NFC Secure Element Data Access Modes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure wireless communication systems face challenges in securely storing and managing identification data, especially when power is low or unavailable, and in preventing unauthorized changes to this data.

Innovation Solution

An apparatus comprising a memory circuit, a near-field communication (NFC) controller, and a secure element that operates in update, read, and read-only modes to securely store and manage identification data, with access limited to the secure element and power received via the NFC antenna, allowing for secure data storage and retrieval even when power is low.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If information is stored in a portable device for secure wireless communication, then data security is improved, but access to the information becomes difficult when power is lost or low

Engineering Contradiction:
Improvedata securityVSAvoidaccess to information
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary device (external reader or programming device) that can communicate with the portable device via NFC to provide power and enable data access when the portable device's internal power is insufficient or lost. This intermediary acts as a mediator that bridges the gap between secure storage and accessible retrieval.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The NFC interface is designed to serve multiple functions: it enables both secure data communication and power transfer. The same NFC antenna and controller used for authenticated data exchange can also receive power from an external source, allowing the secure element to maintain operation and enable data access even when internal power is depleted.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If user input such as PIN is required for authorization, then security is improved, but the communication process becomes more complex and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure element performs self-authentication by presenting cryptographic credentials to the terminal without requiring user intervention. The authenticated session establishes secure communication automatically, and the secure element can then access and transmit stored information without requiring additional user input for each data retrieval operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authentication is performed in advance during the initial connection phase. Once authenticated, the secure element establishes a trusted session that allows subsequent data access operations to proceed without requiring repeated user authorization, thereby simplifying the overall communication process while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Stability of the object's composition

If the secure element restricts access to ID data, then data integrity is improved, but the ability to update and manage data becomes more difficult

Engineering Contradiction:
Improvedata integrityVSAvoiddata management
Core Design Contradiction:
Stability of the object's compositionVSEase of manufacture

Solution Approach 1:

The patent implements dynamic access control where the secure element can transition between different operational states. During manufacturing and initialization, the secure element accepts data writes in a programmable state. After data is written, the secure element can transition to a read-only state to prevent unauthorized modifications, thereby maintaining data integrity while allowing necessary data management operations during setup.

Inventive Principle:
Principle #15Dynamics

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Ensures secure storage and management of identification data, preventing unauthorized changes and maintaining accessibility during low power conditions, suitable for various applications including payment authorization and device authentication.

Implementation Method 1

a near-field communication (NFC) controller circuit (150) that communicates with and receives power via a near-field communication antenna

Methodology Applied
Scientific EffectElectromagnetic Induction: Electromagnetic Induction

Data Source

PatentUS9281872B2Near-field communication authentication
Publication Date: 2016.03.08 NXP BV
  • US9281872B2 patent drawing
  • US9281872B2 patent drawing
  • US9281872B2 patent drawing

AI summary

Various aspects are directed to circuit apparatuses, portable electronic devices, and executable applets pertaining to storing and providing secure access to data. As consistent with one or more embodiments, an apparatus includes a memory circuit that stores executable applet data, a near-field communication (NFC) controller that communicates and receives power via an NFC antenna, and a secure element connected to and powered by the NFC controller circuit (e.g., and operable within a portable device). The secure element executes the applet data as follows. In response to an update command and identification (ID) data, the secure element operates in an update mode by storing the ID data. In response to a read command, the secure element operates in a read mode by providing access to the stored ID data. In response to a read-only command, the secure element operates in a read-only mode by providing read-only access to the stored ID data and preventing changes to the stored ID data. With this approach, the ID data can be stored (e.g., in a manufacturing environment) and future changes thereto can be prevented.