Secure Element Personalization for NFC E-Commerce
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single functional smart card technologies face challenges in expanding to open environments like the Internet for e-commerce and m-commerce due to security concerns related to key delivery and authentication, making it difficult to secure financial transactions over public networks.
Innovation Solution
The implementation of a method to personalize a secure element in NFC devices, enabling secure transactions by generating and managing symmetric or asymmetric security keys, and using an e-purse manager to establish a secured channel for transactions over wired or wireless networks, allowing NFC devices to function as electronic purses for secure financial operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If single functional smart card technology is used with stored values and transaction information protected by keys, then security authentication is achieved, but the system cannot be expanded to open environments like the Internet for e-commerce and m-commerce due to security concerns about key delivery over public networks
Solution Approach 1:
The system is divided into two distinct components: a secure element (SE) that stores sensitive data and keys in an enclosed environment, and a host environment that handles open network communications. This segmentation allows the secure element to maintain security while the host provides adaptability to open environments like the Internet.
Solution Approach 2:
The secure element acts as an intermediary between the host environment and external systems. It provides a secure channel for key storage and authentication operations, mediating between the need for security and the requirements of open environment expansion. The secure element interface enables controlled interaction without exposing sensitive keys to public networks.
2Reliability
If keys are delivered to the card for authentication before any data can be accessed during a transaction, then security authentication is enabled, but the constraint makes systems difficult to expand to open environments as key delivery over public domain networks causes security concerns
Solution Approach 1:
The system separates key storage and authentication operations (confined to the secure element) from network communications (handled by the host). This allows authentication to occur in a secure environment without requiring key delivery over public networks, enabling expansion to open environments while maintaining authentication reliability.
Solution Approach 2:
The secure element serves as an intermediary that performs authentication operations without exposing keys to public networks. It receives authenticated requests from the host and processes them securely, enabling open environment expansion while maintaining authentication security.
3Reliability
If a secure element is personalized with generated keys for secure transactions, then security over open networks is achieved, but additional personalization and provisioning processes are required
Solution Approach 1:
The secure element is pre-personalized with unique identifiers and cryptographic keys before deployment. This preliminary action enables the secure element to immediately participate in secure transactions without requiring complex provisioning during initial use, reducing operational complexity while maintaining security.
Solution Approach 2:
The secure element performs self-authentication using its pre-loaded keys and identifiers. It autonomously verifies its identity and establishes secure channels without requiring external provisioning during transactions, simplifying the overall system complexity while ensuring security over open networks.
Data Source
AI summary
Techniques for managing modules or applications installed in a mobile device are described. To provide authentic and secured transactions with another device, each of the installed applications is provisioned with a server through data communication capability in a mobile device. A provisioned application is associated with the personalized secure element in the mobile device and works with a set of keys that are generated in accordance with a set of keys from the personalized secure element. Further management of controlling an installed application is also described.


