HCE Authentication Key Diversification for Mobile Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current short-range communication systems, such as NFC and BLE, lack effective authentication mechanisms for Host Card Emulation (HCE) applications, making them vulnerable to theft and misuse, where stolen devices can continue to authenticate transactions beyond their intended validity.

Innovation Solution

Implementing a system that transmits HCE application data with unique identifiers and time-limited authentication keys to registered devices, diversifying the keys with expiry dates to prevent fake applications and limit the lifespan of stolen applications, and maintaining a central system for renewing these keys and tracking transactions across multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If HCE application data including authentication keys is stored in mobile devices, then users can perform contactless transactions, but the authentication keys can be stolen and used on other devices leading to fraudulent transactions

Engineering Contradiction:
Improvecontactless transaction capabilityVSAvoidtransaction security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication by validating the HCE application data against the central system before allowing transaction use. The authentication key is verified against the unique identifier and expiry date stored in the central system, preventing stolen keys from being used fraudulently

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The central system provides feedback validation by checking each HCE authentication attempt against the registered unique identifier and expiry date. This feedback mechanism confirms whether the authentication key is legitimate and currently valid, blocking fraudulent transactions in real-time

Inventive Principle:
Principle #23Feedback

2Reliability

If authentication keys are made time-limited with expiry dates, then stolen applications can be invalidated automatically, but the system complexity increases due to key management requirements

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoidauthentication key management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The central system serves multiple functions: it stores unique identifiers, manages authentication keys with expiry dates, validates HCE applications, and maintains a database of all registered devices. This multi-functional approach consolidates complexity into a single centralized system rather than distributing it across multiple components

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication key is designed as a short-lived credential that becomes invalid after its expiry date or upon detection of theft. This disposable nature of the key means that even if stolen, it has limited utility window, reducing the impact of security breaches while maintaining simple validation logic

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If the authentication key is diversified by unique identifier and expiry date, then fake HCE applications are prevented, but the validation process becomes more complex

Engineering Contradiction:
Improveauthentication securityVSAvoidvalidation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the unique identifier, expiry date, and authentication key into a single validation process. The central system combines these elements to verify the HCE application's legitimacy, preventing fake applications while maintaining a unified validation approach rather than separate checks

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11743243B2Post billing short-range communications HCE (host card emulation) method and system
Publication Date: 2023.08.29 CONDUENT BUSINESS SERVICES LLC
  • US11743243B2 patent drawing
  • US11743243B2 patent drawing
  • US11743243B2 patent drawing

AI summary

Methods and systems for authenticating a short-range communications HCE (Host Card Emulation) application for mobile communications devices. HCE application data can be transmitted to each registered mobile communications device among a group of mobile communications devices for storage of the HCE application data in a non-volatile memory associated with each registered mobile communications device. The HCE application data include a unique identifier, an expiry date, and an authentication key valid only for a user of each registered mobile communications device. The authentication key can then be diversified by the expiry date and the unique identifier so that the authentication key is only usable for a limited amount of time and the unique identifier is only usable for a single mobile communications device.