Secure Element Personalization for Mobile Commerce
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single functional smart cards, such as MIFARE, face challenges in expanding to open environments like e-commerce and m-commerce due to security concerns related to key delivery over public networks, making it difficult to secure financial transactions and manage applications in NFC-enabled devices.
Innovation Solution
The implementation of a method to personalize a secure element in NFC devices, enabling secure transactions by generating and delivering personalized security keys, such as operation keys and PINs, to establish a secured channel between the device and a payment server, allowing for secure financial transactions over wired and wireless networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If single functional smart cards like MIFARE are used in enclosed systems, then security and simplicity are improved, but adaptability to open environments like e-commerce and m-commerce deteriorates due to key delivery security concerns
Solution Approach 1:
The system divides the security architecture into separate functional components: a secure element (SE) for key storage and cryptographic operations, and a communication layer for key delivery. This segmentation allows the secure element to maintain strong security while the communication layer adapts to different deployment scenarios including enclosed and open environments.
Solution Approach 2:
A server acts as an intermediary between the smart card and the external network. The server receives encryption keys from the network, securely transmits them to the smart card through established secure channels, and manages the key lifecycle. This intermediary enables key delivery over public networks without compromising the security of the smart card itself.
2Reliability
If keys are delivered to the card for authentication before data access, then security authentication is improved, but device complexity increases when expanding to open networks
Solution Approach 1:
The system performs preliminary key exchange and authentication setup before actual data transactions occur. The server establishes secure communication channels with the smart card in advance, pre-loads necessary authentication keys, and configures security parameters. This preliminary action simplifies subsequent transaction processing while maintaining strong authentication security.
3Adaptability or versatility
If smart cards contain multiple banking credentials and applications, then versatility is improved, but security management complexity increases
Solution Approach 1:
Each application or service on the smart card is associated with its own dedicated security domain and key set. The secure element organizes multiple credentials and applications into separate, isolated security compartments. This segmentation allows the system to support multi-functionality while maintaining clear security boundaries and simplifying key management for each individual application.
Data Source
AI summary
Techniques for managing modules or applications installed in a mobile device are described. To provide authentic and secured transactions with another device, each of the installed applications is provisioned with a server through data communication capability in a mobile device. A provisioned application is associated with the personalized secure element in the mobile device and works with a set of keys that are generated in accordance with a set of keys from the personalized secure element. Further management of controlling an installed application is also described.


