Virtual Secure Element for NFC Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of secure processors in mobile phones for NFC transactions is hindered by complexity and cost, requiring multiple bank keys and significant computing power, along with the need for secure customization and vulnerability to fraud.

Innovation Solution

A method utilizing a virtual secure element system where a portable device connects to a transaction server via the internet, using a virtual card with a virtual operating system and card application to emulate a secure processor, reducing hardware complexity and enhancing security through partitioned memory and cryptographic keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure processor is integrated in mobile phones for NFC transactions, then transaction security is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improvetransaction securityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of a secure processor using software (virtual machine, virtual file system, virtual communication interface) that replicates the functionality of a physical secure processor. This virtual secure element emulates the behavior and security functions of hardware-based secure processors without requiring actual hardware integration, thereby maintaining transaction security while reducing device complexity

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/hardware-based secure processor with a software-based virtual secure element. The virtual machine, virtual file system, and virtual communication interface collectively substitute for physical hardware components, transforming the security implementation from a hardware-centric approach to a software-centric approach that achieves the same security objectives without the associated hardware complexity and cost

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If multiple bank keys are stored in secure processor, then transaction versatility is improved, but security vulnerability increases

Engineering Contradiction:
Improvetransaction versatilityVSAvoidfraud vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the secure element functionality into virtual components (virtual machine, virtual file system, virtual communication interface) that can be dynamically configured. Different bank keys and transaction types can be isolated in separate virtual environments, allowing versatility while maintaining security through logical separation. Each virtual secure element can be independently managed and secured

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtual machine as an intermediary layer between the mobile device's application processor and the NFC hardware interface. This virtual machine mediates all secure transactions, managing bank keys and cryptographic operations in a controlled software environment. The intermediary provides security policies, access control, and fraud prevention mechanisms that reduce vulnerability while maintaining versatility

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If secure customization is performed on processor, then transaction reliability is improved, but manufacturing cost and complexity increase

Engineering Contradiction:
Improvetransaction reliabilityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a dynamic, software-based secure element that can be customized and configured after device manufacturing through over-the-air updates. The virtual machine and virtual file system can be dynamically loaded, updated, and reconfigured without requiring hardware customization or re-manufacturing. This dynamic approach allows flexible customization while maintaining cost-effective standard manufacturing processes

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent pre-configures the virtual secure element with necessary security policies, virtual file system structures, and communication interface protocols during software initialization rather than during hardware manufacturing. This preliminary software configuration enables reliable secure transactions while avoiding the need for expensive and complex hardware customization processes

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach simplifies the implementation of NFC transactions in mobile devices, reduces costs, and enhances security by using a virtual card system that is resistant to fraud, allowing secure and efficient transactions without the need for complex hardware secure processors.

Implementation Method 1

The terminal TT itself comprises an antenna coil AC2 and is configured to conduct a near field transaction with the card CC1 by emitting a magnetic field FLD

Methodology Applied
Scientific EffectElectromagnetic induction: Electromagnetic Induction

Data Source

PatentEP2646990B1Improved method and system for NFC transaction
Publication Date: 2020.02.12 VERIMATRIX INC
  • EP2646990B1 patent drawingFigure 1~3
  • EP2646990B1 patent drawingFigure 4
  • EP2646990B1 patent drawingFigure 5

AI summary

The invention relates to a method for conducting a transaction between a portable device (HD2) and a transaction terminal (TT), comprising the steps of establishing a communication channel between the portable device (HD2) and the transaction terminal (TT); establishing a first data link (CX3) between the transaction terminal (TT) and the transaction server (SV1); and using an application program (CAPj) in the transaction server (SV1) to conduct the transaction with the transaction terminal by way of the data link (CX3), on behalf of the portable device.