FIME launches online NFC CAP file security analysis service

FIME has launched TrustApp, a secure online testing portal for near field communication (NFC) applications embedded in secure elements.

Mobile network operators (MNO) and NFC service providers can now validate the security of their sensitive and basic NFC applications, quicker and more cost effectively.

“As TrustApp is online, it allows stakeholders to perform on-demand pre-certification security testing throughout the development process, 24/7 and wherever they are,” commented Christian Damour, head of Product and Services Marketing, Security, at FIME. “Applications can then be submitted to a test laboratory for final validation with confidence that they will pass the official testing process. This process helps our customers save time and money while avoiding the frustration that can arise if an issue is identified at this final approval stage.”

The primary function of the portal is CAP File analysis. Due to the sensitivity of testing the CAP File – an NFC application’s bytecode which contains intellectual property – the file is automatically encrypted on the client’s machine before it is uploaded to the testing platform and stored on a secure server. Testing this file confirms that the NFC application conforms to the relevant industry security standards. The portal also gives users immediate and convenient access to fully automated end-to-end application testing and report generation, as well as report download.

Christian Damour, head of Product and Services Marketing, Security, FIME
Christian Damour, head of Product and Services Marketing, Security, FIME

“This service helps NFC service providers to ensure their NFC applications are compliant, at their convenience,” added Christian. “Both sensitive and basic applications need to be tested to complete the NFC security chain as even the simplest of NFC applications could compromise a user’s device if it does not meet the required standards. The ability to access a secure online portal to perform pre-certification testing makes the whole process quicker and more convenient, while reducing overall costs and maintaining the security of customers’ data.”

FIME has developed this service in collaboration with the Celtique team at Inria, a research team dedicated to improving the security and reliability of smart card and secure device software. It includes analysis for alignment with key security rules from a number of international industry authorities and platform manufacturers. Additional bespoke security rules can also be developed and added to the tool.

Once the basic or sensitive application has been verified by the online portal, the final stage is local laboratory validation by FIME’s experts. Applications are subjected to additional CAP File analysis, source code review and testing for compliance to the key security rules. Sensitive applications are also security tested against relevant industry application requirements.

Comment on this article below or via Twitter: @ VanillaPlusMag OR @jcvplus

RECENT ARTICLES

EchoStar to provide 5G services for U.S. Navy’s spiral 4 programme

Posted on: May 16, 2024

EchoStar Corporation has announced they have been awarded an indefinite delivery, indefinite quantity (IDIQ) contract as part of the U.S. Naval Supply Systems Command Spiral 4 wireless products and services

Read more

Open6G OTIC at Northeastern launches open RAN testing solutions

Posted on: May 15, 2024

The Open6G Open Testing and Integration Center (OTIC) at the Institute for the Wireless Internet of Things (WIoT) at Northeastern University announces the general availability of testing and integration solutions for

Read more