Return of NFC: Curse of the secure element

by Cherian Abraham 8 min read March 13, 2013

This post is in response to the recent Bankinter story of NFC payments at the point-of-sale without requiring SE – and the lack of any real detail around how it plans to achieve that goal. I am not privy to Bankinter’s plan to dis-intermediate the SE, but as I know a wee bit about how NFC works, I thought a post would help in clearing up any ambiguity as to how Card emulation and Host Card emulation differs, upsides, challenges – the whole lot.

Back in December of 2012, Verizon responded to an FCC complaint over its continued blocking of GoogleWallet on Verizon network. The gist of Verizon’s response was that as GoogleWallet is different to PayPal, Square and other wallet aggregators in that its reliance on the phone’s Secure Element – a piece of proprietary hardware, lies behind the reason for Verizon denying GoogleWallet from operating on its devices or network. Verizon continued to write that Google is free to offer a modified version of GoogleWallet that does not require integration with the Secure Element.

Now Software Card Emulation was not born out of that gridlock. It had been always supported by both NXP and Broadcom chipsets at the driver level. Among operating systems, BlackberryOS supports it by default. With Android however, application support did not manifest despite interest from the developer community. Google chose to omit exposing this capability via the API from Android 2.3.4 – may have to do with opting to focus its developer efforts elsewhere, or may have been due to carrier intervention. What very few knew is that a startup called SimplyTapp had already been toiling away at turning the switch back on – since late 2011.

Host Card What?

But first – let’s talk a bit about Card Emulation and how Host Card Emulation (or SE on the Cloud) differs in their approach. In the case of GoogleWallet, Card Emulation represents routing communication from an external contactless terminal reader directly to the embedded secure element, dis-allowing visibility by the operating system completely. Only the secure element and the NFC controller are involved. Card Emulation is supported by all merchant contactless terminals and in this mode, the phone appears to the reader as a contactless smart card. Google Wallet, Isis and other NFC mobile wallets rely on card emulation to transfer payment credentials to the PoS. However the downsides to this are payment apps are limited to the SE capacity (72kb on the original embedded SE on Nexus S), SE access is slower, and provisioning credentials to the SE is a complex, brittle process involving multiple TSM’s, multiple Carriers (in the case of Isis) and multiple SE types and handsets.

Host Card Emulation (or Software Card Emulation) differs from this such that instead of routing communications received by the NFC controller to the secure element, it delivers them to the NFC service manager – allowing the commands to be processed by applications installed on the phone. With that, the approach allows to break dependency on the secure element by having credentials stored anywhere – in the application memory, in the trusted execution environment (TEE) or on the cloud.

The benefits are apparent and a couple is noted:

  • NFC returns to being a communication standard, enabling any wallet to use it to communicate to a PoS – without having to get mired down in contracts with Issuers, Carriers and TSMs.
  • No more complex SE cards provisioning to worry about
  • Multiple NFC payment wallets can be on the phone without worrying about SE storage size or compartmentalizing.
  • No need to pay the piper – in this case, the Carrier for Over-the-air SE provisioning and lifecycle management. Card Issuers would be ecstatic.

However this is no panacea, as software card emulation is not exposed to applications by Android and host card emulation patches that have been submitted (by SimplyTapp) have not yet been merged with the main android branch – and therefore not available to you and I – unless we root our phones.

Which is where SimplyTapp comes in.

SimplyTapp appealed to an early segment of Android enthusiasts who abhorred having been told as to what functionality they are allowed to enable on their phones – by Google, Carriers or anyone else. And to any who dared to root an NFC phone (supported by CyanogenMod) and install the Cyanogenmod firmware, they were rewarded by being able to use both SimplyTapp as well as GoogleWallet to pay via NFC – the former where credentials were stored on the cloud and the latter – within the embedded SE.

So how does this work? SimplyTapp created a Host Card Emulation patch which resolves potential conflicts that could arise from having two competing applications (SimplyTapp and GW) that has registered for the same NFC event from the contactless external reader. It does so by ensuring that upon receiving the event – if the SimplyTapp app is open in the foreground (On-Screen) then the communication is routed to it and if not – it gets routed to GoogleWallet. This allows consumers to use both apps harmoniously on the same phone (take that ISIS and Google Wallet!). SimplyTapp today works on any NFC phone supported by CyanogenMod. Apart from SimplyTapp, InsideSecure is working on a similar initiative as reported here.

You get a wallet! And you get a wallet! Everyone gets a wallet!

Well not quite. What are the downsides to this approach? Well for one – if you wish to scale beyond the enthusiasts, you need Google, the platform owner to step up and make it available to all without having to root our phones. For that to happen it must update the NFC service manager to expose Host Card emulation for the NXP and Broadcom chipsets. And if Google is not onboard with the idea, then you need to find an OEM, a Handset manufacturer or an Amazon ready to distribute your amended libraries. Further, you can also expect Carriers to fight this move as it finds its investment and control around the secure element threatened. With the marked clout they enjoy with the OEM’s and Handset manufacturers by way of subsidies, they can influence the outcome.

Some wonder how is it that BlackberryOS continues to support Host Card Emulation without Carrier intervention. The short answer may be that it is such a marginal player these days that this was overlooked or ignored.

The limitations do not stop there. The process of using any cloud based credentials in an EMV or contactless transaction has not been certified yet. There is obviously interest and it probably will happen at some point – but nothing yet. Debit cards may come first – owing to the ease in certification. Further, Closed loop cards may probably be ahead of the curve compared to Open loop cards. More about that later. *Update: Latency is another issue when the credentials are stored on the cloud. Especially when NFC payments were called out last year to be not quick enough for transit.*

So for all those who pine for the death of secure elements, but swear fealty to NFC, there is hope. But don’t set your alarm yet.

So what will Google do?

Let’s consider for a moment that Google is down with this. If so, does that represent a fork in the road for Google Wallet? Will the wallet application leverage HCE on phones with inaccessible Secure Elements, while defaulting to the Secure Element on phones it has? If so, it risks confusing consumers. Further – enabling HCE lets other wallets to adopt the same route. It will break dependency with the secure element, but so shall it open the flood gates to all other wallets who now wants to play. It would seem like a pyrrhic victory for Google. All those who despised proximity payments (I am looking at you Paypal & Square!) will see their road to contactless clear and come calling. As the platform owner – Google will have no choice but to grin and bear it. But on a positive note, this will further level the playing field for all wallets and put the case for contactless back – front and center. Will Google let this happen? Those who look at Google’s history of tight fisted control over the embedded SE are bound to cite precedent and stay cynical.

But when it comes down it, I believe Google will do the right thing for the broader android community. Even on the aspect of not relinquishing control over the embedded SE in the devices it issued, Google had put the interests of consumer first. And it felt that, after all things considered it felt it was not ready to allow wanton and unfettered access to the SE. Google had at one point was even talking about allowing developers write their own “card emulation” applets and download them to the SE.

Broadcom also has an upcoming quad-combo chip BCM43341 that has managed to wrap NFC, Bluetooth 4.0, Wi-Fi and FM Radio, all on a single die. Further, the BCM43341 also supports multiple Secure Elements. Now, I also hear Broadcom happens to be a major chip supplier to a fruit company.

What do you think?

This is content was originally posted to Cherian's personal blog at DropLabs.

Related Posts

New Data Available for MBS Investors: Current Credit Score 

In a previous post, we described how every mortgage borrower’s financial situation and credit profile evolve over time.  After a borrower opens a loan, their financial status evolves—jobs are gained and lost; incomes can rise or fall, and financially stressful situations or windfalls can occur. These effects are often reflected in the consumer’s evolving credit score, which changes with the consumer’s payment behavior on open loans, credit inquiry activity, credit card utilization, and other revolving lines, among other things.    Even though MBS, whole loan, and MSR investors ultimately bear borrower credit risk, they may have access to less current borrower credit information than other participants in the mortgage ecosystem.   In securitized markets (both agency MBS and private-label MBS), updated scores are not provided in disclosure to bondholders, even as loans age year over year.  In whole loan and MSR markets, a single origination credit score is often provided at the time of bid, and after a successful bid, the investor may have a permissible purpose to pull individual scores on an owned portfolio. But until recently, there was no single loan-level dataset that included continuously refreshed credit scores across the U.S. mortgage market—the type of foundational dataset needed to build and tune credit and prepayment models.  A monthly-refreshed Current Credit Score field meets our three-pronged materiality standard for new data delivery to MBS markets:  New: Provides information not available in existing datasets (i.e., orthogonal to currently available data). Neither private-label MBS nor agency MBS standard market data includes a monthly-refreshed borrower credit score.  Material: Impacts a sizeable portion of the MBS universe. For the vast majority of loans in MBS, borrowers credit scores are available.  Significant: Differentiates collateral performance by a large enough margin to influence trading and risk management decisions.  A current credit score wraps all of a borrower’s credit-related behaviors into a single numerical value and has historically been associated with a borrower’s likelihood of becoming 60+ days past due on any obligation within the subsequent 24 months.    In fact, a current credit score is among the most informative indicators of near-term mortgage default risk, as shown in the image below, which depicts 30+ DPD rates by current credit score bands for the entire U.S. mortgage market, controlling for origination score <=650.    Without access to current credit scores, investors are limited to the score at origination—causing the four distinct performance trends shown here to appear as a single averaged line. In reality, score migration since origination reveals significant divergence in credit risk, with the lowest current-score bucket exhibiting a nearly 10 times higher 30+ DPD rate than the highest-score bucket in the latest period shown.  Source:  Experian Mortgage Loan Performance (MLP) dataset hosted on IVolatility DataDriven Platform  In this article, we’ll take a quick look at how score migration acts as an early predictor of a performing loan’s first roll into 30-day delinquent status.    MBS Investors’ Current Credit Score Blindspot: Solved   An MBS investor relying on standard market data and securitization remittance reports sees no sign of borrower stress until the subject mortgage loan in the securitization misses a payment and is reported at 30 days delinquent. Of course, in the vast majority of cases, a borrower begins struggling financially well before missing a mortgage payment:  The borrower may miss payments on other types of loans (credit card, auto loan, personal unsecured, or payday loans) as they prioritize their home and mortgage.  Outstanding balances on credit cards may grow as the borrower begins to make only minimum payments on revolvers.  The borrower may apply for additional credit cards, personal or payday loans   The borrower may apply to increase limits on existing credit cards as outstanding balance nears spending limit  All these stress-indicative behaviors result in a decreasing credit score, many months before the borrower misses their first mortgage payment. An MBS investor with access to each borrower’s current credit score, refreshed each month, can predict increased likelihood of default many months before the first missed mortgage payment—and is therefore at a major information advantage relative to the market generally.  Experian’s Mortgage Loan Performance (MLP) dataset contains thousands of fields describing mortgage performance from each borrower, loan, and property perspective, all refreshed monthly (including, amongst other things, new credit scores and refinance inquiry activity, loan performance on all types of debt, filed junior liens, and AVM values).   MLP is much more comprehensive than loan-level data provided by Freddie Mac, Fannie Mae, Ginnie Mae, and PLS data vendors in several ways:   Standard market datasets may not contain certain data elements that some market participants consider useful when evaluating mortgage prepayment or credit performance. Basic, critical fields such as the borrower’s current credit score and the current junior lien balance on the property are missing.    MLP contains borrower, loan, and property data fields spanning a broad portion of the mortgage universe, including Agency, Non-Agency, and Esoteric mortgage products (CES, HELOC, Reverse), including both securitized and non-securitized loans.   MLP enables full three-dimensional (borrower + loan + property) tracking with persistent keys for borrower (before and after refinancing), loan (in securities/deals even after exit due to payoffs or buyouts, including before and after MSR sales), and property.  This enables end-to-end analysis of each borrower’s (and property’s) mortgage experience throughout their credit lifecycle.  Is Downward-Trending Credit Score a Signal for Impending Delinquency?  MLP contains thousands of fields describing each loan, borrower, and property across all U.S. mortgages.  It allows for virtually unlimited segmentation and granular analysis.   For purposes of this illustrative article, we’ll take a high-level look at the entire U.S. mortgage market and perform a quick analysis to confirm intuition that a declining credit score provides a signal for higher likelihood of near-term mortgage delinquency.  Figure 1 illustrates the current pay status (as of 6/30) for the entire U.S. mortgage market, as contained in the MLP dataset, along with count, UPB and UPB-weighted Vantage 4.0 credit score for each bucket.  Figure 1  Source:  Experian Mortgage Loan Performance dataset  As illustrated in Figure 1, approximately 772,000 individual mortgage loans were reported to Experian as 30 days delinquent as of 6/30/2026.  Of the 772,000 30d delinquent loans in the June snapshot, approximately 426,000 were current in the prior (May) snapshot.  Some of these 426,000 loans were reperformers which had been bouncing from 30 DPD to current over the prior few snapshots. To remove reperformance score noise, we further parsed out the population which: 1) had rolled from current to 30 DPD from May to June; and 2) was consistently current for a full year prior to the 6/30 missed payment.  The population meeting both conditions totaled approximately 123,000 loans.  Figure 2 below shows, for this population of 123,000 “clean current” loans, the UPB-weighted average Vantage4 credit score for each of the 12 months leading up to the June missed payment, as well as the impact of the missed payment on the 6/30 score.  Figure 2  Source:  Experian Mortgage Loan Performance Dataset  Figure 2 reveals a rather slow and steady ~20-point deterioration of score in the 12 months prior to first missed payment – as well as the 80-point drop once the missed payment hits.  When we compare this cohort’s Vantage 4.0 score trend to the broader Current population across the entire dataset in Figure 3, we see a marked difference in both absolute value and trend:  Figure 3  Source:  Experian Mortgage Loan Performance Dataset  Not only is the cohort’s starting Vantage 4.0 score lower than the broader current population, but it also displays a dropping trend (with a notable 2 to 3x acceleration in monthly score drop the month before the first missed mortgage payment) while the broader Current population’s score (of which the isolated cohort is a subset) remains rock steady.  Lastly, we present Figure 4, a histogram comparing the distribution of at-origination and as-of 5/30 (i.e., the period just before the missed June mortgage payment) credit scores for the clean current population. The distribution appears to shift toward lower credit scores. To the extent credit scores are correlated with credit risk, this shift may indicate elevated credit risk relative to origination. Since this degradation occurs during a period of perfect mortgage pay performance, it is invisible to MBS investors who lack access to current borrower credit scores. Experian MLP provides monthly refreshed credit scores for mortgage borrowers contained within the MLP database.  Figure 4  Source:  Experian Mortgage Loan Performance Dataset 

September 22, 2026 by Michael Pyatski, Perry DeFelice
Ask the Expert: The Future of Lending Starts With Identity With Shawn Rife and Brian Cardona

Identity intelligence and alternative data can help lenders validate consumers and support more informed decisions across the customer lifecycle.

September 16, 2026 by Julie Lee
Financial Institutions Are Rethinking Customer Acqusition

Customer acquisition strategies are constantly evolving toward more precise targeting. From a marketing lens, you can track every step, optimize communication channels and still miss the person most likely to convert. Attribution can tell us which channels work and automation can make marketing spend more efficient. But both assume we know who is actually on the other end. Financial institutions are learning that finding audiences and targeting them is no longer the biggest challenge. As acquisition optimization marketing becomes more sophisticated, teams can measure and act on more signals than before. What they can't always know is whether the person on the receiving end is real. Customer acquisition has evolved into an identity problem. The challenge is not that every questionable signal represents malicious activity. It's that acquisition systems must make increasingly intelligent decisions with an imperfect understanding of who they're actually engaging. When identities are fragmented, duplicated, temporary or synthetic, optimization becomes a question of trust as much as targeting. When your signals don't reliably identify customers The customer journey often includes searching, filling out a form, creating an account, requesting a quote and subscribing. All of these signals work well when identity is relatively stable.  However, financial institutions are finding that these signals are becoming less reliable. A single person can operate across multiple personas, devices, browsers, aliases, accounts and intermediaries while several apparent “people” may actually represent one underlying actor. Financial instituions are finding: Fragmented customer signals Difficulty distinguishing an old account from a new one Different digital pathways associated with the same individual Signals that are generated by automation Real customers getting flagged because signals are too thin to evaluate confidently Legacy signals continue to be challenged Marketing has historically treated intent as a valuable signal because intent was relatively difficult to produce. A search required human intent. A form required someone to fill it out. An inquiry implied a meaningful amount of human effort. Financial institutions are already combating AI-enabled fraud, and now marketing teams are starting to face it on a massive scale. AI can mimic human behavior by researching products, comparing prices, filling out forms, creating accounts and signing up for services. A valid email address is no longer enough. Marketers need to know: How long has it existed? How recently has it been active? Does its activity appear consistent or suddenly anomalous? Has it gone dormant and returned? Is it associated with patterns that suggest stability or unusual behavior? How to build on your strongest signal Email remains one of the most persistent identifiers in digital commerce, following people across devices, platforms, transactions, subscriptions, accounts and years of activity. For over two decades, this has shaped how AtData thinks about identity. Now, as part of Experian, it’s shaping how an entire platform and team approach identity. A marketer doesn’t need every prospect to have existed online for twenty years. But understanding whether a newly acquired prospect has meaningful identity context can dramatically improve the quality of the decision being made around it. Better identity intelligence can help organizations reduce unnecessary friction by improving their ability to recognize legitimate customers. With a strong identity foundation, marketing teams can better address: Which audiences are more likely to convert? Which leads are high quality? Which channels are driving incremental growth? What do the best prospects look like? The value isn't simply having an email address. It's understanding the history and behavioral context associated with it. That context can provide a stronger digital identity signal, helping marketers understand how long they have been active, whether its behavior is consistent with that of a real person and whether current activity aligns with past patterns. It continues to be one of the most persistent identifiers in digital commerce. An infrastructure built for what's coming The acquisition of AtData by Experian reflects a fundamental shift in how identity infrastructure needs to work. Experian's scale and decisioning capabilities, combined with AtData's real-time email intelligence, create a strong platform. Read more about the why behind the acquisition and see how email works as an identity anchor for fraud prevention. Contact us to learn about our customer acquisition solutions

September 15, 2026 by Zohreen Ismail

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe