Security 205
payment cards can be distributed in real time without having to
change the software on the smartphone or tablet.
HCE technology facilitates information transfer across an NFC
interface between the NFC component and a remote secure element
which can be treated as local. HCE requires the NFC protocol to
channel the data to smartphone’s operating system instead of to a
secure element such as a local smartcard based on hardware
configured specifically to respond only as a card, with no other
functions.
Android 4.4 and later from Google uses HCE which allows an
NFC interface to communicate with the terminal’s operating system.
Google introduced this platform to carry out secure NFC transactions
for payments, loyalty programs, access to external cards and other
personalized services. With HCE, any application on an Android 4.4
and later device can emulate an NFC smartcard, enabling users to
initiate transactions with an application of their choice. The
applications can also use a new type of reader, to act as a reader of
HCE cards and other NFC devices.
7.7. Securing solutions
Having described TEE, TSM and HCE, we can now go on to
describe the different effective solutions in terms of access security
using secure elements. There are two opposing solutions: the local
solution, with a secure element in the terminal or connected directly to
it, and the delocalized solution, which is based on virtualized secure
elements.
Figure 7.12 illustrates the first solution, whereby a secure element
must be available locally. That secure element could be a SIM card
from a telecom operator, the inbuilt secure element from the
manufacturer that made the terminal, a secure element hosted
on an SD card and inserted into the reader of the mobile terminal, or
even an external secure element, communicating with the mobile via
an NFC interface, for example. These different solutions developed
www.it-ebooks.info
payment cards can be distributed in real time without having to
change the software on the smartphone or tablet.
HCE technology facilitates information transfer across an NFC
interface between the NFC component and a remote secure element
which can be treated as local. HCE requires the NFC protocol to
channel the data to smartphone’s operating system instead of to a
secure element such as a local smartcard based on hardware
configured specifically to respond only as a card, with no other
functions.
Android 4.4 and later from Google uses HCE which allows an
NFC interface to communicate with the terminal’s operating system.
Google introduced this platform to carry out secure NFC transactions
for payments, loyalty programs, access to external cards and other
personalized services. With HCE, any application on an Android 4.4
and later device can emulate an NFC smartcard, enabling users to
initiate transactions with an application of their choice. The
applications can also use a new type of reader, to act as a reader of
HCE cards and other NFC devices.
7.7. Securing solutions
Having described TEE, TSM and HCE, we can now go on to
describe the different effective solutions in terms of access security
using secure elements. There are two opposing solutions: the local
solution, with a secure element in the terminal or connected directly to
it, and the delocalized solution, which is based on virtualized secure
elements.
Figure 7.12 illustrates the first solution, whereby a secure element
must be available locally. That secure element could be a SIM card
from a telecom operator, the inbuilt secure element from the
manufacturer that made the terminal, a secure element hosted
on an SD card and inserted into the reader of the mobile terminal, or
even an external secure element, communicating with the mobile via
an NFC interface, for example. These different solutions developed
www.it-ebooks.info
