Secure Element Isolating NFC Transaction Data from Application Processor
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional programmable portable devices, such as mobile phones and PDAs, are vulnerable to malicious software that can corrupt transaction data during contactless transactions, leading to unintended payment amounts being processed.
Innovation Solution
A method that requires users to enter agreed transaction data, monitors and verifies the transaction data exchanged between the device and an external device, and prevents or interrupts transactions if the data differs from the agreed amount, using a communication controller to ensure secure transactions by encapsulating and accompanying data with specific information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional programmable portable devices are used for transactions, then ease of operation and versatility are improved, but security and reliability deteriorate due to vulnerability to malicious software
Solution Approach 1:
The patent introduces a dedicated secure element or security module as an intermediary component between the application processor and the transaction execution. This secure element independently verifies transaction data integrity and authenticates communication partners, preventing malicious software in the main application processor from corrupting transaction data while maintaining the device's programmable versatility.
Solution Approach 2:
The patent segments the device into distinct functional zones: a secure element for cryptographic operations and transaction verification, and a general-purpose application processor for user interactions. This segmentation isolates the security-critical functions from the potentially compromised application software, allowing the device to maintain both versatility and reliability.
2Reliability
If transaction data is monitored and verified against agreed data, then reliability and security are improved, but device complexity increases
Solution Approach 1:
The secure element autonomously performs cryptographic verification of transaction data against agreed parameters without requiring complex monitoring systems in the application processor. The security module self-manages its verification logic, using pre-shared keys or certificates to authenticate transaction integrity, thereby improving reliability while minimizing added complexity.
Solution Approach 2:
The patent changes the verification parameters from complex multi-step validation procedures to simplified cryptographic comparisons. Instead of monitoring multiple data attributes, the system uses cryptographic hashes and digital signatures to verify transaction data integrity, reducing the complexity of the monitoring system while enhancing reliability.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach effectively prevents unauthorized transactions by ensuring that only verified and agreed-upon transaction data is processed, protecting users from malicious software-induced errors and ensuring accurate payment amounts.
Implementation Method 1
The NFC communication controller 10 includes an antenna coil that allows a contactless data link COL to be established with an external NFC device 40... both the external device and the NFC communication controller can exchange data by inductive coupling
Data Source
AI summary
A transaction device for securing a transaction includes an NFC controller, a communication interface, an application processor, a display and a user input device. The NFC controller is configured to receive, via a contactless NFC interface, data related to the transaction from an external device. The communication interface is configured to receive an application program for the transaction device. The application processor is coupled to the NFC controller and configured to process the application program. The display is coupled to the application processor and configured to display transaction information. The user input device is linked to the NFC controller and configured to receive a user acknowledgement of the transaction. The NFC controller is further configured to transmit, via the contactless NFC interface, a transaction agreement of the transaction to the external device in response to the user acknowledgement from the user input device, without the user acknowledgement and the transaction agreement being routed through the application processor.


