HEADLINE NEWS

Taiwan Chip Company Supplies NFC Technology to Low-Cost Phone Maker

Taiwan-based chip maker MStar Semiconductor announced today it is supplying NFC technology to Russia-based phone maker Fly for one or more handsets for the European market to be released as early as next month.

Austrian Bank Announces Plans to Launch Mobile-Payment Service with microSDs and iPhone

Jan 30 2012 (All day)

Raiffeisen Bank International, one of Austria’s largest banks, is planning to launch contactless-mobile payment with microSD cards and an iPhone attachment.

Samsung Confirms NFC Chip in Galaxy Note, though NFC Version Already Shipping in Korea

Samsung Electronics has confirmed it has an NFC version of its Galaxy Note, though that comes as no surprise to operators in South Korea, which have been selling the tablet-smartphone hybrid with NFC inside for about two months.

Inside Secure Releases New Android NFC Stack; Accuses NXP of Monopolizing Market

NFC chip supplier Inside Secure has released a new version of its NFC software stack, as it seeks to break rival NXP Semiconductors’ dominance of the market for NFC chips in Android phones.

Microsoft Requires ‘Visual Mark’ for Windows 8 Devices Supporting NFC

Microsoft is requiring device makers to include a “visual mark” for tablets and PCs supporting NFC and running the software giant’s forthcoming Windows 8 operating system.

Japan’s KDDI Announces Plans for Small NFC Launch with Galaxy S II

Jan 17 2012 (All day)

Japan’s second largest mobile operator, KDDI, said it would launch Japan’s first mobile NFC service late this month with the Samsung Galaxy S II–though the service will start out small because of the lack of phones that support both standard NFC and Japan's proprietary FeliCa technology, as well as Japan's nearly nonexistent infrastructure of standard contactless readers.

Spanish Bank Plans To Turn Barcelona into Contactless-Payment City

Large Spanish retail bank La Caixa will begin rolling out 1 million contactless cards along with more than 15,000 point-of-sale terminals and 500 contactless ATMs in Barcelona this month.

GlobalPlatform and SIMalliance Seek to Build ‘De Facto Standard’ for Accessing Secure Elements

Jan 12 2012 (All day)

The SIMalliance trade group and GlobalPlatform standards organization say they are working on what they predict will become a “de-facto standard” for the way apps on NFC phones communicate with secure elements.

Sony Unveils Pair of Android NFC Phones and ‘SmartTags’

Sony Ericsson has announced two NFC-enabled Android smartphones and NFC tags for its Xperia series, touting NFC as enabling consumers to share content, as well as “an increasing number of NFC applications.”

Visa Announces Certification of Six NFC Phone Models for SIM-based payWave

Jan 11 2012 (All day)

Visa has announced its first certifications of NFC phones, approving six models to run its contactless application, payWave, on SIM cards.

Intel, HP Signal Plans for Supporting NFC on Ultrabooks

Jan 11 2012 (All day)

U.S.-based Intel, as expected, is planning to incorporate NFC technology into chip designs for future ultrabook computers, the vice president and general manager of the chip maker’s PC group said Monday.

Sprint Announces Two New NFC Phones Supporting Google Wallet

U.S. mobile carrier Sprint has announced two more phones supporting the Google Wallet, including Google’s new Android smartphone, the Galaxy Nexus.

Standard Seeks to Create More Secure PIN Entry for NFC Payment

As prospects for NFC-based mobile payment heat up, banks and payment brands are left with the problem of how to secure high-value transactions.

With viruses on smartphones an ever-present worry, some are not convinced it’s safe to allow consumers to enter PIN codes on handset keypads, which could be spied upon by fraudsters.

So some banks are requiring users in trials, such as one now going on in Spain, to enter their PINs on point-of-sale terminal keypads, which are then compared with PINs stored on the backend. Some NFC trial organizers don’t allow high-value transactions at all.

And while most banks and payment companies likely will want to enable PIN entry on the NFC handset to ensure the user experience is consistent, they might follow the lead of French banks, which in NFC pilots have renamed the PIN as the “personal code.” Although the banks emphasize that this code is different from the PINs used by customers for their French debit cards, it does not avoid the potential risks of an insecure phone keypad.

But vendors have been developing hardware and software that could provide a trusted area right on the phone processor, which could store encryption keys, certificates and other security measures.

This so-called “trusted execution environment” would add security features to help safeguard PIN entry on the phone keypad and also deter hackers from spying on transaction data displayed on the handset screen. It could offer a security boost for a range of other applications, including enabling secure access through corporate virtual private networks or digital rights management for games or music, among a range of services in app stores of the various smartphone makers.

“The picture is very clear, you will have a smartphone in your pocket; you will have a rich OS (operating system), and there is a real need for security whatever the OS,” Gil Bernabeu, technical director for GlobalPlatform, told NFC Times. “Currently, the Apple and RIM (BlackBerry maker Research in Motion) and Android stores, those guys are making applications with no security.”

GlobalPlatform is developing specifications that apply to software and hardware that use the trusted execution environment in phones. The specifications are for the application programming interface, or API, for applications that run in this trusted environment. The API would enable developers working with various smartphone operating systems and chips to develop applications across all the platforms. Their products now remain proprietary.

While most trusted execution environments on phones use a secure area called TrustZone by UK-based chip design company ARM Holdings, TrustZone ties into different operators systems, such as BlackBerry OS and Android. There are also different phone processor chip makers and also at least two major providers of software platforms for applications using TrustZone and the trusted execution environment–smart card vendor Giesecke & Devrient and Trusted Logic, owned by smart card maker Gemalto.

GlobalPlatform members ARM, Giesecke & Devrient, Trusted Logic and chip makers ST-Ericsson and Texas Instruments have worked on the specifications.

These specs will not only be used for NFC applications, and mobile operator group, the Open Mobile Terminal Platform, also worked on the specifications. The group is now known as the Wholesale Applications Community, or WAC.

But GlobalPlatform needs some support from the major smartphone makers and other chip makers for its specifications. The initiative presumably has the backing of Giesecke & Devrient and Trusted Logic. GlobalPlatform has formed a working group to continue work on the standard.

There is also a need for a secure connection from the trusted execution environment to the secure element or secure chip in the NFC phones, which would store the actual keys to the payment applications and the customers’ PIN codes. This chip could be on a SIM card, embedded in the handset itself or located elsewhere, such as in a microSD card inserted in the phone.

And even with the more secure phone keypad that the trusted environment provides, PIN entry on the phone to complete a payment transaction would not be considered as secure as entering PINs on POS terminal keypads that support the PIN Entry Device standard, or PED, of the PCI Security Standards Council.

But with NFC-based mobile payment expected to begin rolling out by next year, a standard promoting more secure phone keypads and screens is no doubt welcome news for banks and card brands. 

Article comments

 
MK.Mustafa Sep 14 2010

All these security issues can be solved if SCWS enabled SIM cards, this will enable all mobile to interact with mobile payment application which stored in SIM cards through web server. All encryption keys are stored in SIM and are not visible to phone OS all encryption operations are done in SIM card level.

Please register or login to post a comment.