NFC Secure Element Authorization for Confidential Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices face challenges in securely exchanging secret and critical data during near-field communication (NFC) transactions, lacking protection and confidentiality.

Innovation Solution

Implementing a mobile terminal with a processor, a near-field communication module, and a secure element distinct from the processor, where the near-field communication module ciphers and deciphers data using keys supplied by the secure element, and an interface software manages authorization for data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If secret data and critical data are exchanged between modules during NFC transactions, then the functionality and utility of the device is improved, but the security and confidentiality of the data is compromised

Engineering Contradiction:
ImproveNFC transaction functionalityVSAvoiddata confidentiality
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments data into different categories (secret data, critical data, non-critical data) and applies different protection mechanisms to each. The secure element is physically separated from the processor, creating distinct security zones. This segmentation allows NFC transactions to proceed while protecting sensitive data through isolated storage and controlled access mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element acts as an intermediary between the processor and external NFC communications. It mediates data exchanges by receiving data from the processor, storing it securely in isolated memory, and controlling access through authorized applications. This intermediary role prevents direct exposure of secret data while enabling necessary NFC functionalities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If data is stored in the processor for NFC transactions, then the device complexity is reduced, but the security protection of sensitive data is insufficient

Engineering Contradiction:
Improvesystem structureVSAvoiddata protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system divides the device into two distinct components: the processor for general operations and the secure element for secure data storage. This segmentation increases device complexity but provides necessary security protection by isolating sensitive data from the main processor, preventing unauthorized access while enabling NFC functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element extracts and isolates critical security functions from the main processor. By taking out the secure data storage and management capabilities into a separate dedicated component, the system enhances data protection reliability while maintaining manageable device complexity through specialized functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If all applications can access NFC data, then the ease of operation is improved, but the security control over critical data is weakened

Engineering Contradiction:
Improveapplication accessVSAvoidaccess control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements dynamic access control where application permissions are not static but can be granted or revoked based on security requirements. The secure element dynamically manages which applications can access stored data, allowing flexible operation while maintaining security control. Authorized applications can access data when needed, but unauthorized applications are blocked, balancing ease of operation with security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different access rights are assigned to different applications based on their specific needs and security clearances. Instead of uniform access for all applications, the system applies local quality control where each application receives appropriate access permissions for its function, enabling ease of operation for authorized apps while maintaining security through differentiated access control.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12475447B2NFC transaction
Publication Date: 2025.11.18 STMICROELECTRONICS BELGIUM
  • US12475447B2 patent drawing
  • US12475447B2 patent drawing
  • US12475447B2 patent drawing

AI summary

In an embodiment a method for implementing a NFC transaction between a mobile terminal and a distant module is disclosed. The terminal includes a processor hosting an application configured to establish the NFC transaction and an interface software configured to execute instructions of the application, a near-field communication module and a secure element distinct from the processor. The method includes requesting, by the application via the interface software, which verifies whether the application is authorized to communicate with the secure element, authorization to implement the NFC transaction from the secure element, sending, by the secure element, a first temporary authorization to the interface software, verifying, by the interface software, at least for a first time when the near-field communication module receives first data from the distant module, whether the interface software has received the first temporary authorization and transmitting, by the interface software, the first data to the application when the interface software has received the first temporary authorization.