Return of NFC: Curse of the secure element

by Cherian Abraham 8 min read March 13, 2013

This post is in response to the recent Bankinter story of NFC payments at the point-of-sale without requiring SE – and the lack of any real detail around how it plans to achieve that goal. I am not privy to Bankinter’s plan to dis-intermediate the SE, but as I know a wee bit about how NFC works, I thought a post would help in clearing up any ambiguity as to how Card emulation and Host Card emulation differs, upsides, challenges – the whole lot.

Back in December of 2012, Verizon responded to an FCC complaint over its continued blocking of GoogleWallet on Verizon network. The gist of Verizon’s response was that as GoogleWallet is different to PayPal, Square and other wallet aggregators in that its reliance on the phone’s Secure Element – a piece of proprietary hardware, lies behind the reason for Verizon denying GoogleWallet from operating on its devices or network. Verizon continued to write that Google is free to offer a modified version of GoogleWallet that does not require integration with the Secure Element.

Now Software Card Emulation was not born out of that gridlock. It had been always supported by both NXP and Broadcom chipsets at the driver level. Among operating systems, BlackberryOS supports it by default. With Android however, application support did not manifest despite interest from the developer community. Google chose to omit exposing this capability via the API from Android 2.3.4 – may have to do with opting to focus its developer efforts elsewhere, or may have been due to carrier intervention. What very few knew is that a startup called SimplyTapp had already been toiling away at turning the switch back on – since late 2011.

Host Card What?

But first – let’s talk a bit about Card Emulation and how Host Card Emulation (or SE on the Cloud) differs in their approach. In the case of GoogleWallet, Card Emulation represents routing communication from an external contactless terminal reader directly to the embedded secure element, dis-allowing visibility by the operating system completely. Only the secure element and the NFC controller are involved. Card Emulation is supported by all merchant contactless terminals and in this mode, the phone appears to the reader as a contactless smart card. Google Wallet, Isis and other NFC mobile wallets rely on card emulation to transfer payment credentials to the PoS. However the downsides to this are payment apps are limited to the SE capacity (72kb on the original embedded SE on Nexus S), SE access is slower, and provisioning credentials to the SE is a complex, brittle process involving multiple TSM’s, multiple Carriers (in the case of Isis) and multiple SE types and handsets.

Host Card Emulation (or Software Card Emulation) differs from this such that instead of routing communications received by the NFC controller to the secure element, it delivers them to the NFC service manager – allowing the commands to be processed by applications installed on the phone. With that, the approach allows to break dependency on the secure element by having credentials stored anywhere – in the application memory, in the trusted execution environment (TEE) or on the cloud.

The benefits are apparent and a couple is noted:

  • NFC returns to being a communication standard, enabling any wallet to use it to communicate to a PoS – without having to get mired down in contracts with Issuers, Carriers and TSMs.
  • No more complex SE cards provisioning to worry about
  • Multiple NFC payment wallets can be on the phone without worrying about SE storage size or compartmentalizing.
  • No need to pay the piper – in this case, the Carrier for Over-the-air SE provisioning and lifecycle management. Card Issuers would be ecstatic.

However this is no panacea, as software card emulation is not exposed to applications by Android and host card emulation patches that have been submitted (by SimplyTapp) have not yet been merged with the main android branch – and therefore not available to you and I – unless we root our phones.

Which is where SimplyTapp comes in.

SimplyTapp appealed to an early segment of Android enthusiasts who abhorred having been told as to what functionality they are allowed to enable on their phones – by Google, Carriers or anyone else. And to any who dared to root an NFC phone (supported by CyanogenMod) and install the Cyanogenmod firmware, they were rewarded by being able to use both SimplyTapp as well as GoogleWallet to pay via NFC – the former where credentials were stored on the cloud and the latter – within the embedded SE.

So how does this work? SimplyTapp created a Host Card Emulation patch which resolves potential conflicts that could arise from having two competing applications (SimplyTapp and GW) that has registered for the same NFC event from the contactless external reader. It does so by ensuring that upon receiving the event – if the SimplyTapp app is open in the foreground (On-Screen) then the communication is routed to it and if not – it gets routed to GoogleWallet. This allows consumers to use both apps harmoniously on the same phone (take that ISIS and Google Wallet!). SimplyTapp today works on any NFC phone supported by CyanogenMod. Apart from SimplyTapp, InsideSecure is working on a similar initiative as reported here.

You get a wallet! And you get a wallet! Everyone gets a wallet!

Well not quite. What are the downsides to this approach? Well for one – if you wish to scale beyond the enthusiasts, you need Google, the platform owner to step up and make it available to all without having to root our phones. For that to happen it must update the NFC service manager to expose Host Card emulation for the NXP and Broadcom chipsets. And if Google is not onboard with the idea, then you need to find an OEM, a Handset manufacturer or an Amazon ready to distribute your amended libraries. Further, you can also expect Carriers to fight this move as it finds its investment and control around the secure element threatened. With the marked clout they enjoy with the OEM’s and Handset manufacturers by way of subsidies, they can influence the outcome.

Some wonder how is it that BlackberryOS continues to support Host Card Emulation without Carrier intervention. The short answer may be that it is such a marginal player these days that this was overlooked or ignored.

The limitations do not stop there. The process of using any cloud based credentials in an EMV or contactless transaction has not been certified yet. There is obviously interest and it probably will happen at some point – but nothing yet. Debit cards may come first – owing to the ease in certification. Further, Closed loop cards may probably be ahead of the curve compared to Open loop cards. More about that later. *Update: Latency is another issue when the credentials are stored on the cloud. Especially when NFC payments were called out last year to be not quick enough for transit.*

So for all those who pine for the death of secure elements, but swear fealty to NFC, there is hope. But don’t set your alarm yet.

So what will Google do?

Let’s consider for a moment that Google is down with this. If so, does that represent a fork in the road for Google Wallet? Will the wallet application leverage HCE on phones with inaccessible Secure Elements, while defaulting to the Secure Element on phones it has? If so, it risks confusing consumers. Further – enabling HCE lets other wallets to adopt the same route. It will break dependency with the secure element, but so shall it open the flood gates to all other wallets who now wants to play. It would seem like a pyrrhic victory for Google. All those who despised proximity payments (I am looking at you Paypal & Square!) will see their road to contactless clear and come calling. As the platform owner – Google will have no choice but to grin and bear it. But on a positive note, this will further level the playing field for all wallets and put the case for contactless back – front and center. Will Google let this happen? Those who look at Google’s history of tight fisted control over the embedded SE are bound to cite precedent and stay cynical.

But when it comes down it, I believe Google will do the right thing for the broader android community. Even on the aspect of not relinquishing control over the embedded SE in the devices it issued, Google had put the interests of consumer first. And it felt that, after all things considered it felt it was not ready to allow wanton and unfettered access to the SE. Google had at one point was even talking about allowing developers write their own “card emulation” applets and download them to the SE.

Broadcom also has an upcoming quad-combo chip BCM43341 that has managed to wrap NFC, Bluetooth 4.0, Wi-Fi and FM Radio, all on a single die. Further, the BCM43341 also supports multiple Secure Elements. Now, I also hear Broadcom happens to be a major chip supplier to a fruit company.

What do you think?

This is content was originally posted to Cherian's personal blog at DropLabs.

Related Posts

Workflow Automation for Financial Services

Manual processes are quietly expensive. Every handoff between teams, every file transfer waiting in a queue and every decision that sits on someone's desk adds cost, introduces risk and slows the customer experience. For financial institutions, those delays translate directly into lost revenue and eroded margins. That’s why workflow automation is becoming critical for financial institutions looking to stay competitive. Done well, it doesn't just make existing tasks faster. It reshapes how decisions get made across the entire customer lifecycle, from the first marketing touch to account servicing and beyond. What is workflow automation? Workflow automation is the use of technology to run a sequence of tasks, decisions and handoffs with minimal manual intervention. Instead of a person moving work from one step to the next — pulling data, applying a rule, routing an account and sending a communication — software executes those steps automatically based on defined logic and real-time data. For financial institutions, workflow automation usually combines four ingredients: Data Connecting to the internal and external data sources that inform a decision. Analytics Scores, models and attributes that turn raw data into insights. Decisioning A rules engine that determines the right action for each customer or account. Execution The operational layer that carries out the action, whether that's an offer, a credit line change or outreach. The benefits of workflow automation The value of automation goes well beyond "doing the same thing faster." The benefits financial institutions consistently see include:Greater efficiency and lower operating costsAutomation frees underwriters, analysts and agents to focus on exceptions and high-value work rather than repetitive processing. Faster, more consistent decisionsA credit application that once waited in a queue can be assessed in real time against consistent, auditable policies, improving both the applicant's experience and portfolio quality. Better customer experiencesAutomation enables financial institutions to personalize communications at the point of interaction and offer the self-service options that many people now prefer. Improved compliance and governanceReduce the risk of costly compliance failures with built-in controls, audit trails and guided workflows. ScalabilityRespond to changing volumes without sacrificing speed, consistency or the customer experience. Where workflow automation makes the biggest difference Workflow automation tends to deliver the most value where decisions are frequent, repeatable and informed by data. In financial services, those opportunities exist across the customer lifecycle. Onboarding Onboarding is a customer's first experience of your organization, and it's also where friction can cause customers to abandon the process and turn to another provider. Forty percent of U.S. consumers have considered walking away from opening a new account when the process felt burdensome.1 An automated onboarding workflow can bring together document verification, device intelligence, behavioral analytics, credit attributes and more, then orchestrate them into a single decision. The result is a lower-friction experience for the customer and a consistent, auditable process. Once customers are on the books, serving them well means making continuous, high-volume decisions: credit line changes, cross-sell and up-sell opportunities, risk monitoring and retention actions. Automation makes it practical to run these recurring decisions consistently across an entire portfolio, using a holistic view of each customer that draws on multiple scores and attributes. Lending The underwriting process is a great example of how workflow automation can help prevent applicants from waiting days for an answer. Loan origination and credit decisioning capabilities are designed to create a seamless review process across consumer and commercial lending. After automating originations with our solutions, Michigan State University Federal Credit Union cut application processing time to under 24 hours. Fraud Financial institutions are checking fraud at every touchpoint, and the standard for AI fraud detection continues to rise as fraudsters use AI to slip under the thresholds of any single detection tool. Rather than running fraud checks in isolation, an automated workflow can run multiple fraud and identity verification services in parallel and weigh signals together. A fraud decisioning platform connects signals across internal systems, Experian data and third-party services, allowing teams to stay on top of evolving threats. Build a strong foundation for workflow automation Workflow automation can connect these stages, creating a consistent decisioning framework. What ultimately separates good automation from great automation is the quality of the data and decisioning software underneath it. An automated workflow is only as good as the information feeding it. That's where our comprehensive credit, alternative and identity data with the tools financial institutions need to act on it. Learn more here FAQs How does automated decisioning improve credit decisions? Automated decisioning applies consistent logic to every account in real time or in bulk, enabling faster and more informed decisions, quicker responses to market and regulatory changes at the point of interaction. What is workflow automation in financial services? It's the use of software to execute sequences of data gathering, analysis, decisioning and action. Does workflow automation replace human judgment? No. The goal is to automate routine, high-volume decisions so skilled staff can focus on the exceptions and complex cases that genuinely require human judgment. For example, a sensitive collections conversation or a nuanced underwriting call. Are we still compliant with regulations if we use an automated workflow process? Well-designed platforms include built-in governance, audit trails and compliance controls that help institutions align with requirements like the Fair Credit Reporting Act (FCRA) and other regulatory guidelines improving compliance compared with manual processes. How long does it take to implement? It varies by solution and scope, but modern cloud-based platforms are designed for fast onboarding and limited IT involvement. 1Global Fraud Snapshot 2025: Opportunities and challenge in identity, fraud and financial crime

September 9, 2026 by Zohreen Ismail
Expanding the Prescreen View with Alternative Credit Data

Start with a simple question Credit prescreen is an important tool in many lenders’ growth strategies. But the precision of any prescreen strategy depends on the data behind it. What financial behavior might traditional credit data alone not reveal? With Clarity data now available for Instant Prescreen decisioning, lenders can bring alternative credit insights into their targeting strategy, helping them identify prospects who may align with their established criteria, refine targeting strategies and explore additional acquisition opportunities while maintaining control over their risk thresholds. Additional insights alongside traditional credit data For many consumers, a traditional credit file tells a rich and reliable story. But it doesn't always tell the whole story. Consumers may also be using alternative financial products, such as small-dollar installment loans, single-payment loans, auto title loans or rent-to-own agreements and building payment histories that provide additional signals about their financial behavior. For lenders, those unseen signals can represent untapped opportunities. With more than 60 million unique subprime identities, Clarity's database helps lenders gain a more complete view of their applicant pool. Clarity data adds another dimension to that view, providing alternative credit insights that can help lenders better understand consumers whose financial behavior may not be fully represented by traditional credit data alone. How Clarity data sharpens instant prescreen decisioning Clarity provides specialty alternative credit data, with insights into subprime and near-prime consumer activity that may not appear in traditional credit files. And because Clarity is part of Experian, those insights can now be brought directly into Instant Prescreen decisioning. That means lenders can incorporate additional attributes and scores into their credit decisioning strategies without managing a separate data feed or stitching together disconnected sources. It has quickly become a visibility gap lenders can't ignore. Additional data may help support more granular segmentation and targeting strategies. Lenders remain in control of their criteria and risk thresholds while gaining additional information to inform their prescreen strategies. When considered alongside traditional credit data, alternative credit insights can support several aspects of prescreen decisioning: Identify more opportunities: Surface qualified prospects who may be harder to identify using traditional credit data alone. Refine targeting: Add alternative credit insights to help differentiate consumers with greater precision. Inform offer strategies: Use a broader view of financial behavior to help align consumers with appropriate offers. Expand intelligently: Explore incremental audience opportunities while maintaining control over your established risk criteria. Simplify execution: Access Experian and Clarity insights within a connected Instant Prescreen decisioning environment. See more opportunity in your prescreen strategy Growth doesn’t always require looking for an entirely new audience. Sometimes, it starts with seeing more in the audience already in front of you. By bringing Clarity data into Instant Prescreen, lenders can add another layer of insight to their decisioning, helping identify incremental opportunities, refine targeting and support acquisition decision processes across a broader range of consumers. Explore prescreen solutions

September 3, 2026 by Zohreen Ismail
Are Fraudsters Building Better Identities Than Your Customers?

Fraudsters are getting surprisingly good at onboarding. Sometimes, better than your customers. Legitimate customers treat onboarding like an errand. They start an application between other tasks, get distracted, forget a password, switch devices, upload a document or come back later to finish. Their digital lives aren’t always linear, because real life isn’t either. Fraudsters approach onboarding differently. For them, opening an account is the objective. Every interaction is designed to increase the odds of success. The difference raises an uncomfortable question hanging over onboarding: What exactly are we rewarding? When smooth becomes suspicious Digital onboarding has traditionally rewarded experiences that feel smooth, consistent and complete. The challenge is that legitimate customers rarely behave that way. Most people approach onboarding somewhere between mildly distracted and mildly annoyed. They pause halfway through because dinner is burning. They reopen an old account only to realize everything is attached to an email they made in college and, somehow, still use for airline receipts. Digital life accumulates history unevenly, because ordinary life does too. Fraudsters have every reason to eliminate those inconsistencies. Applications may be rehearsed. Identity attributes are assembled deliberately. Contact points are prepared in advance. Every interaction is optimized to make the application appear credible. Ironically, the qualities organizations often associate with confidence — clean submissions, steady progression and few corrections — can also describe applications that have been carefully engineered to pass inspection. The challenge isn't that smooth onboarding is meaningless. It's that smooth onboarding, by itself, doesn't tell the whole story. Context changes interpretation A smooth onboarding experience should be the beginning of the evaluation, not the end. Behavior provides important context. How someone moves through an application can reveal whether the experience feels naturally human or unusually orchestrated. Do they interact naturally? Do they hesitate, correct mistakes or navigate in ways that resemble ordinary human behavior? Or does the session appear unusually scripted, automated or repetitive? Identity verification adds another layer. Matching information across trusted sources, validating identity details and strengthening confidence in account creation remain important, particularly when onboarding decisions carry financial, fraud or customer experience consequences. But verification largely answers a point-in-time question: Does this information match right now? A third layer comes from digital history. An inbox attached to years of airline receipts, loyalty accounts, subscription renewals, account recovery, financial notifications and familiar digital routines introduces a different kind of confidence. Legitimate digital identities leave behind patterns of persistence and engagement that develop gradually over time. Fraudsters can assemble convincing identity attributes, but creating years of ordinary digital life is much harder. Building confidence in an identity requires more than verifying information submitted during a single onboarding session. It requires understanding whether the identity reflects a broader history that supports what the application suggests. A multilayered approach builds stronger identity confidence No single signal can provide a complete view of identity risk. Organizations need multiple sources of confidence that reinforce one another. That's the thinking behind our approach: combining behavioral intelligence, identity verification and digital identity continuity into a more complete view of risk. We bring these complementary layers together through: • NeuroID adds behavioral context during onboarding and account creation, helping identify interaction patterns that may indicate automation, manipulation or coordinated fraud. • Precise ID® strengthens identity verification and resolution by comparing applicant information with trusted identity data. • AtData, recently added to our portfolio, contributes email-centered intelligence based on persistence, engagement and long-term digital history. Together, these capabilities help organizations move beyond evaluating a single moment in time to understanding whether an identity is supported by consistent behavior, trusted identity data and an established digital history. The future of fraud prevention isn't about rewarding the smoothest application. It's about recognizing the most trustworthy identity. Fraudsters can rehearse an application. They can optimize an onboarding journey. They can even assemble convincing identity attributes. What they can't easily manufacture is years of ordinary digital life. That's why digital identity continuity has become an important layer of modern fraud prevention. Combined with identity verification and behavioral intelligence, it helps organizations distinguish between identities that simply look convincing and those supported by a history that is much harder to fake. Learn more Contact us

September 2, 2026 by Julie Lee

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe