Multi-Issuer Secure Element Partition Architecture for NFC Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current NFC technologies lack a methodology for managing multiple Secure Element (SE) partitions within NFC-enabled devices, leading to security vulnerabilities such as eavesdropping, data manipulation, and denial of service, as they do not permit the coexistence of multiple SEs on the same device.
Innovation Solution
A multi-issuer architecture is implemented, allowing for the allocation of multiple SE partitions to different card issuers on an NFC-enabled device, with each partition having its own access rules and unique security keys, managed by a SE partition manager, ensuring secure data integrity and privacy through implicit key management and cryptographic modules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single Secure Element partition is allocated to one card issuer, then security management is simplified, but multiple card issuers cannot coexist on the same NFC enabled device
Solution Approach 1:
The Secure Element is divided into multiple independent partitions, each allocated to a specific card issuer. Each partition contains its own security domain with dedicated access control lists and security keys, allowing multiple card issuers to coexist on the same NFC enabled device while maintaining independent security management for each issuer
Solution Approach 2:
A SE partition manager is introduced as an intermediary component that handles the complexity of managing multiple SE partitions. The manager provides a standardized interface for applications to access different card issuer partitions, abstracting away the underlying complexity of multi-issuer security management from both applications and individual card issuers
2Reliability
If proprietary proof-of-end point protocols are implemented by card issuers, then security for NFC data exchange is improved, but compatibility and coexistence with other card issuers deteriorates
Solution Approach 1:
Each card issuer partition is configured with its own local security domain containing issuer-specific access control lists and security parameters. This allows each card issuer to maintain its proprietary security requirements and proof-of-end point protocols within its own partition while coexisting with other card issuers in the same NFC enabled device through the partitioned architecture
3Adaptability or versatility
If multiple SE partitions are allocated to different card issuers, then support for multiple issuers is improved, but access control and security management complexity increases
Solution Approach 1:
The SE partition manager provides universal access control functionality that works across all card issuer partitions. It implements a standardized interface that allows applications to access any card issuer partition through a common mechanism, while each partition maintains its own issuer-specific access control lists. This multi-functional approach simplifies operation for applications while supporting multiple card issuers
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for providing secure element partitions for an NFC enabled device for a plurality of card issuers, the method comprising creating in a secure element of the NFC enabled device a plurality of secure element partitions; and allocating said secure element partitions of the secure element to the respective card issuers.