Secure element with external resource
By utilizing the external memory of a computer system and cryptographic processing, secure elements solve the resource shortage problem caused by the fixed memory of traditional secure elements, achieving flexible adaptation and cost reduction.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-02-27
- Publication Date
- 2026-03-17
AI Technical Summary
Traditional security elements have fixed non-volatile memory capacity, which cannot meet the ever-increasing resource demands and functional upgrades of computer systems, resulting in high costs and insufficient resources.
Secure elements utilize external memory of the computer system, such as flash memory, to store secure applications and sensitive information, and process and verify information internally through a cryptographic processing engine, reducing the need for internal memory.
It enables flexible adaptation to the resource needs of computer systems without increasing internal memory, reducing costs and maintaining security.
Smart Images

Figure CN114616569B_ABST
Abstract
Description
Background Technology
[0001] Computer systems such as smartphones, wearable computers, and tablets typically include one or more secure elements to perform specialized functions using sensitive information. In other words, secure elements provide an environment to securely store sensitive information and execute applications for completing financial transactions, performing cryptographic functions, accessing telecommunications networks and other external resources, authenticating users, or accessing sensitive user data.
[0002] A secure element is typically a standalone component of a computer system with a fixed capacity of non-volatile memory. As computer systems perform increasingly specialized functions using sensitive information, the resources of the secure element become insufficient. Significantly expanding the non-volatile memory of the secure element is prohibitively expensive, especially since some computer systems will not utilize additional memory. A secure element with sufficient resources is needed to accommodate a wide range of computer system and system function upgrades. Summary of the Invention
[0003] This document describes a secure element that utilizes the resources of a computer system to perform dedicated functions using sensitive information. The secure element securely stores sensitive information on the computer system's non-volatile memory. In response to a request to use the sensitive information, the secure element loads a security application and the sensitive information from the computer system. By utilizing external resources, the secure element can flexibly adapt to the increasing resource demands of the computer system and can be used in a wide range of computer systems.
[0004] For example, a secure element is described that cryptographically processes sensitive information before storing it in the memory of a computer system. In response to a request to use the sensitive information, the secure element loads a security application and the sensitive information from the computer system's memory into its internal memory. The secure element cryptographically processes the sensitive information (e.g., decrypts, authenticates, and verifies its freshness). The secure element then executes the security application and generates a result using the sensitive information. The secure element outputs the result to the computer system.
[0005] This document also describes other configurations and methods for using the resources of a computer system to process and protect sensitive information, as well as computer systems that include these security element configurations.
[0006] This invention is provided to introduce a simplified concept of a security element utilizing external resources, which will be further described in the detailed description and accompanying drawings below. This invention is not intended to identify essential features of the claimed subject matter, nor is it intended to define the scope of the claimed subject matter. Attached Figure Description
[0007] This document describes in detail one or more aspects of a security element utilizing external resources with reference to the following figures. The same reference numerals are used in the various figures to refer to the same features and components:
[0008] Figure 1 The illustration shows an exemplary security element of a computer system that uses the computer system's memory to securely store sensitive information.
[0009] Figure 2 The illustration shows an example of a secure element that utilizes a computer system's memory to respond to requests for access to sensitive information.
[0010] Figure 3 This is a flowchart illustrating an exemplary operation performed by a security element in response to a request for access to sensitive information, utilizing external resources of a computer system.
[0011] Figure 4-1 The illustration shows an exemplary configuration of a security element used to complete a financial transaction.
[0012] Figure 4-2 The illustration shows an exemplary configuration of a security element that accesses a user's biometric data to log in to an application.
[0013] Figures 5-1 to 5-4 An exemplary configuration of a security element for accessing a mobile network is illustrated. Detailed Implementation
[0014] Overview
[0015] This document describes a secure element that utilizes the resources of a computer system to perform dedicated functions that require the use of sensitive information. In response to a request to use sensitive information, the secure element loads a security application and the sensitive information from the memory of the computer system external to the secure element. The processor of the secure element then executes the security application to generate results using the sensitive information. By utilizing external resources of the computer system, the secure element can be used in a wide range of computer systems and flexibly adapts to increasing resource demands, such as when the computer system is upgraded or when additional dedicated functions need to be performed. In doing so, the described secure element reduces costs without compromising the security of sensitive information.
[0016] For example, consider a secure element installed in a smartphone. Upon purchase, the secure element is configured to access communication networks using cryptographic keys and complete financial transactions using financial data. When new applications are added, the secure element must protect and process additional sensitive information. Traditional secure elements have a fixed amount of non-volatile memory and cannot utilize the resources of a smartphone (e.g., flash memory). Therefore, traditional secure elements ultimately cannot protect and process additional sensitive information. Alternatively, a secure element could have sufficient non-volatile memory to accommodate future upgrades and added features. However, additional memory is expensive and may be unnecessary for certain market segments, computer systems, and the use cases of the secure element.
[0017] Unlike conventional security elements, the described secure element utilizes the large external memory (e.g., flash memory) of a smartphone to store applications and sensitive information. Typically, a smartphone's flash memory is orders of magnitude larger than that of a conventional security element. The cryptographic processing of the secure element securely stores sensitive information in the smartphone's flash memory along with other system code and data. Although other smartphone components can access the flash memory, the cryptographic processing protects the sensitive information from their influence. In response to a request to use the sensitive information, the secure element loads the secure application and sensitive information from the smartphone's external memory. The secure element then executes the secure application to generate results using the sensitive information. The smartphone is configured to perform security functions, access resources, etc., based on the output of the secure element's results. Therefore, the secure element maintains the security of a conventional security element, while its secure storage capacity is limited only by the capacity of the computer system's external memory.
[0018] Furthermore, the described security element can be configured with reduced memory or to perform better by sequentially loading portions of the security application. The security element can then generate the intermediate results required for its dedicated functions, thereby reducing the security element's internal volatile memory (e.g., random access memory (RAM) requirements).
[0019] As a working example, consider a smartphone that initiates and attempts to connect to a mobile network. The smartphone sends a message to the mobile network to initiate the connection process. In response, the mobile network sends an authentication request to the smartphone, which includes a random value. The secure element loads the network authentication software and related sensitive information, including a Mobile Network Operator (MNO) profile with an authentication key, from the smartphone's memory into its internal RAM. When a user subscribes to a mobile network service, the MNO initially provides the authentication key to the smartphone within its MNO profile during the provisioning step. The secure element stores the MNO profile containing the authentication key as encrypted data in the smartphone's flash memory. The secure element then cryptographically processes the MNO profile and the authentication key and executes the network authentication software. The secure element uses an algorithm within the network authentication software to calculate a response value based on the random value and the authentication key.
[0020] Before the smartphone sends a response, the secure element loads network cryptographic software from the smartphone's memory into its internal RAM. The secure element can load the network cryptographic software, overriding previously loaded network authentication software. Based on a random value and the authentication key, the secure element uses an algorithm contained in the network cryptographic software to calculate a session key. The smartphone then sends the response value and session key to the mobile network. If the response value matches the value calculated by the mobile network, the mobile network authenticates the smartphone and grants it access. Subsequent voice messages on the mobile network are then encrypted and decrypted using the session key.
[0021] These are merely two examples of how the described secure element can be configured to utilize external resources of a computer system. Other exemplary configurations and usage methods are described throughout this document. This document now describes exemplary configurations of the described secure element, followed by exemplary methods.
[0022] The configuration of the described safety elements
[0023] Figure 1 The illustration shows an exemplary security element 110 that utilizes the resources of computer system 100 to protect sensitive information 108. Sensitive information 108 may include access keys, cryptographic keys, financial data, user health data, user biometric data, etc. Computer system 100 may be various consumer electronic devices. As a non-limiting example, computer system 100 may be a mobile phone 100-1, a tablet device 100-2, a car display, a laptop computer 100-3, a television, an electronic display, a desktop computer 100-4, a computerized watch 100-5, a wearable computer 100-6, a video game controller 100-7, a server, a networked multimedia or voice assistant system 100-8, or an appliance 100-9.
[0024] Computer system 100 includes a secure element 110, a processing unit 122, random access memory (RAM) 102, and flash memory 104. RAM 102 and flash memory 104 are external to and not incorporated into the secure element 110. The secure element 110 utilizes flash memory 104 to store a security application 106 and sensitive information 108. As used herein, the term "security application" refers to an application that can be executed by the processor 114 within the secure element 110. In the context of security application 106, the word "security" is intended for identification purposes and should not be construed as implying any requirement or limitation on the functionality of security application 106.
[0025] RAM 102 can load security application 106 to perform functions that do not require the use of sensitive information 108. Within secure element 110, security application 106 can use sensitive information 108 to perform dedicated functions. For example, secure element 110 can facilitate financial transactions by storing and using users' personal information (e.g., account number, routing number, credentials, security token). Secure element 110 can also perform health monitoring functions to record users' health records in flash memory 104. As another example, computer system 100 may include software for an embedded user identity module (eSIM), and secure element 110 can use flash memory 104 to store telecommunications data associated with the user. Furthermore, secure element 110 can perform authentication functions (e.g., password authentication, facial authentication, fingerprint authentication) and require flash memory 104 to store authentication data for subsequent use and retrieval.
[0026] The processing unit 122 serves as the central processing unit of the computer system 100. The processing unit 122 may include other components such as a processor, a communication unit (e.g., a modem), an input / output controller, a sensor hub, a system interface, etc.
[0027] Flash memory 104 stores sensitive information 108 and security applications 106, as well as other executable instructions (e.g., firmware, recovery firmware, software, applications, modules, programs, functions, etc.) and data (e.g., user data, operational data, scan results). Flash memory 104 provides a large storage capacity. Although primarily described as flash memory, flash memory 104 can be any non-volatile memory component used for permanent storage. Flash memory 104 can be accessed by processing unit 122 and other components of computer system 100. Unless data is cryptographically protected before being written to flash memory 104, any system component can read or modify the data.
[0028] When computer system 100 executes security application 106, security application 106 or a portion thereof is loaded into RAM 102. RAM 102 can be any volatile memory used by computer system 100 to store active code and data. RAM 102 can include various implementations of RAM, including dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate (DDR) SDRAM, and other types of volatile memory in various configurations.
[0029] RAM 102 and flash memory 104 are not typically certified as components with security features. Computer components can be evaluated against industry standards to obtain certification for specific security attributes. For example, general standards for information technology security assessment (also known as universal standards) are international standards used to develop, evaluate, and certify the security features of hardware and software components. Therefore, RAM 102 and flash memory 104 can be implemented using general-purpose and widely available memory components instead of proprietary certified components.
[0030] RAM 102, flash memory 104, and processing unit 122 communicate via link 130. Link 130 may be a memory bus that links processing unit 122 and other components of computer system 100 to RAM 102 and flash memory 104. RAM 102, flash memory 104, and processing unit 122 are physically separate components from secure element 110. In other words, secure element 110 can access RAM 102, flash memory 104, and processing unit 122, but these components are external to secure element 110.
[0031] The secure element 110 and the processing unit 122 communicate via link 132. Link 132 is not typically secure. Link 132 may be a memory bus that links the processing unit 122 and other components of the computer system 100 to the secure element 110.
[0032] Secure element 110 communicates with RAM 102 and flash memory 104 via links 132 and 130. Secure element 110 accesses secure application 106 from RAM 102 or flash memory 104. Secure element 110 also accesses sensitive information 108 from RAM 102 or flash memory 104. Secure element 110 directs read or write commands to RAM 102 and flash memory 104 via links 132 and 130.
[0033] The secure element 110 includes a memory 112, a processor 114, and a cryptographic processing engine 116. In some cases, the memory 112 may include more than one component, such as non-volatile memory and internal RAM. The non-volatile memory of the memory 112 may include any flash memory or non-flash memory configured to securely store data. The non-volatile memory may include flash memory and read-only memory (ROM). Similar to RAM 102, the internal RAM of the memory 112 may include various implementations of RAM, including DRAM, SDRAM, DDR SDRAM, and other types of volatile or non-volatile memory with different configurations. In other cases, the memory 112 may include a single component, such as non-volatile RAM (NVRAM). The NVRAM of the memory 112 may include magnetic RAM (MRAM) or resistive RAM (RRAM). If power to the secure element 110 is lost, the MRAM and RRAM will not lose stored data. In addition, the MRAM and RRAM allow the secure element 110 to respond to requests in low-power mode or when powered by an electromagnetic radiation field. The memory 112 is typically much smaller than the flash memory 104. As an example, the flash memory 104 of a smartphone may have a capacity of 64 gigabytes (GB); in contrast, the memory 112 of the secure element 110 is several orders of magnitude smaller (e.g., 1 megabyte (MB)). However, memory 112 provides sufficient storage to store cryptographic keys 120 and other cryptographic information (e.g., additional cryptographic keys, timestamp information, replay counters) to protect and process sensitive information 108. Unlike the data stored in flash memory 104, the data maintained in memory 112 is only accessible within the secure element 110.
[0034] Memory 112 or its internal RAM stores working data and code. When the security element 110 responds to a request to use sensitive information 108, security application 106 or a portion thereof is loaded from RAM 102 or flash memory 104 into memory 112 via links 130 and 132.
[0035] Because memory 112 stores cryptographic keys 120 but not sensitive information 108 or security applications 106, memory 112 is much smaller than flash memory 104. As the computer system 100 is upgraded and expanded in the future, the amount of sensitive information 108 protected and processed by the described security element 110 can grow without increasing memory 112.
[0036] Processor 114 executes computer-executable instructions, including security application 106, to perform special functions using sensitive information 108. Processor 114 may include any combination of one or more controllers, microcontrollers, processors, microprocessors, etc.
[0037] Cryptographic processing engine 116 manages the cryptographic processing of sensitive information 108, either alone or in combination with processor 114. Cryptographic processing engine 116 can be implemented as hardware, programmable logic, software, a controller, or a microcontroller. Cryptographic processing engine 116, either alone or in combination with processor 114, encrypts sensitive information 108 using cryptographic key 120 before writing it to flash memory 104. After secure element 110 loads sensitive information 108 from flash memory 104, cryptographic processing engine 116, either alone or in combination with processor 114, decrypts sensitive information 108 using cryptographic key 120. Cryptographic processing engine 116, either alone or in combination with processor 114, also authenticates and verifies the freshness of sensitive information 108. Without cryptographic key 120, sensitive information 108 is secure and unusable by other components and systems.
[0038] The cryptographic processing engine 116 can provide forward security by automatically changing the cryptographic key 120. To prevent the cryptographic key 120 from being leaked at some point, the cryptographic key 120 is automatically updated before each encryption and the subsequent writing of sensitive information 108 to flash memory 104. Alternatively, the cryptographic processing engine 116 can generate new cryptographic keys randomly, periodically, or in response to events.
[0039] Figure 2 An exemplary configuration of a security element 210 is illustrated, which utilizes RAM 102 and flash memory 104 in response to a request for access to sensitive information 108. In this example, the computer system 200 and the security element 210 include... Figure 1 The components shown in the computer system 100 and security element 110 are similar to those in the computer system 100, but with some additional details.
[0040] The memory of the secure element 210 includes internal RAM 218, internal flash memory 212, and read-only memory (ROM) 214. The internal flash memory 212 stores the cryptographic key 120. The internal flash memory 212 can also temporarily store the sensitive information 108 when the secure element 210 loads the sensitive information 108 in response to a special function request.
[0041] ROM 214 stores operating system (OS) 220 that manages the operation of security element 210. When security application 106 or a portion thereof is loaded into internal RAM 218, processor 114 uses operating system 220 to execute security application 106 or a portion thereof.
[0042] The secure element 210 can receive requests to perform security functions, such as facilitating financial transactions or performing cryptographic functions; accessing resources inside or outside the computer system, such as authenticating access to a communication network, logging into applications on the computer system 200, or entering the authentication status of the computer system 200; or processing sensitive data, such as performing health monitoring functions. The request requires the secure element 210 to use sensitive information 108 to perform a security application 106.
[0043] In response to the request, security element 210 loads security application 106 or a portion thereof into internal RAM 218. Security application 106 or a portion thereof is loaded from RAM 102 or flash memory 104 via links 130 and 132.
[0044] The secure element 210 also loads sensitive information 108 from flash memory 104 into internal RAM 218 or internal flash memory 212 via links 130 and 132. Links 130 and 132 may be low-latency links without internal buffers, allowing the secure element 210 to perform direct read and write operations to RAM 102 and flash memory 104. As an example, links 130 and 132 may include peripheral component fast interconnect (fast PCI or PCIe) links. Alternatively, the secure element 210 loads security application 106, a portion of security application 106, or sensitive information 108 via link 234. Link 234 provides the secure element 210 with direct byte-by-byte or memory-mapped access to data stored in flash memory 104 (e.g., sensitive information 108, security application 106, a portion of security application 106). Link 234 enables the secure element 210 to treat the mapped portion of the flash memory 104 as if it were included in the secure element 210, thereby allowing faster read and write operations than via links 130 and 132.
[0045] The cryptographic processing engine 116, alone or in combination with the processor 114, uses cryptographic key 120-1 to decrypt sensitive information 108. The cryptographic processing engine 116, alone or in combination with the processor 114, uses cryptographic key 120-1 to authenticate and verify the freshness of sensitive information 108. Cryptographic key 120-1 is obtained from internal flash memory 212. The cryptographic processing engine 116, alone or in combination with the processor 114, can also use cryptographic key 120-1 or another cryptographic key (not shown) to cryptographically process security application 106 or a portion thereof.
[0046] Processor 114 executes security application 106 or a portion thereof to generate results using sensitive information 108. Security element 210 uses processor 114 to output the results to processing unit 122. Computer system 200 is configured to perform security functions, authenticate access to resources internal or external to computer system 200, or process sensitive data based on the output of the results from the security element. For example, computer system 200 is configured to facilitate financial transactions, perform cryptographic functions, authenticate access to communication networks by computer system 200 or its users, log in to applications on computer system 200, enter the authentication state of computer system 200, perform health monitoring functions, etc., based on the output of the results.
[0047] Then, the cryptographic processing engine 116, alone or in combination with the processor 114, can use cryptographic key 120-1 or a newer cryptographic key 120-2 to cryptographically process (e.g., encrypt, sign, timestamp) the sensitive information 108. The secure element 210 then writes the sensitive information 108 to flash memory 104, overwriting older sensitive information 108. The secure element 210 also removes the sensitive information 108 from internal RAM 218 or internal flash memory 212.
[0048] Alternatively, after executing security application 106 or a portion thereof, security element 210 determines whether sensitive information 108 has been modified. If sensitive information 108 has been modified, cryptographic processing engine 116, alone or in combination with processor 114, processes sensitive information 108 cryptographically using cryptographic key 120-1 or a newer cryptographic key 120-2. Security element 210 then writes sensitive information 108 to flash memory 104, overwriting older sensitive information 108. If sensitive information 108 has not been modified, security element 210 removes sensitive information 108 from internal RAM 218 or internal flash memory 212.
[0049] Figure 3This is a flowchart illustrating an exemplary operation 300 performed by security element 110 in response to a request for access to sensitive information 108. Figure 1 Operation 300 is described in the context of computer system 100. Operation 300 may be executed in a different order, or may have more or fewer operations than those illustrated.
[0050] At 302, the security element 110 loads the security application 106 or a portion thereof into the memory 112 from the RAM 102 or the flash memory 104 via a first interface consisting of links 130 and 132.
[0051] At 304, the security element 110 loads sensitive information 108 from flash memory 104 into memory 112 via a second interface or a first interface consisting of memory-mapped links.
[0052] At 306, the cryptographic processing engine 116, alone or in combination with the processor 114, uses the cryptographic key 120-1 to perform cryptographic processing on the sensitive information 108. In some cases, the cryptographic processing engine 116, alone or in combination with the processor 114, may also use the cryptographic key 120-1 to cryptographically process the security application 106 or a portion thereof.
[0053] At 308, processor 114 executes security application 106 or a portion thereof to generate results using sensitive information 108. In some cases, security element 110 repeats operations 302 and 308 to sequentially load and execute portions of security application 106 to generate intermediate results using sensitive information 108 or earlier intermediate results.
[0054] At 310, the secure element 110 outputs the result to the processing unit 122 via the processor 114. In some cases, the result includes one or more intermediate results from operation 308. The computer system 100 is configured to perform security functions, authenticate access to resources internal or external to the computer system 100, or process sensitive data based on the output of the result from the secure element 110. For example, the computer system 100 may be configured to facilitate financial transactions, encrypt communications, perform health monitoring functions, access communication networks, etc.
[0055] In some cases, the secure element 110 performs further operations on the sensitive information 108. At 312, the secure element 110 determines whether the sensitive information 108 has been modified. At 314, if the sensitive information 108 has been modified, the cryptographic processing engine 116, alone or in combination with the processor 114, uses the cryptographic key 120-1 or a newer cryptographic key to process the sensitive information 108 cryptographically. At 316, the modified sensitive information 108 is written to the flash memory 104, overwriting the sensitive information 108. At 318, the sensitive information 108 is removed from the memory 112. If the sensitive information 108 has not been modified, the secure element 110 skips operations 314 and 316 and executes operation 318. In other cases, the secure element 110 may skip operation 312 and execute operations 314 through 318.
[0056] If a second request is received requesting the use of sensitive information, the security element 110 repeats operations 302 to 318 as needed.
[0057] Exemplary configuration
[0058] This section illustrates exemplary configurations of safety elements that can operate individually or together, in whole or in part. Various exemplary configurations are described in this section, each illustrated in a subsection for ease of reading; these subsection headings do not limit the interoperability of each of these configurations.
[0059] Financial transactions
[0060] Figure 4-1 The illustration shows an exemplary configuration of a secure element 410 that utilizes the RAM 102 and flash memory 104 of a smartphone 400 to complete financial transactions with a cash register 450. The smartphone 400 and the secure element 410 include... Figure 1 The computer system 100 shown is similar to the secure element 110, wherein the memory 112 of the secure element 110 includes the internal RAM 418 and non-volatile memory 412 in the secure element 410.
[0061] Smart phone 400 is Figure 1 The example device of computer system 100 has some additional details. Smartphone 400 includes RAM 102, flash memory 104, processing unit 122, and security element 410. Smartphone 400 also includes one or more communication components 440 and one or more input / output components 442. Processing unit 122 also includes one or more system processors 424, one or more communication interfaces 426, and one or more input / output interfaces 428.
[0062] System processor 424 executes computer-executable instructions and performs operations on smartphone 400. System processor 424 may include any combination of one or more controllers, microcontrollers, processors, microprocessors, hardware processors, graphics processors, video processors, etc.
[0063] Communication component 440 enables wired or wireless data communication between smartphone 400 and other devices, computer systems, and networks (e.g., cash register 450). Communication component 440 may include receivers, transmitters, and transceivers for various types of wired and wireless communications. Communication component 440 may include short-range radios (e.g., near field communication (NFC) transceivers) capable of connecting to nearby devices and cellular radios for connecting to base stations. Processing unit 122 includes communication interface 426 for processing message passing and protocols for sending and receiving communications via communication component 440.
[0064] Input / output component 442 provides connectivity to smartphone 400. Input / output component 442 may include a user interface device that manages the user interface of smartphone 400. Input / output component 442 may also include sensors for obtaining contextual information indicative of the physical operating environment or characteristics of smartphone 400. Examples of input / output component 442 include cameras, optical sensors, infrared sensors, radar sensors, accelerometers, temperature sensors, gyroscopes, proximity sensors, light sensors, humidity sensors, pressure sensors, etc. Input / output component 442 can provide additional connectivity beyond the user interface device and sensors. System processor 424 can customize the operation of smartphone 400 based on input information obtained from input / output component 442 via input / output interface 428.
[0065] As a working example, consider a smartphone 400 held by a user purchasing products in a store. When the user places the smartphone 400 near a cash register 450, a communication component 440 detects a short-range communication signal (e.g., an NFC signal) from the cash register 450. A system processor 424 receives information from a communication interface 426 based on the communication signal received by the communication component 440. A secure element 410 acts on the information received by the system processor 424 to complete the payment. The secure element 410 loads a payment application 406 into internal RAM 418. The payment application 406 is loaded from RAM 102 via links 130 and 132. The secure element 410 also loads the user's financial data 408 (e.g., credit card number, credit card expiration date) into internal RAM 418 or non-volatile memory 412. The financial data 408 is stored as encrypted data on flash memory 104. The secure element 410 loads the financial data 408 via links 130 and 132. Cryptographic processing engine 116 uses cryptographic key 120 to cryptographically process financial data 408. Processor 114 executes payment application 406 and completes the payment using financial data 408. Then, secure element 410 sends a signal indicating payment completion to input / output interface 428 and communication interface 426 via system processor 424. In response to this signal, input / output component 442 changes the user interface of smartphone 400 to indicate successful payment. Communication component 440 also sends a message indicating payment completion to cash register 450.
[0066] Biostatistics
[0067] Figure 4-2 The illustration shows an exemplary configuration of a security element 410 that verifies a user's biometric data to complete login to an application. The smartphone 400 and the security element 410 include... Figure 4-1 The components shown are the same components.
[0068] As a working example, consider a user of a smartphone 400 who wants to complete the integration Figure 4-1Shortly after the financial transaction discussed, the user checks his credit card balance. The user opens a banking app 404 on smartphone 400. The banking app 404 prompts the user for his username and password. Input / output component 442 modifies the user interface of smartphone 400 to indicate that the user can use biometric data (e.g., facial recognition data, fingerprint data) to enter his account information. In response to the user selecting the autofill option, input / output component 442 activates a sensor (e.g., an infrared camera or radar system) to capture an image of the user's face. System processor 424 receives the facial image and sends it to secure element 410. Secure element 410 then loads a password manager app 402 into internal RAM 418, overwriting payment app 406. Secure element 410 also loads the user's facial recognition data 414 from flash memory 104 into internal RAM 418 or non-volatile memory 412. Cryptographic processing engine 116 decrypts facial recognition data 414 using cryptographic key 120-2. Processor 114 compares facial recognition data 414 with a facial image received from system processor 424. If the facial image matches facial recognition data 414, secure element 410 provides a username and password to banking application 404. Banking application 404 receives the username and password and logs the user into her credit card account.
[0069] Network authentication
[0070] Figures 5-1 to 5-4 An exemplary configuration of a secure element 410 connecting a smartphone 400 to a mobile network 550 is illustrated. The smartphone 400 and the secure element 410 include components... Figure 4-1 and Figure 4-2 The components shown are the same components.
[0071] As another working example, consider Figure 5-1 The smartphone 400 is activated and attempts to connect to the mobile network 550. The communication component 440 sends a message to the mobile network 550 to initiate the connection process. This message includes the identity of the mobile network 550 and the subscriber identifier of the smartphone 400. In response, the mobile network 550 sends an authentication request, including a random value 520, to the smartphone 400. The communication component 440 detects the signal with the authentication request and forwards it to the system processor 424 via the communication interface 426. The system processor 424 then sends the authentication request to the secure element 410.
[0072] exist Figure 5-2In this process, secure element 410 loads a random value 520 into internal RAM 418 and applies it to the authentication request to calculate a response value. Secure element 410 loads network authentication software 506-1 from flash memory 104 into internal RAM 418. Secure element 410 also loads an authentication key 508 into internal RAM 418. The authentication key 508 is stored as encrypted data on flash memory 104. During the setup process when smartphone 400 subscribes to mobile network 550, mobile network 550 initially provides authentication key 508 to smartphone 400 in a mobile network operator (MNO) profile. Cryptographic processing engine 116 uses cryptographic key 120 to cryptographically process authentication key 508. Processor 114 applies the algorithm contained in network authentication software 506-1 to the random value 520 and authentication key 508 to obtain response value 530.
[0073] like Figure 5-3 As shown, before sending the response value 530 to the mobile network 550, the secure element 410 loads the network cryptography software 506-2 from the flash memory 104 into the internal RAM 418 via the network authentication software 506-1. The processor 114 applies the algorithm contained in the network cryptography software 506-2 to the random value 520 and the authentication key 508 to generate the session key 532.
[0074] like Figure 5-4 As shown, the security element 410 sends a response value 530 and a session key 532 to the communication component 440. The communication component 440 sends an authentication response, including the response value 530 and the session key 532, to the mobile network 550. If the response value 530 matches the expected value, the smartphone 400 is authenticated and granted access to the mobile network 550. Subsequent voice communications between the smartphone 400 and the mobile network 550 are encrypted (and decrypted) using the session key 532.
[0075] After sending the authentication response, the secure element 410 removes the network cryptographic software 506-2 from the internal RAM 418. Then, the cryptographic processing engine 116 processes the authentication key 508 and session key 532 cryptographically using the cryptographic key 120 or a newer cryptographic key (not shown). The authentication key 508 and session key 532 are written to the flash memory 104 and removed from the internal RAM 418.
[0076] Example
[0077] Examples are provided in the following sections.
[0078] Example 1: A security element for use in a computer system, the security element comprising: a processor; a memory; and a cryptographic processing engine, the security element being configured, in response to a request for use of sensitive information, to: load a security application or a portion thereof into the memory from a first external memory of the computer system via a first interface, the first external memory being accessible by a processing unit of the computer system, the processing unit being external to the security element; load the sensitive information into the memory from the first external memory or a second external memory of the computer system via the first interface or a second interface, the second external memory being accessible by the processing unit; process the sensitive information cryptographically using a cryptographic key obtained from the memory, either alone or in conjunction with the processor, the cryptographic processing engine; execute the security application or the portion thereof by the processor to generate a result using the sensitive information; and output the result to the processing unit by the processor.
[0079] Example 2: According to the security element of Example 1, wherein the security element is configured to: load a first portion of the security application when loading the security application or a portion thereof, and execute the first portion of the security application by the processor to generate a first intermediate result using the sensitive information when executing the security application or a portion thereof to generate a result using the sensitive information; wherein the security element is further configured to: load a second portion of the security application into the memory from the first external memory via the first interface before outputting the result to the processing unit; and execute the second portion of the security application by the processor to generate a second intermediate result using the sensitive information or the first intermediate result; and wherein the security element is configured to output the first intermediate result or the second intermediate result by the processor when outputting the result to the processing unit.
[0080] Example 3: A security element according to any of the preceding examples, wherein the security element is further configured to: process the sensitive information cryptographically by the cryptographic processing engine alone or in conjunction with the processor using the cryptographic key or a second cryptographic key, the second cryptographic key being obtained from the memory; write the cryptographically processed sensitive information to the first external memory or the second external memory to overwrite the sensitive information in the first external memory or the second external memory; and remove the sensitive information from the memory.
[0081] Example 4: A security element according to Example 1 or Example 2, wherein the security element is further configured to: determine that the sensitive information has been modified; process the modified sensitive information cryptographically by the cryptographic processing engine alone or in conjunction with the processor using the cryptographic key or a second cryptographic key, the second cryptographic key being obtained from the memory; write the cryptographically modified sensitive information to the first external memory or the second external memory to overwrite the sensitive information in the first external memory or the second external memory; and remove the modified sensitive information from the memory.
[0082] Example 5: A security element according to Example 1 or Example 2, wherein the security element is further configured to: determine that the sensitive information has not been modified; and remove the sensitive information from the memory.
[0083] Example 6: According to any of the preceding examples, the security element is further configured to: perform cryptographic processing on the security application, the portion of the security application, the first portion of the security application, or the second portion of the security application by the cryptographic processing engine, either alone or in conjunction with the processor, using the cryptographic key or a third cryptographic key, wherein the third cryptographic key is obtained from the memory.
[0084] Example 7: A security element according to any of the preceding examples, wherein, in response to a second request for the use of second sensitive information, the security element is configured to: load a second security application or a portion thereof into the memory from the first external memory via the first interface; load the second sensitive information into the memory from the first external memory or the second external memory via the first interface or the second interface; process the second sensitive information cryptographically using the cryptographic key or a fourth cryptographic key, obtained from the memory, alone or in conjunction with the processor, by the cryptographic processing engine; execute the second security application or the portion thereof by the processor to generate a second result using the second sensitive information; and output the second result to the processing unit by the processor, the second result being used to authenticate access to resources outside the computer system, authenticate access to internal resources of the computer system, facilitate financial transactions, perform cryptographic functions, or perform health monitoring functions.
[0085] Example 8: A security element according to any of the preceding examples, wherein the first interface is a low-latency interface for direct read and write operations by the security element from the first external memory or the second external memory.
[0086] Example 9: A security element according to any one of Examples 1 to 7, wherein a direct byte-by-byte association is assigned to the security element via the first interface with the security application, the portion of the security application, the first portion of the security application, the second portion of the security application, the second security application, the portion of the second security application, the sensitive information, or the second sensitive information, the direct byte-by-byte association enabling the security element to have memory-mapped access to data stored on the first external memory or the second external memory.
[0087] Example 10: A security element according to any of the preceding examples, wherein the first external memory and the second external memory are not proven to have security functions.
[0088] Example 11: A security element according to any of the preceding examples, wherein the sensitive information includes one or more of network access credentials, cryptographic keys, security keys, financial data, passwords, user health data, or sensitive user data.
[0089] Example 12: A security element according to any of the preceding examples, wherein the memory of the security element comprises non-volatile random access memory.
[0090] Example 13: The security element according to Example 12, wherein the non-volatile random access memory includes magnetic random access memory or resistive random access memory.
[0091] Example 14: A security element according to any one of Examples 1 to 11, wherein the memory of the security element comprises random access memory and non-volatile memory, and wherein the security element is configured to: load the security application, a portion of the security application, the first portion of the security application, the second portion of the security application, the second security application, or a portion of the second security application into the random access memory; load the sensitive information or the second sensitive information into the random access memory or the non-volatile memory; and load the cryptographic key, the second cryptographic key, the third cryptographic key, or the fourth cryptographic key into the non-volatile memory.
[0092] Example 15: The security element according to Example 14, wherein the non-volatile memory of the security element includes a read-only memory and a flash memory, and wherein the security element is configured to load the sensitive information or the second sensitive information into the flash memory or the random access memory, and to load the cryptographic key, the second cryptographic key, the third cryptographic key or the fourth cryptographic key into the flash memory.
[0093] Example 16: A security element according to any of the preceding examples, wherein an operating system is stored in the memory, the non-volatile random access memory, the non-volatile memory, or the read-only memory, and wherein the processor is configured to use the operating system to execute the security application, a portion of the security application, the first portion of the security application, the second portion of the security application, the second security application, or a portion of the second security application.
[0094] Example 17: According to any of the preceding examples, the cryptographic processing of the sensitive information, the second sensitive information, the security application, the portion of the security application, the first portion of the security application, the second portion of the security application, the second security application, or the portion of the second security application includes correspondingly encrypting, authenticating, and verifying the freshness of the sensitive information, the second sensitive information, the security application, the portion of the security application, the first portion of the security application, the second portion of the security application, the second security application, or the portion of the second security application.
[0095] Example 18: A security element according to any of the preceding examples, wherein the computer system includes a smartphone, wearable computer, laptop computer, server, networked multimedia system, voice assistant system, or tablet computer.
[0096] Example 19: A computing device comprising: a security element according to any of the preceding examples; a processing unit linked to the security element via a first interface; a first external memory, wherein the storage capacity of the first external memory is greater than the storage capacity of the memory, and the first external memory is linked to the security element via the first interface or the second interface; and a second external memory, wherein the storage capacity of the second external memory is greater than the storage capacity of the memory, and the second external memory is linked to the security element via the first interface or the second interface.
[0097] Example 20: A computing device according to Example 19, wherein the second interface includes: a low-latency interface for direct read and write operations by the security element from the first external memory, or an interface enabling the security element to perform memory-mapped access to sensitive information, a security application, or a portion thereof stored in the first external memory.
[0098] Example 21: A computing device according to Example 19 or Example 20, wherein the computing device is configured to: authenticate access to resources outside the computing device, authenticate access to internal resources of the computing device, facilitate financial transactions, perform cryptographic functions, or perform health monitoring functions based on the output of the result of the security element.
[0099] Example 22: A computing device according to any one of Examples 19 to 21, wherein the computing device includes a smartphone, a wearable computer, a laptop computer, a server, a networked multimedia system, a voice assistant system, or a tablet computer.
[0100] Example 23: A method for a secure element of a computer system in response to a request for use of sensitive information, comprising: loading a security application or a portion thereof from a first external memory of the computer system into a memory of the secure element via a first interface, the first external memory being accessible by a processing unit of the computer system, the processing unit and the first external memory being external to the secure element; loading the sensitive information into the memory from the first external memory or a second external memory via the first interface or a second interface, the second external memory being accessible by the processing unit and external to the secure element; cryptographically processing the sensitive information using a cryptographic key by a cryptographic processing engine of the secure element, either alone or in conjunction with a processor of the secure element, and retrieving the cryptographic key from the memory; executing the security application or the portion thereof by the processor to generate a result using the sensitive information; and outputting the result to the processing unit via the processor in response to the request.
[0101] Example 24: The method according to Example 23 further includes: loading a first part of the security application when loading the security application or a part of the security application; and executing the first part of the security application by the processor to generate a first intermediate result using the sensitive information when executing the security application or a part of the security application to generate a result using the sensitive information; wherein, before outputting the result to the processing unit: loading a second part of the security application into the memory from the first external memory via the first interface; and executing the second part of the security application by the processor to generate a second intermediate result using the sensitive information or the first intermediate result; and outputting the first intermediate result or the second intermediate result by the processor when outputting the result to the processing unit.
[0102] Example 25: The method according to Example 23 or Example 24 further includes: processing the sensitive information cryptographically by the cryptographic processing engine alone or in conjunction with the processor using the cryptographic key or a second cryptographic key, the second cryptographic key being obtained from the memory; writing the cryptographically processed sensitive information to the first external memory or the second external memory to overwrite the sensitive information in the first external memory or the second external memory; and removing the sensitive information from the memory.
[0103] Example 26: The method according to Example 23 or Example 24 further includes: determining that the sensitive information has been modified; processing the modified sensitive information cryptographically by the cryptographic processing engine alone or in combination with the processor using the cryptographic key or a second cryptographic key, the second cryptographic key being obtained from the memory; writing the cryptographically modified sensitive information to the first external memory or the second external memory to overwrite the sensitive information in the first external memory or the second external memory; and removing the modified sensitive information from the memory.
[0104] Example 27: The method according to Example 23 or Example 24 further includes: determining that the sensitive information has not been modified; and removing the sensitive information from the memory.
[0105] Example 28: According to any one of Examples 23 to 27, before executing the security application, the portion of the security application, the first portion of the security application, or the second portion of the security application, the cryptographic processing engine, alone or in conjunction with the processor, uses the cryptographic key or a third cryptographic key to cryptographically process the security application, the portion of the security application, the first portion of the security application, or the second portion of the security application accordingly, wherein the third cryptographic key is obtained from the memory.
[0106] Example 29: The method according to any one of Examples 23 to 28, in response to a second request for the use of second sensitive information, further includes: loading a second security application or a portion of the second security application, or the second security application or the portion of the second security application, into the memory from the first external memory via the first interface; loading the second sensitive information into the memory from the first external memory or the second external memory via the first interface or the second interface; cryptographically processing the second sensitive information using the cryptographic key or a fourth cryptographic key, the fourth cryptographic key being obtained from the memory, by the cryptographic processing engine alone or in conjunction with the processor; executing the second security application or the portion of the second security application by the processor to generate a second result using the second sensitive information; and outputting the second result to the processing unit by the processor, the second result being used to authenticate access to resources outside the computer system, authenticate access to internal resources of the computer system, facilitate financial transactions, perform cryptographic functions, or perform health monitoring functions.
[0107] Example 30: The method according to any one of Examples 23 to 29, wherein the cryptographic processing of the sensitive information, the second sensitive information, the security application, the portion of the security application, the first portion of the security application, the second portion of the security application, the second security application, or the portion of the second security application includes: correspondingly encrypting, authenticating, and verifying the freshness of the sensitive information, the second sensitive information, the security application, the portion of the security application, the first portion of the security application, the second portion of the security application, the second security application, or the portion of the second security application.
[0108] Example 31: The method according to any one of Examples 23 to 30 further includes: authenticating access to resources outside the computer system, authenticating access to internal resources of the computer system, facilitating financial transactions, performing cryptographic functions, or performing health monitoring functions based on the result output by the security element, the first intermediate result, the second intermediate result, or the second result.
[0109] in conclusion
[0110] While various configurations and methods of using secure elements that utilize the resources of a computer system have been described in language specific to the features and / or methods, it should be understood that the subject matter of the appended claims is not necessarily limited to the specific features or methods described. Rather, the specific features and methods are disclosed as non-limiting examples of secure elements utilizing external resources.
Claims
1. A method performed by a secure element of a computer system, comprising: receiving a request for use of sensitive information; loading, through a first interface, a secure application or a portion of the secure application from a first external memory of the computer system into a memory of the secure element, the first external memory being accessible by a processing unit of the computer system, the processing unit and the first external memory being external to the secure element; loading, through the first interface or a second interface, the sensitive information from the first external memory or a second external memory into the memory, the second external memory being accessible by the processing unit and being external to the secure element; cryptographically processing, by a cryptography processing engine of the secure element, alone or in combination with a processor of the secure element, the sensitive information using a cryptography key to make the sensitive information available, the cryptography key being retrieved from the memory; executing, by the processor, the secure application or the portion of the secure application to generate a result using the cryptographically processed sensitive information; and in response to the request, outputting, via the processor, the result to the processing unit.
2. The method of claim 1, further comprising: loading, upon loading the secure application or the portion of the secure application, a first portion of the secure application, and executing, upon executing the secure application or the portion of the secure application to generate a result, the first portion of the secure application to generate a first intermediate result using the cryptographically processed sensitive information; wherein, prior to outputting the result to the processing unit: loading, through the first interface, a second portion of the secure application from the first external memory into the memory; and executing, by the processor, the second portion of the secure application to generate a second intermediate result using the cryptographically processed sensitive information or the first intermediate result; and upon outputting the result to the processing unit, outputting, by the processor, the first intermediate result or the second intermediate result.
3. The method of claim 2, further comprising: cryptographically processing, by the cryptography processing engine, alone or in combination with the processor, the sensitive information using the cryptography key or a second cryptography key, the second cryptography key being retrieved from the memory; writing the cryptographically processed sensitive information to the first external memory or the second external memory, overwriting the sensitive information in the first external memory or the second external memory; and removing the sensitive information from the memory.
4. The method of claim 2, further comprising: determining that the sensitive information is modified; cryptographically processing, by the cryptography processing engine, alone or in combination with the processor, the modified sensitive information using the cryptography key or a second cryptography key, the second cryptography key being retrieved from the memory; writing the modified sensitive information that is cryptographically processed to the first external memory or the second external memory, overwriting the sensitive information in the first external memory or the second external memory; and removing the modified sensitive information from the memory.
5. The method of claim 1, further comprising: determining that the sensitive information was not modified; and removing the sensitive information from the memory.
6. The method of claim 3 or claim 4, prior to executing the secure application, the portion of the secure application, the first portion of the secure application, or the second portion of the secure application, using the cryptographic key or a third cryptographic key by the cryptographic processing engine alone or in combination with the processor to cryptographically process the secure application, the portion of the secure application, the first portion of the secure application, or the second portion of the secure application, respectively, the third cryptographic key being retrieved from the memory.
7. The method of claim 6, in response to a second request requiring use of second sensitive information, further comprising: loading, by the first interface, a second secure application or a portion of the second secure application, the second secure application or the portion of the second secure application from the first external memory into the memory; loading, by the first interface or the second interface, second sensitive information from the first external memory or the second external memory into the memory; cryptographically processing, by the cryptographic processing engine alone or in combination with the processor, the second sensitive information using the cryptographic key or a fourth cryptographic key, the fourth cryptographic key being retrieved from the memory; executing, by the processor, the second secure application or the portion of the second secure application to generate a second result using the second sensitive information; and outputting, by the processor, the second result to the processing unit, the second result being effective to authenticate access to a resource external to the computer system, to authenticate access to an internal resource of the computer system, to facilitate a financial transaction, to perform a cryptographic function, or to perform a health monitoring function.
8. The method of claim 7, wherein, the cryptographic processing of the sensitive information, the second sensitive information, the secure application, the portion of the secure application, the first portion of the secure application, the second portion of the secure application, the second secure application, or the portion of the second secure application includes encrypting, authenticating, and verifying freshness of the sensitive information, the second sensitive information, the secure application, the portion of the secure application, the first portion of the secure application, the second portion of the secure application, the second secure application, or the portion of the second secure application, respectively.
9. The method of claim 7, further comprising: based on the result, the first intermediate result, the second intermediate result, or the second result output by the secure element, authenticating access to a resource external to the computer system, authenticating access to an internal resource of the computer system, facilitating a financial transaction, performing a cryptography function, or performing a health monitoring function.
10. The method of claim 1, wherein, The first interface is a low-latency interface for direct read and write operations by the secure element from the first external memory or the second external memory.
11. The method of claim 7, wherein, assigning, via the first interface, a direct byte-by-byte association to the secure element with the secure application, the portion of the secure application, the first portion of the secure application, the second portion of the secure application, the second secure application, the portion of the second secure application, the sensitive information, or the second sensitive information, the direct byte-by-byte association enabling the secure element to have memory-mapped access to data stored on the first external memory or the second external memory.
12. The method of claim 1, wherein, The first external memory and the second external memory are not attested to have a secure function.
13. The method of claim 1, wherein, The sensitive information includes one or more of network access credentials, cryptography keys, security keys, financial data, passcodes, user health data, and sensitive user data.
14. The method of claim 7, wherein, The memory of the secure element includes non-volatile random access memory.
15. The method of claim 14, wherein, The non-volatile random access memory includes magnetic random access memory or resistive random access memory.
16. The method of claim 14, wherein, The memory of the secure element includes random access memory and non-volatile memory, and wherein the method further comprises: loading, by the secure element, the secure application, the portion of the secure application, the first portion of the secure application, the second portion of the secure application, the second secure application, or the portion of the second secure application into the random access memory; loading, by the secure element, the sensitive information or the second sensitive information into the random access memory or the non-volatile memory; and loading, by the secure element, the cryptography key, the second cryptography key, the third cryptography key, or the fourth cryptography key into the non-volatile memory.
17. The method of claim 16, wherein, The non-volatile memory of the secure element includes read-only memory and flash memory, and wherein the secure element is configured to load the sensitive information or the second sensitive information into the flash memory or the random access memory, and to load the cryptography key, the second cryptography key, the third cryptography key, or the fourth cryptography key into the flash memory.
18. The method of claim 17, wherein, An operating system is stored in the memory, the non-volatile random access memory, the non-volatile memory, or the read-only memory, and wherein the processor is configured to execute the secure application, the portion of the secure application, the first portion of the secure application, the second portion of the secure application, the second secure application, or the portion of the second secure application using the operating system.
19. The method of any one of claims 1, wherein, The computer system comprises a smartphone, a wearable computer, a laptop computer, a server, a networked multimedia system, a voice assistant system, or a tablet computer.
20. A secure element for use in a computer system, the secure element comprising: a processor; a memory; and a cryptography processing engine, the secure element being configured to perform the method of any of claims 1-19.
21. A computing device comprising: a secure element according to claim 20; a processing unit linked to the secure element via a first interface; a first external memory, wherein a storage capacity of the first external memory is greater than a storage capacity of the memory, and the first external memory is linked to the secure element via the first interface or a second interface; and a second external memory, wherein a storage capacity of the second external memory is greater than a storage capacity of the memory, and the second external memory is linked to the secure element via the first interface or the second interface.
22. The computing device of claim 21, wherein, The second interface comprises a low-latency interface for direct read and write operations by the secure element from the first external memory, or an interface for enabling the secure element to perform memory-mapped access to sensitive information, a secure application, or a portion of the secure application stored in the first external memory.
23. The computing device of claim 21, wherein, The computing device is configured to authenticate access to resources external to the computing device, authenticate access to internal resources of the computing device, facilitate a financial transaction, perform a cryptography function, or perform a health monitoring function based on an output of the result of the secure element.
24. The computing device of any of claims 21-23, wherein, The computing device comprises a smartphone, a wearable computer, a laptop computer, a server, a networked multimedia system, a voice assistant system, or a tablet computer.
Citation Information
Patent Citations
Method and security module for providing a security function for a device
CN108369623A
System-on-chip and method for switching secure operating systems
WO2018119904A1