card swiping speed.

[0057] In some embodiments, the application 401 or the middleware 402 may store the encrypted card data. After the application 401 or the middleware 402 sends the card data to the NFC controller 403, the card data on both sides is not synchronized in real time. If the external NFC reader modifies the card data, the application 401 or the middleware 402 can actively read the card data stored in the NFC controller 403 by means of software NCI commands or reading through the hardware interface. During the idle period, the NFC controller 403 can report a Card Info update notification to synchronize and modify the card data for the application 401 or the middleware 402. In addition, after the card data on the NFC side is updated, the NFC controller 403 can send a card data update notification to the middleware 402 or the application 401. The middleware 402 or the application 401 can update the card data on the middleware side or the application side based on the card data update notification from the NFC controller 403.

[0058] In some embodiments, the card data can be directly uploaded to the TSM 500 by operating the application 401. Specifically, in response to a data migration request sent by the application 401 via the middleware 402, the NFC controller 403 sends the encrypted card data to the application 401 via the middleware 402. The application 401 sends the encrypted card data to the TSM 500. After the user replaces another NFC device, after the TSM 500 verifies the user's personal information, the required card data can be directly sent to the new NFC device.

[0059] The embodiments of the present application further provide a near-field communication method, which is applied to an NFC device including an NFC controller and middleware. The NFC device includes, but is not limited to Figure 1 , 3 the NFC device shown. In the NFC device, the middleware processes the transmission logic between the NFC controller and the application, and the application communicates with the TSM. Identity authentication and encrypted transmission are performed between the NFC controller and the TSM, and the middleware transparently transmits the encrypted card data.

[0060] In some embodiments, identity authentication and encrypted transmission are performed between the NFC controller and the TSM based on a root key. The root key is used to derive a session key, and the session key can be used to generate an identity authentication token and data encryption. In some implementations, the root key on the NFC side can be pre-set in the permanent storage area of the NFC controller. In a specific implementation, the production line device can write the root key into the permanent storage area of the NFC controller before the NFC device leaves the factory. In some implementations, when the NFC controller has no permanent storage area, the NFC controller can obtain the encrypted root key from the TSM and decrypt it using a fixed key value in the program code, and temporarily save the decrypted root key.

[0061] In some embodiments, as Figure 4 shown, the NFC controller authenticates with the TSM when opening a card. After the authentication between the TSM and the NFC controller is passed, the TSM sends the encrypted card data to the application. The application receives the sent encrypted card data and sends the encrypted card data to the middleware. The middleware receives the card data issuance request from the application and transparently transmits the encrypted card data to the NFC controller when issuing the card data in response to the request. The NFC controller can store the encrypted card data and decrypt the encrypted card data when swiping the card; or decrypt the encrypted card data and store the decrypted card data.

[0062] The authentication between the NFC controller and the TSM is based on the root key and can adopt the Challenge-Response authentication mechanism. In some embodiments, the authentication between the NFC controller and the TSM is based on the root key, as Figure 5 shown, including:

[0063] The NFC controller generates a random number when opening a card, and this challenge is sent to the TSM via the middleware and the application. Specifically, the application can initiate the card opening process based on user operations to generate an NFC card. When the application initiates the card opening process, it requests the random number of the NFC controller from the middleware. The middleware requests the NFC controller to generate a random number. The NFC controller generates a random number in response to the request of the middleware, and this random number is sent to the application via the middleware. The application requests to open a card from the TSM, and this request carries the random number generated by the NFC controller.

[0064] The TSM receives the request sent by the application, obtains the random number generated by the NFC controller from the request, and generates an authentication token and a message authentication code based on the root key on the TSM side and this random number. The TSM carries the authentication token and the message authentication code in the response message and sends this response message to the application. The message authentication code is used to verify the legality of the response message. The application sends this response message to the NFC controller via the middleware.

[0065] The NFC controller verifies the message authentication code of the root key verification response message on the NFC side. When the message authentication code verification passes, the NFC controller verifies the identity authentication token based on the root key on the NFC side. When the identity authentication token verification passes, the NFC controller confirms that the TSM is legal, destroys the random number, and generates the message authentication code of the preset data based on the root key on the NFC side. The message authentication code generated by the NFC controller is sent to the TSM via the middleware and the application. The TSM verifies the NFC controller based on the root key on the TSM side and the message authentication code of the preset data. In some implementations, when the identity authentication token verification passes, the NFC controller returns the verification result to the middleware; the middleware receives the verification result, performs the card opening operation, and requests the message authentication code of the preset data from the NFC controller. In response to the request from the middleware, the NFC controller generates the message authentication code of the preset data based on the root key on the NFC side. If the NFC controller passes the verification, the NFC controller and the TSM complete mutual authentication.

[0066] After the NFC controller and the TSM complete mutual authentication, the TSM encrypts the card data based on the root key and sends the encrypted card data to the application. The application receives the sent encrypted card data and requests the middleware to send the card data to the NFC controller. The middleware transparently transmits the encrypted card data to the NFC controller when sending the card data. The NFC controller receives and stores the card data. In one implementation, the NFC controller stores the encrypted card data and decrypts the encrypted card data when swiping the card. In this implementation, the NFC controller stores the encrypted card data, which can ensure the security of the card data. In some other implementations, the NFC controller decrypts the encrypted card data and stores the decrypted card data, and uses the stored decrypted card data to swipe the card when swiping the card, which can avoid decrypting during swiping and reducing the swiping speed. In addition, the NFC controller stores the card data, which can achieve offline and shutdown card swiping.

[0067] In some embodiments, the NFC controller can also respond to a data migration request sent by the application via the middleware, and send the encrypted card data to the application via the middleware, where the application sends the encrypted card data to the TSM.

[0068] In some embodiments, the NFC controller can also send a card data update notification to the middleware or the application after the card data on the NFC side is updated; the middleware or the application is also used to update the card data on the middleware side or the application side based on the card data update notification from the NFC controller.

[0069] In a specific embodiment, authentication and encrypted transmission are performed between the NFC controller (NFCC) and the TSM. The message authentication code verification process and token verification process using a pre-set key are as follows Figure 6 shown. In this specific embodiment, AES-CMAC (Cipher-based Message Authentication Code), a message authentication code algorithm based on the AES encryption algorithm, is used to verify the integrity and authenticity of data. The specific description is shown in the following table:

[0070]

[0071]

[0072] In this specific embodiment, when the card emulation solution is running normally, it is imperceptible to the user and does not send additional commands or disrupt the interaction with the remote device, ensuring the integrity of the NFC system interaction.

[0073] The above are only the preferred embodiments of the present application and do not impose any formal restrictions on the present application. Although the present application has been disclosed above with preferred embodiments, it is not intended to limit the present application. Any person skilled in the art can make some modifications or equivalents by using the disclosed technical content without departing from the technical solution of the present application. However, any brief modifications, equivalent changes, and modifications made to the above embodiments based on the technical essence of the present application without departing from the technical solution content of the present application still fall within the scope of the technical solution of the present application.

Claims

1. A near field communication (NFC) device, characterized in that: include: NFC controller and middleware, where: The middleware is used to process the transmission logic between the NFC controller and the application, and the application communicates with the trusted service manager TSM; The NFC controller is used to perform identity authentication and encrypted transmission with the TSM, and the middleware is used to transparently transmit the encrypted card data.

2. The NFC device according to claim 1, characterized in that: The NFC controller and the TSM perform identity authentication and encrypted transmission based on a root key, and the root key is used to derive a session key, wherein: In the case where the NFC controller includes a permanent storage area, the root key is preset in the permanent storage area; In the case that the NFC controller has no permanent storage area, the NFC controller obtains the encrypted root key from the TSM, decrypts it using a fixed key value in the program code, and temporarily stores the decrypted root key.

3. The NFC device according to claim 1, characterized in that: The NFC controller is used to perform identity authentication with the TSM when opening the card; The middleware is used to, after the application receives the encrypted card data sent by the TSM after identity authentication is passed: transparently transmit the encrypted card data to the NFC controller when issuing the card data; The NFC controller is used to: store the encrypted card data and decrypt the encrypted card data when the card is swiped; or decrypt the encrypted card data and store the decrypted card data.

4. The NFC device according to claim 3, characterized in that: The NFC controller is used to: generating a random number when activating a card, wherein the random number is sent to the TSM via the middleware and the application; Receiving a response message sent by the TSM via the application and the middleware, wherein the response message carries an identity authentication token and a message verification code, the identity authentication token is generated based on a root key on the TSM side and the random number, and the message verification code is used to verify the legitimacy of the response message; Verifying the message authentication code of the response message based on the root key on the NFC side; If the message authentication code is verified, verifying the identity authentication token based on the root key on the NFC side; When the identity authentication token is verified successfully, the random number is destroyed, and a message verification code of preset data is generated based on the root key on the NFC side, wherein the generated message verification code is sent to the TSM via the middleware and the application, so that the TSM verifies the NFC controller based on the root key on the TSM side and the message verification code of the preset data.

5. The NFC device according to claim 4, characterized in that: The NFC controller is further configured to return a verification result to the middleware if the identity authentication token is verified successfully; The middleware is also used to: receive the verification result, perform a card opening operation, and request a message verification code of the preset data from the NFC controller.

6. The NFC device according to claim 1, wherein: The NFC controller is further configured to: in response to a data migration request sent by the application via the middleware, send the encrypted card data to the application via the middleware, wherein the application sends the encrypted card data to the TSM.

7. The NFC device according to claim 1, characterized in that: The NFC controller is further used to send a card data update notification to the middleware or the application after the card data on the NFC side is updated; the middleware or the application is further used to update the card data on the middleware side or the application side based on the card data update notification of the NFC controller.

8. A near field communication (NFC) method, characterized in that: Applied to an NFC device including an NFC controller and a middleware, the middleware processing the transmission logic between the NFC controller and an application, the application communicating with a trusted service manager TSM, the method comprising: The NFC controller performs identity authentication and encrypted transmission with the TSM, and the middleware transparently transmits the encrypted card data.

9. The NFC method according to claim 8, characterized in that: The NFC controller and the TSM perform identity authentication and encrypted transmission based on a root key, and the root key is used to derive a session key, wherein: In the case where the NFC controller includes a permanent storage area, the root key is preset in the permanent storage area; The NFC controller has no permanent storage area. The NFC controller obtains the encrypted root key from the TSM, decrypts it using a fixed key value in the program code, and temporarily stores the decrypted root key.

10. The NFC method according to claim 8, characterized in that: The NFC controller and the TSM perform identity authentication and encrypted transmission, including: The NFC controller performs identity authentication with the TSM when opening the card; After the application receives the encrypted card data sent by the TSM after identity authentication, the middleware transparently transmits the encrypted card data to the NFC controller when issuing the card data; The NFC controller stores the encrypted card data and decrypts the encrypted card data when the card is swiped; or decrypts the encrypted card data and stores the decrypted card data.

11. The NFC method according to claim 10, characterized in that: The NFC controller performs identity authentication with the TSM when opening the card, including: generating a random number when activating a card, wherein the random number is sent to the TSM via the middleware and the application; Receiving a response message sent by the TSM via the application and the middleware, wherein the response message carries an identity authentication token and a message verification code, the identity authentication token is generated based on a root key on the TSM side and the random number, and the message verification code is used to verify the legitimacy of the response message; Verifying the message authentication code of the response message based on the root key on the NFC side; If the message authentication code is verified, verifying the identity authentication token based on the root key on the NFC side; When the identity authentication token is verified successfully, the random number is destroyed, and a message verification code of preset data is generated based on the root key on the NFC side, wherein the generated message verification code is sent to the TSM via the middleware and the application, so that the TSM verifies the NFC controller based on the message verification code of the preset data based on the root key on the TSM side.

12. The NFC method according to claim 11, characterized in that: The NFC controller performs identity authentication with the TSM when opening the card, and further includes: When the identity authentication token is verified, the NFC controller returns the verification result to the middleware; The middleware receives the verification result, performs a card opening operation, and requests a message verification code of the preset data from the NFC controller.

Citation Information

Patent Citations

  • Secure reset of personal and service provider information on mobile devices

    CN103493079A

  • Mobile payment terminal, mobile payment system and mobile payment method

    CN104751329A

  • Portable secure element

    CN104992319A

  • Method and device for controlling NFC function, electronic equipment and storage medium

    CN115550913A

  • NFC function control method based on secure channel and mobile terminal equipment

    CN115604715A

Cited By

  • Near field communication device and method

    WO2026184579A1

  • Near-field communication device and method

    WO2026184583A1