NFC Device Dual-Level Security System for Contactless Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Portable communication devices face security risks due to the potential vulnerability of virtual secure elements, which can be accessed via the internal secure element, and the need for third-party applications to protect payment data and credentials with a different security control.
Innovation Solution
The implementation of a dual-level security system using an internal secure element and an external smartcard reader, where the smartcard reader has its own keys and can activate/deactivate the secure element without accessing its content, providing independent and additional security controls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a virtual secure element is used in portable communication devices, then contactless services and application versatility are improved, but security control and data protection are worsened due to potential vulnerability and unauthorized access
Solution Approach 1:
The security system is divided into two independent parts: a virtual secure element for storing contactless applications and credentials, and a physical smartcard reader for security control. This segmentation allows the virtual secure element to provide versatile contactless services while the physical smartcard reader maintains security control, resolving the contradiction between adaptability and reliability.
Solution Approach 2:
The physical smartcard reader acts as an intermediary between the user and the virtual secure element. It provides an additional security layer by requiring physical card insertion and PIN verification before allowing access to or modification of credentials in the virtual secure element, thus enhancing security control without limiting the versatility of contactless services.
2Adaptability or versatility
If the secure element is made accessible for third-party applications, then application functionality is improved, but security integrity and data protection are worsened
Solution Approach 1:
The system performs preliminary security verification through the physical smartcard reader before allowing third-party applications to access the virtual secure element. The smartcard must be physically inserted and the correct PIN entered before any credentials can be downloaded or modified, preventing unauthorized access and maintaining security integrity while enabling legitimate application functionality.
Solution Approach 2:
The physical smartcard reader serves as an intermediary security layer that mediates between third-party applications and the virtual secure element. It controls access by verifying the smartcard and PIN, allowing applications to function while protecting the security integrity of stored credentials.
3Reliability
If a dual-level security system with physical smartcard reader is implemented, then security control and data protection are improved, but device complexity is worsened
Solution Approach 1:
The physical smartcard reader is designed to be multi-functional: it reads smartcards for authentication, controls access to the virtual secure element, and manages credential downloads. By making the additional component serve multiple security-related functions, the increase in device complexity is justified by the significant improvement in security control.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This dual-level security system ensures the secure operation of third-party applications by maintaining the internal secure element's integrity and allowing external control without compromising its data, enhancing transaction security and user authentication.
Implementation Method 1
In this battery-off mode the device is powered by a magnetic induction field issued from the point of sale system (POS)
Data Source
AI summary
The present device aggregates all kinds of contactless services such as credit card, loyalty card, micro-payment, discount card, transport card, access control, e-ticket, parking, etc. An NFC (Near Field Communication) device comprises a host CPU, a memory, a GPRS modem controlled by the CPU to access Internet, a SIM holder, an antenna and a battery. The NFC device is shaped as a credit card and it also includes a touch-screen, able to implement technical functionalities to operate contactless services, visualize his ticket/coupon and consult the latest transaction, a secure element to store and execute the contactless applications, and a ST controller connected to Host CPU and to the SE.


