HYBRID SECURITY METHOD BASED ON ENCRYPTION AND SELECTIVE MATCHING FOR BLE TOKEN DEVICES WITH ESIM-BASED SECURE ELEMENTS.
Patent Information
- Application Number
- TR202612751
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-07-29
- Publication Date
- 2026-09-21
Abstract
Description
FOR ESIM-BASED SECURE ELEMENT INCLUDED BLE TOKEN DEVICE HYBRID BASED ON BUILT-IN ENCRYPTION AND SELECTIVE MATCHING. SECURITY METHOD Technical Area The invention is a portable device that enables wireless data communication. cryptographic token devices, secure electronic signatures, and authentication hardware, embedded software-based data protection mechanisms and Bluetooth Low Energy (BLE) It is concerned with layered security architectures in communication; More specifically, the invention is a secure element based on an internal eSIM. in a token-based device, communication data always active built-in AES-256 at the firmware level protected by an encryption layer and the need for this protection optional addition of BLE matching security hybrid secure data transmission method and related It relates to the system structure. State of the Art Today, corporate identity verification, electronic signatures, and portable token used in access control fields Devices are increasingly using Bluetooth for data transmission. It prefers the Low Energy (BLE) protocol. BLE means low energy consumption. low power consumption, broad platform compatibility, and easy integration. due to its capabilities, this type of device has a standard It has become a communication infrastructure. However, Current BLE-based security architectures have structural limitations. implementation inconsistencies and design in security management It has critical weaknesses due to its shortcomings. 1 Encryption and authentication mechanisms in the BLE protocol, Security Manager Protocol These mechanisms are defined within the framework of SMP and put into operation. its entry, largely due to the pairing procedure It depends on successful completion. BLE standard; Safety Within Mode 1, Level 1 includes (plaintext, encryption, and (no authentication) Level 4 (LE Secure Connections + Up to four different security levels (ECDH + AES-CCM). It defines this design as a mandatory system of encryption. Not a requirement, but optional and configuration-based. This means it is positioned as a natural characteristic; Therefore, the pairing procedure was not initiated at all, or If the process cannot be completed, data transmission is in plain text. It is possible. This structural choice has been extensively discussed in the technical literature. It has been documented. A BLE connection, a match It can be established even without any prior occurrence; in this case, any without encryption or security mechanisms being activated Communication is ongoing (US8467770B1; "BLE Pairing and Bonding Security Primer"). This vulnerability, as described, particularly token devices that perform security-critical operations This creates an unacceptable level of risk. Enabling encryption in existing BLE-based systems. The mandatory matching procedure is serious in itself. It poses security risks. BLE standard matching The "Just Works" method, which is among the methods, is Temporary. This sets the Key (TK) value to zero; encrypted connections established using this method this leaves them practically defenseless against attacks. It opens. It relies solely on six-digit PIN entry. The methods, however, theoretically only allow for one million combinations. 2 This requires testing against the connection. for an attacker who could listen in during the installation process It creates a realistic breaking point. A more comprehensive threat: Man in the Middle (MITM) In their attacks, the attacker places the blame between two legitimate devices. positioned as a reliable device on both sides It appears to be able to seize and alter all traffic. BLE standard matching procedure protects against this type of attack. protection only with specific authentication methods It can provide this; however, choosing the right method largely depends on device manufacturer's design preferences and user It is left to its own interaction. Within the current technology, a BLE can be established without pairing. The only way to ensure encrypted communication in the connection is to transmit the data It is protected at the application layer; however, current commercial BLE In token devices, this layer is always active, mandatory, and where there is no unbreakable encryption mechanism This is being observed. Patent application number US8646059B1 secure element (Secure Element — SE) is interpreted as being related to technology; cryptographic key generation and storage, sensitive data a well-established infrastructure in the areas of protection and transaction security It offers SE in compliance with GlobalPlatform standards. components; EAL4+ and higher safety certification, hardware tamper resistor and side channel superior security features such as protection against attacks It is thought to contain it. However, the current SE SE's cryptographic properties in BLE-based token systems its capacity is only for authentication or key It was limited to storage functions, coming from SE. 3 before the data is transmitted to the BLE link layer It is thought that it is not systematically encrypted at the layer. US12314959B2 and "Secure End-to-End Pairing of Secure In the patent application titled "Element to Mobile Device," SE and BLE encryption key between smart devices transmission and key status at a later stage The method of upgrading is described. However, in this patent... even when the BLE matching mechanism is disabled or not yet it intervenes when the communication is incomplete. an independent and mandatory practice that continues to provide protection The encryption layer is not mentioned. Therefore, the security of the system largely depends on matching. It depends on the successful completion of the procedure. In the areas of corporate identity authentication and access control. security requirements of organizations operating It is not homogeneous. Public institutions, financial institutions and private companies Sector businesses are subject to different regulations (e.g., PCI-DSS, ISO) This difference is subject to 27001, KVKK / GDPR compliance requirements. the need to change the security profile of the token device This brings with it. However, the existing BLE token security level in solutions during the design phase being fixed; different institutional or regulatory scenarios a policy-driven system that can be dynamically adapted to the situation. There is no double-layered security access control mechanism. SG11202104780XA numbered "Collaborative Risk Awareness The patent application on "Authentication" is risk-based. a selective authentication architecture is being implemented. This is understood. However, BLE is embedded in the communication layer. encryption combined with standard matching protocol. It is interpreted that the management of this is not addressed in this patent. 4 eSIM is a direct SIM card that does not require physical SIM card insertion. embedded SIM that can be integrated and remotely managed It is a technology. The eSIM component provides cryptographic identification. information and profile data securely It offers a superior platform for concealment. However, the eSIM's cryptographic engine is BLE. communication is integrated with the data bus, providing real-time and to always create an active encryption layer its use is not sufficiently addressed within the scope of current technology. It appears that it was not obtained. Patent number EP4525359A1. in the eSIM profile provisioning process in the application the security vulnerability created by the single existing encryption layer attention is being drawn to the need for multi-layered encryption. However, the application in question is an eSIM profile. It remains limited to management; eSIM-based SE is a BLE always active application layer in the token device not including its use in a way that would enable encryption It is being interpreted. Considering the technical vulnerabilities summarized above; the current BLE token systems, the BLE matching procedure operating regardless of whether it is completed or not, a non-disabled element located in the firmware architecture eSIM does not offer an application-layer encryption mechanism. SE's cryptographic capabilities, based on BLE, are always active. an approach that integrates data transmission security is available not included in the systems; and different corporate security policy that can dynamically adapt to their profiles guided dual-layer hybrid safety architecture technology as a known need that remains unresolved It is understood that he remained there. This gap; BLE communication in enterprise token devices. making eSIM security independent of matching status Integration of application layer encryption with SE-based encryption. and security layers are dynamic according to operational needs. the need for a new technical solution in management issues It clearly demonstrates this. Problems that the invention aims to solve. As is known, portable cryptographic token devices, mobile electronic signature, identity verification, transaction confirmation and common in use cases such as secure data access. They are used as such; however, these types of devices mobile phones, tablets and similar client devices in wireless communication, especially Bluetooth Low In BLE (Building Energy Least Energy) based connections, communication security is crucial. leaving it solely to standard protocol mechanisms This can lead to various technical and operational drawbacks. Security in BLE-based communication solutions with current technology. In most cases, standard pairing refers to connection. installation and link-level encryption mechanisms It relies on this approach. However, this approach largely depends on security. how the connection is established, what kind of pairing mode is used depending on which one is chosen, the client-side application discipline, and the final This can lead to it remaining dependent on user behavior; This situation necessitates electronic signatures requiring high security. finance, public, corporate access and similar uses This can create undesirable areas of vulnerability in these fields. Especially in mobile device ecosystems, the token device different operating systems, different application infrastructures and with organizations that have varying security policies 6 The need for this work, standard communication security is the only This reveals situations where it may not be sufficient on its own. In other words, only during connection setup. a security approach implemented between the device and the client every data packet between them, in every use case and the same minimum level of security under every set of policies It cannot guarantee its protection. One of the main problems encountered in this context is the device. cryptographic data exiting or entering the device its protection is a variable depending on the connection conditions. It is a matter of abandoning the security model. However, mobile e-signature, In applications such as identity verification and secure transaction approval, especially key management, signing commands, verification messages, session data and similar sensitive data elements at every stage of the communication path a predictable, mandatory and continuous layer of security It needs to be carried underneath. Another problem with current solutions is the safety element or Hardware-based key in devices containing a secure element Despite having protection, the safe switch inside the device continuous between the environment and the external communication line The inability to always achieve a unified security architecture is a significant issue. In other words, the keys are inside the secure element. Producing and storing it alone is not enough; data processing and data transmission logic associated with switches with a secure architecture at the firmware level It needs to be integrated. Furthermore, different institutional and application scenarios differ from each other. Having different security requirements, uniform and A fixed safety model is not always sufficient or efficient. 7 This leads to it not happening. In some use cases While built-in end-to-end data protection is considered sufficient, in some scenarios additional standard BLE matching security to be implemented as a security layer This may be necessary. Therefore, in the technical field, on the one hand... on the one hand, which makes basic security mandatory in all circumstances, and on the other hand... Additional communication security can be optionally enabled if needed. a flexible yet secure system that can be activated Architecture is needed. Another problem seen in current technology is safety. the level depends on user preference and the final device configuration. or due to incomplete integration on the application side It can fall. Especially for the end user, just the device itself. it opens, pairs, and initiates the process through the application In practical usage models, safety is the user's responsibility. Leaving it to fate is problematic. Therefore, the security layer is built into the device firmware, It is always active and cannot be disabled by the user. The need for it to be in a structured form arises. In addition, cryptographic systems using wireless communication. Low power consumption and small size in token devices. design features such as portability and multi-platform compatibility There are also requirements. The device in question has Android, With different platforms such as iOS, Windows, Linux and macOS It can work with different connections such as BLE 5.2 and USB. supporting these methods and yet security protection further enhances the technical problem that needs to be solved. It makes things complicated. 8 Within this framework, the primary aim of the invention is to provide secure internal eSIM-based technology. In a token device containing an element, Bluetooth Low Energy data transmitted via communication, standard firmware, regardless of communication security an always active AES-256 encryption layer at this level a method and system that ensures its protection to place. Another objective of the invention is to utilize the aforementioned embedded AES-256 the encryption layer, the device's normal operating architecture structured in such a way that it will be an integral part of it and thus all sensitive data coming from the device, connection the minimum safety threshold regardless of the conditions The goal is to ensure it is protected without falling below a certain level. Another purpose of the invention is to address corporate policy, regulation, Depending on the application scenario or risk profile, the word The subject is the standard BLE built upon the existing encryption architecture. as an optional overarching layer of match security to enable the addition of a single layer, thus making the device single-layered. Dual-layer hybrid security from built-in encryption mode. The aim is to allow dynamic switching between modes. Another purpose of the invention is to conduct within a secure element. Key generation and storage functions, and external communication. Data protection functionality in the channel is performed using the same security architecture. to combine under, thus secure element-based not leaving security only at the key storage level also continuously and necessarily at the data transmission level To spread. 9 Another purpose of the invention is mobile e-signature, digital contract. approval, banking transactions, public applications, corporate high security such as identity verification and field operations In areas requiring such applications, it is both energy efficient and... a flexibly implementable layered security approach The aim is to provide this. Thus, the portable nature of the device, low energy efficiency and multi-platform support are maintained, communication security depends on the application, user preference or dependence on the standard pairing mechanism alone is being reduced. Finally, the aim of the invention is to make security not just about the connection. Not just the installation itself, but the entire process of data processing and data transmission. maintained throughout; additional matching as needed. security can be activated, in contrast to the basic scalable, with the encryption layer remaining constantly active. and a highly secure token communication architecture to provide. Disclosure of the Invention The invention relates to mobile devices, portable computers, and the like. to perform secure data exchange with client systems a portable cryptographic token structured for It relates to the device. That device, specifically, is a mobile device. electronic signature, identity verification, secure transaction approval, such as document signing and corporate access verification. Designed for use in applications, Bluetooth Low Energy (BLE) based wireless communication and when needed Hardware that supports USB-based connectivity infrastructure and It includes embedded software architecture. The device that is the subject of the invention must consist of at least one body structure, a processor, or microcontroller unit, a Bluetooth Low Energy communication module, a power management unit, a user interface unit and an internal eSIM-based secure element It includes. As stated in the device's technical documentation. secure element, key generation and key storage an EAL4+ certified structure capable of performing its functions It is positioned as such, and the cryptographic security of the device It forms the basis. As part of an application related to the invention, the device is connected to a mobile client. Communication is via BLE 5.2 and the device is operated. via a physical button by the user The connection is being initiated. The device is in a state of readiness for connection. the indicator to the user, for example, with an LED display The token can then be reported via the client device. A communication session can be initiated by selecting the device. The preferred application of the invention is where safety is ensured only with BLE. matching or connection level offered by the standard not leaving it to protection mechanisms, instead the device each one running built-in within embedded software time active and cannot be disabled by the user a data protection layer is provided. In this context, the device, sensitive data transferred between the client device and the standard on or logically connected to the BLE communication stack AES-256 via an attached firmware security layer It encrypts based on a base system. According to one application related to the invention, every application that comes out of the device data, command data, verification message, signing request, session data or payload associated with a cryptographic transaction, A security check is performed before the BLE signal is transmitted to the communication layer. 11 It is directed to the control module. This safety control The module depends on the data type, session status, and active security. Regardless of its policy, the data in question should first be processed by the established company. It is subjected to AES-256 encryption and only then... then the encrypted data to the BLE communication stack It allows the transfer. In this way, the invention is structured within an AES-256 based framework. Data protection layer is an optional feature of communication. No, it's a necessary and integral part of the device architecture. It operates as such. In other words, the device is BLE. As long as communication is active, anything coming from or going to the device Data entering the protection scope is encrypted using this built-in encryption. It cannot be processed without passing through the layer or It cannot be delivered. In one application, the AES-256 encryption process The key material used is a direct safety element. produced, derived, stored or within is managed. Thus, the keys are in plain text format. This prevents it from being removed from the device and ensures safety. an integrated system between the element and data transmission security A chain of security is being established. Some applications related to the invention. including AES keys, session-based derived keys it is possible; however, in some other forms of implementation, it takes a long time. Timed switches, sub-switches derived from master switches. keys or renewed subject to specific policy conditions Key structures can be used. In another application of the invention, the device is only A basic security system that operates with a built-in AES-256 layer. It can be operated in this mode. In this mode, the device and the client interact. Data traffic between devices is via BLE connection. 12 Although transmitted, the protection of the data payload is primarily This is provided via the AES-256 layer at the firmware level. Thus, standard BLE matching security is not effective, restricted or required by specific implementation policies Data security is protected even when not in use. It is possible. According to another application of the invention, the device can be selectively operated. An additional BLE matching security can be enabled. It also supports the layer. In this context, the standard BLE 5.2 matching procedures, e.g., pairing, bonding, keying exchange, connection verification or related security processes, built on top of the AES-256 layer It can be implemented as a second layer of security. Enabling this second layer provides security. policy, corporate configuration, client application profile, regulation rule, use case or prior It can be determined according to a defined device profile. A relevant security policy profile in the form of an application. It is managed on a base basis and policy information is the first link. during installation to the device or client side This is implemented. Thus, the device uses the same hardware infrastructure. on, different institutions or different applications in different security modes according to security requirements It can be operated. In another application of the invention, the device, first in security mode only with built-in AES-256 protection. is working; in the second security scenario, both the built-in AES- 256 layers of encryption as well as standard BLE matching. It uses a security mechanism based on this principle in conjunction with other mechanisms. In this case, the payload is initially AES-256 at the firmware level. 13 protected by, then the BLE connection's own security passing through a second layer of protection via the process is transmitted. Thus, the invention provides single-layer security. It is possible to switch from this mode to a dual-layer hybrid safety mode. It makes it possible. According to one application of the invention, the transition in question is a connection. before installation or during the initial connection process determined by the chosen policy and active session It is protected throughout the session. Thus, the security mode session This prevents unforeseen changes in the middle of the process. Security checks are being simplified and session integrity is being improved. It can be protected. Another application of the invention involves a device inside the device. security controller or security status manager This structure indicates the device's current connection status. key status, pairing status, active security It monitors your profile and data processing permissions. For example, in an initial state, the device might be "unpaired but..." AES protection may be in the "active" state; pairing if a profile requiring this is implemented, the device It can switch to the "paired and AES protection active" state; unauthorized access attempt, key authentication error, or If a policy violation is detected, data transmission will be stopped. may be restricted, connection may be terminated or Certain protective actions can be triggered in the security aspect. Another application of the invention involves the device and the client. messaging at the application level between them, custom commands packets, validation data blocks, signing requests, response data, certificate-related data, or session It is structured in the form of management data. This 14 Each of the messages is independent of the BLE transport architecture. first, it is processed in the invention-specific built-in security layer, It is encrypted and preferably with integrity verification data. They are packaged together. In some applications, the secure element is only the key. It not only serves a storage purpose, but also has cryptographic properties. some or all of the transactions are executed It can also function as a secure operating environment. Data encryption is also included in some other applications. At least part of the operation is performed by the main processor or microcontroller. is being carried out by, but the key material and key Access control is managed by the security element. This Therefore, the invention explores which physical AES-256 encryption method It is not reduced to being executed in the processing unit; essentially Secure element supported, always active at the firmware level. It encompasses a data protection logic. The invention, in the form of an application, can be used on devices such as Android, iOS, and Windows. Compatible with Linux and macOS platforms. It is designed in this way. This multi-platform compatibility allows for different secure data exchange in client ecosystems while enabling its realization, the invention's built-in encryption thanks to the layer, the security logic on the client side minimally affected by operating system differences that is intended. In another application form, the device is used for mobile e-signature transactions. e-government applications, banking transactions, corporate approvals processes, field operations and mobile identity verification, etc. It is used in various scenarios. These areas of use are common. The need is to protect the secure keys inside the device. up to, the commands and data associated with these keys the exchange is also protected throughout the communication process; This invention addresses this need with a layered and policy-controlled security system. It meets [the need for] architecture. According to one of the applications of the invention; security Depending on its policy, only certain data types are available. Additional matching may be required for the basic AES-256 This layer is mandatory for all data types. Others all for specific corporate profiles within the applications Sessions may be initiated in hybrid mode. Thus, the system strikes a balance between flexibility and security. It establishes a constructible balance. According to one of the applications for the invention, the device's software... updating, renewing policy sets, certification or key lifecycle management and troubleshooting secondary processes such as addressing their situations It can be implemented in a way that includes, for example, security. in subsequent connection sessions when the policy is updated A new security profile can be applied; a key renewal is required. a new key within the secure element when the condition is met derivation can be performed; failed validation or The system enters protected mode in case of a suspicious connection attempt. receivable. Thanks to the design described in the invention, standard BLE safety regardless of whether the mechanisms are effective or not, Minimum encryption for sensitive data leaving the device. The protection of this property is always ensured. In addition, a second standard BLE matching security when needed Thanks to the ability to add them as layers, the same device can be used differently. institutional or regulatory with security regimes It becomes usable in various environments. 16 Therefore, the invention is not merely a cryptographic algorithm. not the usage; internal security feature, firmware Mandatory data encryption at the level of optional standard BLE. Matching security, profile-based policy management, and Controlled switching between single / double layer security modes. revealing an integrated method and system architecture that provides It places. 17
Claims
1. Bluetooth Low Energy (BLE) interface and eSIM form factor. a token containing a Secure Element (SE) embedded in the rune is a data transmission method on the device, a) Secure Element, based on eSIM, uses AES-256 encryption. the generation of the reset key and the said key The Secure Element outputs plain text outside its boundaries. storage without being removed; b) Whether the BLE 5.2 pairing procedure is effective regardless of whether it is present or not, via the BLE interface All application data to be transmitted is generated in step (a). with the tiled AES-256 switch continuously and necessarily encryption; c) adoption of the security policy parameter; d) depending on the security policy parameter adopted, (b) additional to the built-in AES-256 encryption layer in step (b) as an optional BLE 5.2 standard matching protocol enabling it in this way; so that the device is single-layered Dual-layer hybrid security with AES-256 (only) Enabling dynamic switching between modes are the process steps. It is characterized by its presence.
2. The method is according to claim 1, and the AES-256 encryption key- their re-creation within Secure Element for each session derived and the derived key is the previous session key- making them cryptographically independent from their counterparts It is characterized by having a step in the process.
3. The method is as per claim 1, and it was implemented in step (b). The AES-256 encryption process provided uses the BLE stack (BLE In the application layer (stack), the BLE link layer encrypts the encryption. the process step before the processing mechanisms It is characterized by its presence. 18 4. The method is according to claim 1, and the encryption process is Secure. In the hardware cryptographic engine within the element (hardware cryptographic engine) implementation work- It is characterized by having a step in the process.
5. According to Claim 1, the method is characterized by its security policy. muscle parameter; corporate identity information, regulations- profile identifier and operational risk level pa- It must include at least one of the parameters.
6. According to Claim 1, the method is characterized by its security policy. muscle parameter; mo- paired with token device the application, the corporate management server and the device- from at least one of the configuration profiles stored in It is characterized by having the acquisition process step. is being done.
7. The method according to claim 1, and its feature is; security mode the transition from single-layer to double-layer hybrid fashion, This was accomplished without interrupting the existing active BLE connection. It is characterized by having the process step that allows it to be delivered. is being done.
8. The method according to claim 1, and its characteristic is; the device; (i) yal- the first security system where only AES-256 encryption is enabled in this case, (ii) AES-256 encryption and BLE matching protocol- in the second security situation where both sides are effective and (iii) verification failure or policy violation In this case, the third security measure terminates the connection. Its operation is characterized by having a process step. It is being done in Rize.
9. The method is according to claim 1, and its feature is; selected in step (d). the BLE matching protocol, which is enabled as required; Just Works, Passkey Entry, Numeric Comparison and Out- The process name must include at least one of the off-band methods. It is characterized by having a mini. 19 10. The method according to claim 1 is characterized by being double-layered. In hybrid security mode, application data is first processed using AES- It was encrypted with 256 layers and then BLE matching protocol- subject to link layer encryption provided by the tokol It is characterized by having a holding process step. is being done.
11. The method is according to Claim 1, and its characteristic is; AES-256 encryption. a specific time interval of the reset switch, connection number threshold or security policy change The process name is to refresh at least one of the ticks. It is characterized by having a mini.
12. The method is according to claim 1, and its feature is; firmware update- During the encryption process, the AES-256 encryption layer was interrupted. as you continue to remain active and update bureau- The process of verifying the integrity by Secure Element. It is characterized by having a step.
13. Bluetooth Low Energy (BLE) interface and eSIM form factor. a token that contains a Secure Element (SE) embedded in its structure It is a device, and its features are: — BLE 5.2 radio frequency interface, — The AES-256 encryption key is transmitted to the device in plain text. made to produce and store without extracting it. The Secure Element, embedded in the eSIM form factor, has been removed. — whether the BLE matching procedure is effective or not performed independently via the BLE interface All data transmission is secured by AES-256 within the Secure Element system. to encrypt continuously and necessarily with the key structured firmware-based encryption manager, And — depending on the security policy parameter, location- In addition to the integrated AES-256 encryption layer, BLE 5.2 also supports the same layer. by selectively enabling the unification protocol, single between layered and dual-layer hybrid security mode security controller (secu-) that manages dynamic transition It has a city controller.
14. It is a token device according to claim 13, and its characteristic is; security controller, firmware-based security it includes a security state machine and BLE matching status, with security policy parameter. Security depends on the result of cryptographic verification. It has a state machine that manages the mode.
15. It is a token device according to claim 13, and its characteristic is; stores security policy parameters and security this policy manager module that transmits information to its controller It is the act of keeping it.
16. It is a token device according to claim 13, and its characteristic is; Never disable the AES-256 layer under any circumstances. including a hardware lock mechanism It has a security controller. 21