Secure Element Card Emulation with Dynamic Communication Modes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless card and NFC technologies face challenges in implementing secure and efficient plain and encrypted communication between mobile devices and Point of Sale (PoS) devices, leading to security concerns and performance degradation.
Innovation Solution
A remote load and update card emulation support apparatus and method that utilize a secure element executing command sets with secure and plain communication keys to authenticate and manage operations, ensuring secure communication without performance degradation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted communication is used between mobile device and PoS device, then security is improved, but communication performance degrades
Solution Approach 1:
The communication protocol is segmented into two distinct modes: encrypted communication mode for secure operations (card updates, authentication) and plain communication mode for standard transactions. This segmentation allows the system to apply encryption only when necessary, maintaining security for critical operations while preserving communication performance for routine transactions.
Solution Approach 2:
The communication mode is made dynamic and adaptable based on the operation being performed. The system automatically switches between encrypted and plain communication modes depending on whether the operation requires enhanced security (e.g., card provisioning, key management) or standard transaction processing. This dynamic approach optimizes the balance between security and performance.
2Reliability
If secure element with multiple command sets is implemented, then security and functionality are improved, but device complexity increases
Solution Approach 1:
The secure element is designed as a universal platform capable of executing multiple command sets (encrypted read-write, plain read-write, encrypted read) within a single hardware component. This multi-functionality consolidates what would otherwise require separate security modules, allowing the secure element to handle both encrypted and plain communication operations, as well as authentication and data storage functions, thereby reducing overall system complexity while maintaining enhanced security.
3Adaptability or versatility
If remote loading and updating of card data is enabled, then flexibility and user convenience are improved, but security risks increase
Solution Approach 1:
Security measures are implemented in advance before remote loading and updating operations occur. The system pre-configures encrypted communication channels, pre-authenticates user identities, and pre-establishes secure protocols for data transmission. By performing these security preparations beforehand, the system enables flexible remote operations while mitigating security risks through proactive protective measures.
Solution Approach 2:
The secure element acts as an intermediary between the mobile device and remote servers during data loading and updating operations. It mediates the communication by handling encrypted data transmission, verifying authentication credentials, and controlling access to card data. This intermediary role isolates the vulnerable remote communication interfaces from the sensitive card data, reducing security risks while maintaining operational flexibility.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Remote load and update card emulation support may include providing emulation support for an emulated card by executing a command set from command sets that include an encrypted read write command set that uses a secure communication read write (SCRW) key, a plain read write command set that uses a plain communication read write (PCRW) key, and an encrypted read command set that uses a secure communication read only (SCR) key.