Preprint
Concept Paper

This version is not peer-reviewed.

Security Architecture and Vulnerabilities of NFC Applications for Mobile Devices

Submitted:

31 December 2025

Posted:

01 January 2026

You are already at the latest version

Abstract
Near Field Communication (NFC) technology is increasingly being integrated into mobile devices, enabling applications such as contactless payments and public transportation access. This paper investigates the security architecture of NFC systems, focusing on mobile device implementations and the vulnerabilities they introduce. Various configurations for NFC’s Secure Element (SE), such as SD cards, multiple UICC slots, and shared SIM resources, are discussed, highlighting potential security challenges related to relay attacks, malware distribution, differential power analysis, and denial-of-service attacks. In particular, relay attacks and malware distribution are identified as significant threats that could compromise user security during transactions. The paper further explores countermeasures like two-factor authentication, distance-bounding protocols, and defensive cryptographic techniques to mitigate these risks. Additionally, it emphasizes the complexities introduced by trust issues between Mobile Network Operators (MNOs) and thirdparty providers in sharing secure resources. Finally, the research suggests that while NFC itself is relatively secure, applications built on top of this infrastructure are more prone to security risks. As NFC technology continues to evolve, ensuring robust security for its applications, particularly in the financial and healthcare sectors, will be critical to its widespread adoption.
Keywords: 
;  ;  ;  ;  ;  ;  ;  ;  ;  ;  ;  ;  ;  
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.
Prerpints.org logo

Preprints.org is a free preprint server supported by MDPI in Basel, Switzerland.

Subscribe

Disclaimer

Terms of Use

Privacy Policy

Privacy Settings

© 2026 MDPI (Basel, Switzerland) unless otherwise stated