Multi-Issuer Secure Element Partition Architecture for NFC Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current NFC technologies lack a methodology for managing multiple Secure Element (SE) partitions within NFC-enabled devices, leading to security vulnerabilities such as eavesdropping, data manipulation, and denial of service, as they do not permit the coexistence of multiple SEs on the same device.

Innovation Solution

A multi-issuer architecture is implemented, allowing for the allocation of multiple SE partitions to different card issuers on an NFC-enabled device, with each partition having its own access rules and unique security keys, managed by a SE partition manager, ensuring secure data integrity and privacy through implicit key management and cryptographic modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single Secure Element partition is allocated to one card issuer, then security management is simplified, but multiple card issuers cannot coexist on the same NFC enabled device

Engineering Contradiction:
Improvesupport for multiple card issuersVSAvoidSE partition management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The Secure Element is divided into multiple independent partitions, each allocated to a specific card issuer. Each partition contains its own security domain with dedicated access control lists and security keys, allowing multiple card issuers to coexist on the same NFC enabled device while maintaining independent security management for each issuer

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A SE partition manager is introduced as an intermediary component that handles the complexity of managing multiple SE partitions. The manager provides a standardized interface for applications to access different card issuer partitions, abstracting away the underlying complexity of multi-issuer security management from both applications and individual card issuers

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If proprietary proof-of-end point protocols are implemented by card issuers, then security for NFC data exchange is improved, but compatibility and coexistence with other card issuers deteriorates

Engineering Contradiction:
ImproveNFC data securityVSAvoidmulti-issuer compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Each card issuer partition is configured with its own local security domain containing issuer-specific access control lists and security parameters. This allows each card issuer to maintain its proprietary security requirements and proof-of-end point protocols within its own partition while coexisting with other card issuers in the same NFC enabled device through the partitioned architecture

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If multiple SE partitions are allocated to different card issuers, then support for multiple issuers is improved, but access control and security management complexity increases

Engineering Contradiction:
Improvemulti-issuer supportVSAvoidaccess control management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The SE partition manager provides universal access control functionality that works across all card issuer partitions. It implements a standardized interface that allows applications to access any card issuer partition through a common mechanism, while each partition maintains its own issuer-specific access control lists. This multi-functional approach simplifies operation for applications while supporting multiple card issuers

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2839602B1Multi-issuer secure element partition architecture for NFC enabled devices
Publication Date: 2017.10.11 SECURE NFC
  • EP2839602B1 patent drawingFigure 1
  • EP2839602B1 patent drawingFigure 2
  • EP2839602B1 patent drawingFigure 3

AI summary

A method for providing secure element partitions for an NFC enabled device for a plurality of card issuers, the method comprising creating in a secure element of the NFC enabled device a plurality of secure element partitions; and allocating said secure element partitions of the secure element to the respective card issuers.