Secure Element Command Segmentation for Emulated Card Security and Performance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless transaction and NFC technologies face challenges in implementing secure and efficient plain and encrypted communication with respect to emulated cards, where plain communication lacks security and encrypted communication degrades performance on Point of Sale (PoS) devices.
Innovation Solution
A remote load and update card emulation support apparatus and method that utilizes a secure element to execute command sets including an encrypted read-write command set, a plain read-write command set, and an encrypted read-only command set, using secure communication keys to authenticate and manage operations, ensuring secure and efficient communication without performance degradation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted communication is used for emulated card operations, then security is improved, but performance on PoS devices degrades
Solution Approach 1:
The patent segments communication operations into three distinct command sets: encrypted read-write commands, plain read-write commands, and encrypted read-only commands. This segmentation allows the system to apply encryption selectively based on operation type, maintaining security for critical operations while using plain text for performance-sensitive operations, thereby resolving the contradiction between security and performance.
Solution Approach 2:
Different communication modes (encrypted vs. plain) are applied to different local contexts or operation types. Encrypted communication is used for read-only and read-write operations requiring high security, while plain communication is used for operations where performance is critical and security risk is lower. This local differentiation resolves the universal contradiction by optimizing each operation type independently.
2Productivity
If plain communication is used for emulated card operations, then performance is improved, but security is compromised
Solution Approach 1:
The communication protocol is segmented into multiple command sets with different security levels. Plain read-write command sets provide high performance for operations where security requirements are lower, while encrypted command sets handle security-critical operations. This segmentation resolves the contradiction by allowing plain communication to improve performance without universally compromising security.
Solution Approach 2:
The system applies different communication qualities (plain vs. encrypted) to different operational contexts. Plain communication is used locally for performance-critical operations, while encrypted communication is used locally for security-critical operations. This contextual differentiation resolves the contradiction by optimizing performance where possible without sacrificing security where needed.
3Adaptability or versatility
If multiple command sets are implemented for different communication modes, then communication flexibility is improved, but device complexity increases
Solution Approach 1:
The secure element is designed with multi-functionality to execute multiple types of command sets (encrypted read-write, plain read-write, encrypted read-only). This universal capability allows a single device component to handle diverse communication requirements, improving flexibility without proportionally increasing complexity, as the same hardware foundation supports multiple communication modes.
Data Source
AI summary
Remote load and update card emulation support may include providing emulation support for an emulated card by executing a command set from command sets that include an encrypted read write command set that uses a secure communication read write (SCRW) key, a plain read write command set that uses a plain communication read write (PCRW) key, and an encrypted read command set that uses a secure communication read only (SCR) key.


