Secure Element Pairing via NFC and BLE

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for an improved method to securely pair a secure element with a second device, ensuring authorized pairing and enhanced security against fraudulent use in digital financial transactions.

Innovation Solution

A secure link is established using Bluetooth Low Energy (BLE) between a secure element and a smart device, following an initial link establishment via Near-Field Communication (NFC). This involves generating a communication encryption key, associating a status with the key, and transmitting the key and status to the smart device. The secure element and smart device then pair over a second protocol, with the secure element transmitting encrypted messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure element is paired with a smart device using traditional methods, then the pairing process is simple, but the security against fraudulent use is insufficient

Engineering Contradiction:
Improvesecurity against fraudulent useVSAvoidpairing process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing an initial NFC link before the main BLE pairing process. This preliminary NFC connection is used to securely exchange pairing information and authentication data, ensuring that the subsequent BLE pairing is already secured before full communication begins. This resolves the contradiction by adding a security layer without significantly increasing user-perceived complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a dual-protocol system where NFC acts as a trusted mediator to establish initial security credentials, which then enable the BLE connection. The NFC protocol serves as an intermediary trust layer that verifies device identity before allowing BLE communication, thereby enhancing security while maintaining a streamlined user experience through automated protocol switching.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are transmitted over the communication link, then secure communication is established, but the risk of key interception increases

Engineering Contradiction:
Improvecommunication securityVSAvoidkey interception risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by dividing the key exchange process into two distinct phases: first, a secure NFC-based key establishment phase that creates initial encryption credentials, and second, a BLE communication phase that uses those pre-established credentials. This segmentation ensures that sensitive key material is never transmitted over the less secure BLE channel, eliminating interception risks while maintaining communication security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses preliminary action by completing the encryption key establishment through NFC before any BLE communication occurs. The NFC link is used to securely provision encryption keys and authentication data in advance, so that when BLE communication begins, the keys are already securely in place and never need to be transmitted over the wireless BLE channel, thus preventing interception.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12314959B2Secure end-to-end pairing of secure element to mobile device
Publication Date: 2025.05.27 THALES DIS FRANCE SA
  • US12314959B2 patent drawing
  • US12314959B2 patent drawing
  • US12314959B2 patent drawing

AI summary

Establishing a secure link on a second protocol between a secure element and a smart device via a link on a first protocol by establishing a link on the first protocol between the secure element and the smart device, and generating, by the secure element, a communication encryption key and associating a status with the encryption key and assigning the status a first level. Transmitting the key and the status of the key from the secure element to the smart device over the link on the first protocol. The secure element and the smart device are paired over the second protocol thereby establishing a second-protocol link. Transmitting a message encrypted using the key to the smart device over the second-protocol link. Upon verifying the cardholder as an authorized cardholder for the secure element, elevating the status of the communication encryption key from the first level to a second level.