HCE Authentication Key Diversification for Mobile Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current short-range communication systems, such as NFC and BLE, lack effective authentication mechanisms for Host Card Emulation (HCE) applications, making them vulnerable to theft and misuse, where stolen devices can continue to authenticate transactions beyond their intended validity.
Innovation Solution
Implementing a system that transmits HCE application data with unique identifiers and time-limited authentication keys to registered devices, diversifying the keys with expiry dates to prevent fake applications and limit the lifespan of stolen applications, and maintaining a central system for renewing these keys and tracking transactions across multiple devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If HCE application data including authentication keys is stored in mobile devices, then users can perform contactless transactions, but the authentication keys can be stolen and used on other devices leading to fraudulent transactions
Solution Approach 1:
The system performs preliminary authentication by validating the HCE application data against the central system before allowing transaction use. The authentication key is verified against the unique identifier and expiry date stored in the central system, preventing stolen keys from being used fraudulently
Solution Approach 2:
The central system provides feedback validation by checking each HCE authentication attempt against the registered unique identifier and expiry date. This feedback mechanism confirms whether the authentication key is legitimate and currently valid, blocking fraudulent transactions in real-time
2Reliability
If authentication keys are made time-limited with expiry dates, then stolen applications can be invalidated automatically, but the system complexity increases due to key management requirements
Solution Approach 1:
The central system serves multiple functions: it stores unique identifiers, manages authentication keys with expiry dates, validates HCE applications, and maintains a database of all registered devices. This multi-functional approach consolidates complexity into a single centralized system rather than distributing it across multiple components
Solution Approach 2:
The authentication key is designed as a short-lived credential that becomes invalid after its expiry date or upon detection of theft. This disposable nature of the key means that even if stolen, it has limited utility window, reducing the impact of security breaches while maintaining simple validation logic
3Reliability
If the authentication key is diversified by unique identifier and expiry date, then fake HCE applications are prevented, but the validation process becomes more complex
Solution Approach 1:
The system merges the unique identifier, expiry date, and authentication key into a single validation process. The central system combines these elements to verify the HCE application's legitimacy, preventing fake applications while maintaining a unified validation approach rather than separate checks
Data Source
AI summary
Methods and systems for authenticating a short-range communications HCE (Host Card Emulation) application for mobile communications devices. HCE application data can be transmitted to each registered mobile communications device among a group of mobile communications devices for storage of the HCE application data in a non-volatile memory associated with each registered mobile communications device. The HCE application data include a unique identifier, an expiry date, and an authentication key valid only for a user of each registered mobile communications device. The authentication key can then be diversified by the expiry date and the unique identifier so that the authentication key is only usable for a limited amount of time and the unique identifier is only usable for a single mobile communications device.


