Secure Element Personalization for Mobile Commerce

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single functional smart cards, such as MIFARE, face challenges in expanding to open environments like e-commerce and m-commerce due to security concerns related to key delivery over public networks, making it difficult to secure financial transactions and manage applications in NFC-enabled devices.

Innovation Solution

The implementation of a method to personalize a secure element in NFC devices, enabling secure transactions by generating and delivering personalized security keys, such as operation keys and PINs, to establish a secured channel between the device and a payment server, allowing for secure financial transactions over wired and wireless networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If single functional smart cards like MIFARE are used in enclosed systems, then security and simplicity are improved, but adaptability to open environments like e-commerce and m-commerce deteriorates due to key delivery security concerns

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability to open environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system divides the security architecture into separate functional components: a secure element (SE) for key storage and cryptographic operations, and a communication layer for key delivery. This segmentation allows the secure element to maintain strong security while the communication layer adapts to different deployment scenarios including enclosed and open environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A server acts as an intermediary between the smart card and the external network. The server receives encryption keys from the network, securely transmits them to the smart card through established secure channels, and manages the key lifecycle. This intermediary enables key delivery over public networks without compromising the security of the smart card itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If keys are delivered to the card for authentication before data access, then security authentication is improved, but device complexity increases when expanding to open networks

Engineering Contradiction:
Improveauthentication securityVSAvoidcomplexity in key delivery management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary key exchange and authentication setup before actual data transactions occur. The server establishes secure communication channels with the smart card in advance, pre-loads necessary authentication keys, and configures security parameters. This preliminary action simplifies subsequent transaction processing while maintaining strong authentication security.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If smart cards contain multiple banking credentials and applications, then versatility is improved, but security management complexity increases

Engineering Contradiction:
Improvemulti-functionalityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Each application or service on the smart card is associated with its own dedicated security domain and key set. The secure element organizes multiple credentials and applications into separate, isolated security compartments. This segmentation allows the system to support multi-functionality while maintaining clear security boundaries and simplifying key management for each individual application.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9240009B2Mobile devices for commerce over unsecured networks
Publication Date: 2016.01.19 RFCYBER CORP
  • US9240009B2 patent drawing
  • US9240009B2 patent drawing
  • US9240009B2 patent drawing

AI summary

Techniques for managing modules or applications installed in a mobile device are described. To provide authentic and secured transactions with another device, each of the installed applications is provisioned with a server through data communication capability in a mobile device. A provisioned application is associated with the personalized secure element in the mobile device and works with a set of keys that are generated in accordance with a set of keys from the personalized secure element. Further management of controlling an installed application is also described.