Return of NFC: Curse of the secure element

by Cherian Abraham 8 min read March 13, 2013

This post is in response to the recent Bankinter story of NFC payments at the point-of-sale without requiring SE – and the lack of any real detail around how it plans to achieve that goal. I am not privy to Bankinter’s plan to dis-intermediate the SE, but as I know a wee bit about how NFC works, I thought a post would help in clearing up any ambiguity as to how Card emulation and Host Card emulation differs, upsides, challenges – the whole lot.

Back in December of 2012, Verizon responded to an FCC complaint over its continued blocking of GoogleWallet on Verizon network. The gist of Verizon’s response was that as GoogleWallet is different to PayPal, Square and other wallet aggregators in that its reliance on the phone’s Secure Element – a piece of proprietary hardware, lies behind the reason for Verizon denying GoogleWallet from operating on its devices or network. Verizon continued to write that Google is free to offer a modified version of GoogleWallet that does not require integration with the Secure Element.

Now Software Card Emulation was not born out of that gridlock. It had been always supported by both NXP and Broadcom chipsets at the driver level. Among operating systems, BlackberryOS supports it by default. With Android however, application support did not manifest despite interest from the developer community. Google chose to omit exposing this capability via the API from Android 2.3.4 – may have to do with opting to focus its developer efforts elsewhere, or may have been due to carrier intervention. What very few knew is that a startup called SimplyTapp had already been toiling away at turning the switch back on – since late 2011.

Host Card What?

But first – let’s talk a bit about Card Emulation and how Host Card Emulation (or SE on the Cloud) differs in their approach. In the case of GoogleWallet, Card Emulation represents routing communication from an external contactless terminal reader directly to the embedded secure element, dis-allowing visibility by the operating system completely. Only the secure element and the NFC controller are involved. Card Emulation is supported by all merchant contactless terminals and in this mode, the phone appears to the reader as a contactless smart card. Google Wallet, Isis and other NFC mobile wallets rely on card emulation to transfer payment credentials to the PoS. However the downsides to this are payment apps are limited to the SE capacity (72kb on the original embedded SE on Nexus S), SE access is slower, and provisioning credentials to the SE is a complex, brittle process involving multiple TSM’s, multiple Carriers (in the case of Isis) and multiple SE types and handsets.

Host Card Emulation (or Software Card Emulation) differs from this such that instead of routing communications received by the NFC controller to the secure element, it delivers them to the NFC service manager – allowing the commands to be processed by applications installed on the phone. With that, the approach allows to break dependency on the secure element by having credentials stored anywhere – in the application memory, in the trusted execution environment (TEE) or on the cloud.

The benefits are apparent and a couple is noted:

  • NFC returns to being a communication standard, enabling any wallet to use it to communicate to a PoS – without having to get mired down in contracts with Issuers, Carriers and TSMs.
  • No more complex SE cards provisioning to worry about
  • Multiple NFC payment wallets can be on the phone without worrying about SE storage size or compartmentalizing.
  • No need to pay the piper – in this case, the Carrier for Over-the-air SE provisioning and lifecycle management. Card Issuers would be ecstatic.

However this is no panacea, as software card emulation is not exposed to applications by Android and host card emulation patches that have been submitted (by SimplyTapp) have not yet been merged with the main android branch – and therefore not available to you and I – unless we root our phones.

Which is where SimplyTapp comes in.

SimplyTapp appealed to an early segment of Android enthusiasts who abhorred having been told as to what functionality they are allowed to enable on their phones – by Google, Carriers or anyone else. And to any who dared to root an NFC phone (supported by CyanogenMod) and install the Cyanogenmod firmware, they were rewarded by being able to use both SimplyTapp as well as GoogleWallet to pay via NFC – the former where credentials were stored on the cloud and the latter – within the embedded SE.

So how does this work? SimplyTapp created a Host Card Emulation patch which resolves potential conflicts that could arise from having two competing applications (SimplyTapp and GW) that has registered for the same NFC event from the contactless external reader. It does so by ensuring that upon receiving the event – if the SimplyTapp app is open in the foreground (On-Screen) then the communication is routed to it and if not – it gets routed to GoogleWallet. This allows consumers to use both apps harmoniously on the same phone (take that ISIS and Google Wallet!). SimplyTapp today works on any NFC phone supported by CyanogenMod. Apart from SimplyTapp, InsideSecure is working on a similar initiative as reported here.

You get a wallet! And you get a wallet! Everyone gets a wallet!

Well not quite. What are the downsides to this approach? Well for one – if you wish to scale beyond the enthusiasts, you need Google, the platform owner to step up and make it available to all without having to root our phones. For that to happen it must update the NFC service manager to expose Host Card emulation for the NXP and Broadcom chipsets. And if Google is not onboard with the idea, then you need to find an OEM, a Handset manufacturer or an Amazon ready to distribute your amended libraries. Further, you can also expect Carriers to fight this move as it finds its investment and control around the secure element threatened. With the marked clout they enjoy with the OEM’s and Handset manufacturers by way of subsidies, they can influence the outcome.

Some wonder how is it that BlackberryOS continues to support Host Card Emulation without Carrier intervention. The short answer may be that it is such a marginal player these days that this was overlooked or ignored.

The limitations do not stop there. The process of using any cloud based credentials in an EMV or contactless transaction has not been certified yet. There is obviously interest and it probably will happen at some point – but nothing yet. Debit cards may come first – owing to the ease in certification. Further, Closed loop cards may probably be ahead of the curve compared to Open loop cards. More about that later. *Update: Latency is another issue when the credentials are stored on the cloud. Especially when NFC payments were called out last year to be not quick enough for transit.*

So for all those who pine for the death of secure elements, but swear fealty to NFC, there is hope. But don’t set your alarm yet.

So what will Google do?

Let’s consider for a moment that Google is down with this. If so, does that represent a fork in the road for Google Wallet? Will the wallet application leverage HCE on phones with inaccessible Secure Elements, while defaulting to the Secure Element on phones it has? If so, it risks confusing consumers. Further – enabling HCE lets other wallets to adopt the same route. It will break dependency with the secure element, but so shall it open the flood gates to all other wallets who now wants to play. It would seem like a pyrrhic victory for Google. All those who despised proximity payments (I am looking at you Paypal & Square!) will see their road to contactless clear and come calling. As the platform owner – Google will have no choice but to grin and bear it. But on a positive note, this will further level the playing field for all wallets and put the case for contactless back – front and center. Will Google let this happen? Those who look at Google’s history of tight fisted control over the embedded SE are bound to cite precedent and stay cynical.

But when it comes down it, I believe Google will do the right thing for the broader android community. Even on the aspect of not relinquishing control over the embedded SE in the devices it issued, Google had put the interests of consumer first. And it felt that, after all things considered it felt it was not ready to allow wanton and unfettered access to the SE. Google had at one point was even talking about allowing developers write their own “card emulation” applets and download them to the SE.

Broadcom also has an upcoming quad-combo chip BCM43341 that has managed to wrap NFC, Bluetooth 4.0, Wi-Fi and FM Radio, all on a single die. Further, the BCM43341 also supports multiple Secure Elements. Now, I also hear Broadcom happens to be a major chip supplier to a fruit company.

What do you think?

This is content was originally posted to Cherian's personal blog at DropLabs.

Related Posts

Expanding the Prescreen View with Alternative Credit Data

Start with a simple question Credit prescreen is an important tool in many lenders’ growth strategies. But the precision of any prescreen strategy depends on the data behind it. What financial behavior might traditional credit data alone not reveal? With Clarity data now available for Instant Prescreen decisioning, lenders can bring alternative credit insights into their targeting strategy, helping them identify prospects who may align with their established criteria, refine targeting strategies and explore additional acquisition opportunities while maintaining control over their risk thresholds. Additional insights alongside traditional credit data For many consumers, a traditional credit file tells a rich and reliable story. But it doesn't always tell the whole story. Consumers may also be using alternative financial products, such as small-dollar installment loans, single-payment loans, auto title loans or rent-to-own agreements and building payment histories that provide additional signals about their financial behavior. For lenders, those unseen signals can represent untapped opportunities. With more than 60 million unique subprime identities, Clarity's database helps lenders gain a more complete view of their applicant pool. Clarity data adds another dimension to that view, providing alternative credit insights that can help lenders better understand consumers whose financial behavior may not be fully represented by traditional credit data alone. How Clarity data sharpens instant prescreen decisioning Clarity provides specialty alternative credit data, with insights into subprime and near-prime consumer activity that may not appear in traditional credit files. And because Clarity is part of Experian, those insights can now be brought directly into Instant Prescreen decisioning. That means lenders can incorporate additional attributes and scores into their credit decisioning strategies without managing a separate data feed or stitching together disconnected sources. It has quickly become a visibility gap lenders can't ignore. Additional data may help support more granular segmentation and targeting strategies. Lenders remain in control of their criteria and risk thresholds while gaining additional information to inform their prescreen strategies. When considered alongside traditional credit data, alternative credit insights can support several aspects of prescreen decisioning: Identify more opportunities: Surface qualified prospects who may be harder to identify using traditional credit data alone. Refine targeting: Add alternative credit insights to help differentiate consumers with greater precision. Inform offer strategies: Use a broader view of financial behavior to help align consumers with appropriate offers. Expand intelligently: Explore incremental audience opportunities while maintaining control over your established risk criteria. Simplify execution: Access Experian and Clarity insights within a connected Instant Prescreen decisioning environment. See more opportunity in your prescreen strategy Growth doesn’t always require looking for an entirely new audience. Sometimes, it starts with seeing more in the audience already in front of you. By bringing Clarity data into Instant Prescreen, lenders can add another layer of insight to their decisioning, helping identify incremental opportunities, refine targeting and support acquisition decision processes across a broader range of consumers. Explore prescreen solutions

September 3, 2026 by Zohreen Ismail
Are Fraudsters Building Better Identities Than Your Customers?

Fraudsters are getting surprisingly good at onboarding. Sometimes, better than your customers. Legitimate customers treat onboarding like an errand. They start an application between other tasks, get distracted, forget a password, switch devices, upload a document or come back later to finish. Their digital lives aren’t always linear, because real life isn’t either. Fraudsters approach onboarding differently. For them, opening an account is the objective. Every interaction is designed to increase the odds of success. The difference raises an uncomfortable question hanging over onboarding: What exactly are we rewarding? When smooth becomes suspicious Digital onboarding has traditionally rewarded experiences that feel smooth, consistent and complete. The challenge is that legitimate customers rarely behave that way. Most people approach onboarding somewhere between mildly distracted and mildly annoyed. They pause halfway through because dinner is burning. They reopen an old account only to realize everything is attached to an email they made in college and, somehow, still use for airline receipts. Digital life accumulates history unevenly, because ordinary life does too. Fraudsters have every reason to eliminate those inconsistencies. Applications may be rehearsed. Identity attributes are assembled deliberately. Contact points are prepared in advance. Every interaction is optimized to make the application appear credible. Ironically, the qualities organizations often associate with confidence — clean submissions, steady progression and few corrections — can also describe applications that have been carefully engineered to pass inspection. The challenge isn't that smooth onboarding is meaningless. It's that smooth onboarding, by itself, doesn't tell the whole story. Context changes interpretation A smooth onboarding experience should be the beginning of the evaluation, not the end. Behavior provides important context. How someone moves through an application can reveal whether the experience feels naturally human or unusually orchestrated. Do they interact naturally? Do they hesitate, correct mistakes or navigate in ways that resemble ordinary human behavior? Or does the session appear unusually scripted, automated or repetitive? Identity verification adds another layer. Matching information across trusted sources, validating identity details and strengthening confidence in account creation remain important, particularly when onboarding decisions carry financial, fraud or customer experience consequences. But verification largely answers a point-in-time question: Does this information match right now? A third layer comes from digital history. An inbox attached to years of airline receipts, loyalty accounts, subscription renewals, account recovery, financial notifications and familiar digital routines introduces a different kind of confidence. Legitimate digital identities leave behind patterns of persistence and engagement that develop gradually over time. Fraudsters can assemble convincing identity attributes, but creating years of ordinary digital life is much harder. Building confidence in an identity requires more than verifying information submitted during a single onboarding session. It requires understanding whether the identity reflects a broader history that supports what the application suggests. A multilayered approach builds stronger identity confidence No single signal can provide a complete view of identity risk. Organizations need multiple sources of confidence that reinforce one another. That's the thinking behind our approach: combining behavioral intelligence, identity verification and digital identity continuity into a more complete view of risk. We bring these complementary layers together through: • NeuroID adds behavioral context during onboarding and account creation, helping identify interaction patterns that may indicate automation, manipulation or coordinated fraud. • Precise ID® strengthens identity verification and resolution by comparing applicant information with trusted identity data. • AtData, recently added to our portfolio, contributes email-centered intelligence based on persistence, engagement and long-term digital history. Together, these capabilities help organizations move beyond evaluating a single moment in time to understanding whether an identity is supported by consistent behavior, trusted identity data and an established digital history. The future of fraud prevention isn't about rewarding the smoothest application. It's about recognizing the most trustworthy identity. Fraudsters can rehearse an application. They can optimize an onboarding journey. They can even assemble convincing identity attributes. What they can't easily manufacture is years of ordinary digital life. That's why digital identity continuity has become an important layer of modern fraud prevention. Combined with identity verification and behavioral intelligence, it helps organizations distinguish between identities that simply look convincing and those supported by a history that is much harder to fake. Learn more Contact us

September 2, 2026 by Julie Lee
From Hybrids to Refinancing: Consumers are Finding New Roads to Vehicle Affordability

For today’s automotive consumers, considering a vehicle purchase isn’t just about the price they see on the window, it’s about finding the right combination of their vehicle preference and monthly payment. In fact, data from Experian Automotive’s State of the Automotive Finance Market Report: Q2 2026 highlighted how affordability continues to shape the automotive finance market. For instance, hybrids offered the lowest average new vehicle loan payment across all fuel types, coming in at $646 in Q2 2026, compared to electric vehicles (EVs) at $692, and gasoline-powered vehicles at $721. This led to considerable growth in new vehicle market share for hybrids this quarter, accounting for 16.80%, from 12.99% last year. While the automotive market continues to offer consumers an expanding mix of fuel types, the combination of growing hybrid share and comparatively lower monthly payments is something worth watching. Affordability isn’t just about what consumers drive, it’s how they finance it While hybrid vehicles are continuing to pave their way in the vehicle market, consumers who already have an auto loan are finding greater savings through refinancing. In the second quarter of 2026, automotive refinancing reached approximately 140,000 loans. More notably, the financial benefit associated with refinancing has grown. Consumers who refinanced this quarter reduced their average interest rate by more than 2.4%, with the average rate moving from 10.40% on the original loan to 7.97% on the refinanced loan. Those rate reductions translated into meaningful monthly savings, especially when refinancing through particular lenders. In Q2 2026, refinancing saved consumers an average of $83 per month, compared to an average monthly savings of $64 this time last year. However, credit unions delivered the largest average payment difference among lender types at $102 this quarter, followed by banks ($65), and finance companies ($38). It’s important for automotive professionals to acknowledge that affordability is not a single moment in the vehicle journey. It can influence the vehicle a consumer chooses, the financing they opt for during that transaction, and the decisions they make years after driving off the lot. Understanding and leveraging those different moments can help professionals identify opportunities to better serve consumers throughout the vehicle ownership lifecycle. To learn more about automotive finance trends, view the full State of the Automotive Finance Market Report: Q2 2026 presentation on demand.

August 27, 2026 by Melinda Zabritski

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe