Enabling presentation of credentials
The auxiliary device with a bistable display and secure elements addresses the cumbersome and security-risk-prone nature of using smartphones for credential presentation by enabling secure and efficient credential display.
Patent Information
- Application Number
- PCT/SE2023/051101
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-01
- Publication Date
- 2025-05-08
AI Technical Summary
Current smartphones are cumbersome for presenting credentials and pose security risks when handed over unlocked to third parties.
An auxiliary device with a bistable display, a second secure element, and a user input device is used to receive credential data from a host device, allowing for secure and convenient presentation of credentials.
The auxiliary device enables efficient and secure presentation of credentials, reducing the need to handle large smartphones and minimizing security risks by allowing credentials to be presented independently of the host device.
Smart Images

Figure SE2023051101_08052025_PF_FP_ABST
Abstract
Description
ENABLING PRESENTATION OF CREDENTIALSTECHNICAL FIELD
[0001] The present disclosure relates to the field of credentials and in particular to enabling presentation of credentials, using an auxiliary device comprising a bistable display, a second secure element and a user input device.BACKGROUND
[0002] Current smartphones are devices that provide a great number of capabilities, such as touchscreen, camera, microphone, speakers, LED (light-emitting diode) torch, all provided within the same form factor. Also, smartphones provide access to the internet and a plethora of applications (also known as apps). In the last few years, smartphones also serve to hold an electronic wallet for presenting credentials such as payment cards, loyalty cards, vaccination records, identification, etc.
[0003] While it may be convenient to have all cards in the smartphone, it can be cumbersome to use the relatively large smartphone for presenting credentials.Furthermore, from a security standpoint it might be a security risk to hand off an unlocked device to a third party for identification or payment.
[0004] It is known to use a smartwatch, paired with a smartphone, as an additional device for providing credentials from the smartphone. However, such a smartwatch is its own complex device that needs to be charged and managed separately.
[0005] US 2020 / 0387888 Ai discloses an apparatus, system, and method for operating a digital transaction. It is disclosed a digital transaction card that comprises card buttons and a display. However, the resulting solution is awkward since the digital transaction card needs to be separately managed.SUMMARY
[0006] One object is to improve handling of credentials from a usability perspective.
[0007] In some aspects, the embodiments described herein relate to a method for enabling presentation of credentials. The method is performed by an auxiliary deviceconfigured to communicate with a host device comprising a first secure element. The auxiliary device comprises a bistable display, a second secure element and a user input device. The method comprises: receiving credential data for a plurality of credentials from the host device over an interface for communicating between the first secure element of the host device and the second secure element, wherein the interface is implemented over a physical connection between the host device and the auxiliary device; storing the credential data in the second secure element; releasing a mechanical connection with the host device based on user manipulation to release the auxiliary device from the host device; receiving user input via the at least one user input device to select one of the plurality of credentials; and presenting a representation of the selected one of the plurality of credentials, based on the credential data, on the bistable display.
[0008] In some aspects, the embodiments described herein relate to the auxiliary device further comprising an input / output, I / O, interface for near-field communication, wherein the method further comprises: communicating with a reader using the I / O interface, for the reader to validate at least part of the credential data.
[0009] In some aspects, the embodiments described herein relate to the method further comprising: receiving, for each one of the at least one credential data, an application comprising executable code; and storing the application for each one of the at least one credential data in the second secure element.
[0010] In some aspects, the embodiments described herein relate to the method further comprising: receiving energy from an external device, being the host device or a reader device.
[0011] In some aspects, the embodiments described herein relate to an auxiliary device for enabling presentation of credentials, the auxiliary device being configured to communicate with a host device comprising a first secure element. The auxiliary device comprises: a bistable display; a second secure element: a user input device; processing circuitry; and memory circuitry storing instructions that, when executed by the processing circuitry, cause the auxiliary device to: receive credential data for a plurality of credentials from the host device over an interface for communicating between the first secure element of the host device and the second secure element, wherein theinterface is implemented over a physical connection between the host device and the auxiliary device; store the credential data in the second secure element; release a mechanical connection with the host device based on user manipulation to release the auxiliary device from the host device; receive user input via the at least one user input device to select one of the plurality of credentials; and present a representation of the selected one of the plurality of credentials, based on the credential data, on the bistable display.
[0012] In some aspects, the embodiments described herein relate to the auxiliary device further comprising an input / output, I / O, interface for near-field communication, and instructions that, when executed by the processing circuitry, cause the co-auxiliary device to: communicate with a reader using the I / O interface, for the reader to validate at least part of the credential data.
[0013] In some aspects, the embodiments described herein relate to the auxiliary device further comprising instructions that, when executed by the processing circuitry, cause the co-auxiliary device to: receive, for each one of the at least one credential data, an application comprising executable code; and store the application for each one of the at least one credential data in the second secure element.
[0014] In some aspects, the embodiments described herein relate to the auxiliary device further comprising instructions that, when executed by the processing circuitry, cause the co-auxiliary device to: receive energy from an external device, being the host device or a reader device.
[0015] In some aspects, the embodiments described herein relate to a computer program for enabling presentation of credentials, using an auxiliary device configured to communicate with a host device comprising a first secure element, the auxiliary device comprising a bistable display, a second secure element and a user input device. The computer program comprises computer program code which, when executed on the auxiliary device causes the auxiliary device to: receive credential data for a plurality of credentials from the host device over an interface for communicating between the first secure element of the host device and the second secure element, wherein the interface is implemented over a physical connection between the host device and the auxiliarydevice; store the credential data in the second secure element; release a mechanical connection with the host device based on user manipulation to release the auxiliary device from the host device; receive user input via the at least one user input device to select one of the plurality of credentials; and present a representation of the selected one of the plurality of credentials, based on the credential data, on the bistable display.
[0016] In some aspects, the embodiments described herein relate to a computer program product comprising the computer program and a computer readable means comprising non-transitory memory in which the computer program is stored.
[0017] In some aspects, the embodiments described herein relate to a method for enabling presentation of credentials, the method being performed by a host device comprising a first secure element, the host device being configured to communicate with an auxiliary device comprising an bistable display and a second secure element. The method comprises: transmitting credential data, stored in the first secure element, for a plurality of credentials to the auxiliary device for presentation on a bistable display of the auxiliary device over an interface for communicating between the first secure element and the second secure element of the auxiliary device, wherein the interface is implemented over a physical connection between the host device and the auxiliary device; and releasing a mechanical connection with the auxiliary device based on user manipulation to release the auxiliary device from the host device.
[0018] In some aspects, the embodiments described herein relate to the method further comprising: transmitting, for each one of the at least one credential data, an application comprising executable code.
[0019] In some aspects, the embodiments described herein relate to the method further comprising: providing energy to the auxiliary device.
[0020] In some aspects, the embodiments described herein relate to the method further comprising: deactivating, in the host device, the credentials corresponding to the credential data transmitted to the auxiliary device.
[0021] In some aspects, the embodiments described herein relate to a host device for enabling presentation of credentials. The host device comprises: a first secure element,the host device being configured to communicate with an auxiliary device comprising an bistable display and a second secure element; processing circuitry; and memory circuitry storing instructions that, when executed by the processing circuitry, cause the host device to: transmit credential data, stored in the first secure element, for a plurality of credentials to the auxiliary device for presentation on a bistable display of the auxiliary device over an interface for communicating between the first secure element and the second secure element of the auxiliary device, wherein the interface is implemented over a physical connection between the host device and the auxiliary device; and release a mechanical connection with the auxiliary device based on user manipulation to release the auxiliary device from the host device.
[0022] In some aspects, the embodiments described herein relate to the host device further comprising instructions that, when executed by the processing circuitry, cause the host device to: transmit, for each one of the at least one credential data, an application comprising executable code.
[0023] In some aspects, the embodiments described herein relate to the host device further comprising instructions that, when executed by the processing circuitry, cause the host device to: provide energy to the auxiliary device.
[0024] In some aspects, the embodiments described herein relate to the host device further comprising instructions that, when executed by the processing circuitry, cause the host device to: deactivate, in the host device, the credentials corresponding to the credential data transmitted to the auxiliary device.
[0025] In some aspects, the embodiments described herein relate to a computer program for enabling presentation of credentials. The computer program comprises computer program code which, when executed on a host device comprising a first secure element, the host device being configured to communicate with an auxiliary device comprising an bistable display and a second secure element, causes the host device to: transmit credential data, stored in the first secure element, for a plurality of credentials to the auxiliary device for presentation on a bistable display of the auxiliary device over an interface for communicating between the first secure element and the second secure element of the auxiliary device, wherein the interface is implemented over a physicalconnection between the host device and the auxiliary device; and release a mechanical connection with the auxiliary device based on user manipulation to release the auxiliary device from the host device.
[0026] In some aspects, the embodiments described herein relate to a computer program product comprising the computer program and a computer readable means comprising non-transitory memory in which the computer program is stored.
[0027] In some aspects, the embodiments described herein relate to a system comprising an auxiliary device and a host device, for enabling presentation of credentials, the auxiliary device and the host device being configured to communicate with each other. The auxiliary device comprises: a bistable display; a second secure element: a user input device; processing circuitry; and memory circuitry storing instructions that, when executed by the processing circuitry, cause the auxiliary device to: receive credential data for a plurality of credentials from the host device over an interface for communicating between a first secure element of the host device and the second secure element, wherein the interface is implemented over a physical connection between the host device and the auxiliary device; store the credential data in the second secure element; release a mechanical connection with the host device based on user manipulation to release the auxiliary device from the host device; receive user input via the at least one user input device to select one of the plurality of credentials; and present a representation of the selected one of the plurality of credentials, based on the credential data, on the bistable display. The host device comprises: the first secure element; processing circuitry; and memory circuitry storing instructions that, when executed by the processing circuitry, cause the host device to: transmit the credential data, stored in the first secure element, for the plurality of credentials to the auxiliary device for presentation on the bistable display of the auxiliary device over the interface for communicating between the first secure element and the second secure element of the auxiliary device, wherein the interface is implemented over the physical connection between the host device and the auxiliary device; and release the mechanical connection with the auxiliary device based on user manipulation to release the auxiliary device from the host device.
[0028] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, step, etc." are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Aspects and embodiments are now described, by way of example, with reference to the accompanying drawings, in which:
[0030] Fig 1 is a schematic diagram illustrating an environment in which embodiments presented herein can be applied;
[0031] Fig 2 is a schematic diagram illustrating components of the host device and the auxiliary device of Fig 1;
[0032] Fig 3 is a schematic side view illustrating how the auxiliary device of Fig 1 can be mechanically coupled with the host device of Fig 1;
[0033] Figs 4A-B are swimlane diagrams illustrating embodiments of methods for enabling presentation of credentials;
[0034] Fig 5 is a schematic diagram showing functional modules of the auxiliary device of Fig 1 according to one embodiment;
[0035] Fig 6 is a schematic diagram showing functional modules of the host device of Fig 1 according to one embodiment; and
[0036] Fig 7 shows one example of a computer program product comprising computer readable means.DETAILED DESCRIPTION
[0037] The aspects of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the invention are shown. These aspects may, however, be embodied in many different forms and should not be construed as limiting; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and to fully convey the scope of all aspects of invention to those skilled in the art. Like numbers refer to like elements throughout the description.
[0038] According to embodiments presented herein, it is provided an auxiliary device that is coupled to a host device (e.g. smartphone). The auxiliary device comprises a bistable display for presentation of a credential. Using a physical connection between the host device and the auxiliary device, credential data for multiple credentials are transferred from a secure element of the host device to a secure element of the auxiliary device. Once the credentials have been transferred to the auxiliary device, the auxiliary device is released from the host device and a credential can be presented on a bistable display of the auxiliary device, instead of presenting the credential using e.g. a wallet application on the host device. The user can select which one of a plurality of credentials to present. The selected credential is then presented on the bistable display of the auxiliary device. In this way, a very convenient and power efficient way is provided to present a credential for the user. More details on this solution are provided below.
[0039] Fig 1 is a schematic diagram illustrating an environment in which embodiments presented herein can be applied. A user 4 has access to both a host device 1 and an auxiliary device 2.
[0040] The host device 1 can e.g. be in the form of a smartphone, tablet computer, or XR (extended reality) glasses. The auxiliary device 2 comprises a bistable display, e.g. an electronic paper display, a memory in pixel TFT (thin-film transistor) display, or an oxide-TFT display, that can retain a particular rendering on the display with no, or negligible, power consumption, as described in more detail below.
[0041] Credentials stored in a first secure element in the host device 1 are transferred securely to a second secure element in the auxiliary device 2. The credentialscan e.g. be in the form of a form of identification, a form of payment (e.g. connected to the global credit / debit card infrastructure e.g. for VISA, MasterCard, American Express, etc.), and / or loyalty cards. In this way, when the user 4 wants to present a credential to a reader device 6 or to a credential verifier 5, e.g. for payment, identification or loyalty club membership, the user 4 simply presents the auxiliary device 2. In this context, the credential verifier 5 is a person. Since the auxiliary device 2 is used to present the credentials, the host device 1 can remain securely stowed in a pocket or bag of the user 4-
[0042] When the credential is presented optically to the credential verifier 5 using the bistable display of the auxiliary device 2, the credential verifier can examine the bistable display of the auxiliary device 2 to determine its validity. When the credential is presented to the reader device 6, the reader device 6 can read the credential optically from the display of the auxiliary device 2, e.g. using a QR (quick-response) code or other machine-readable optical code. Alternatively or additionally, the reader device 6 reads the credential from the auxiliary device 2 over near-field communication (NFC) or another suitable wireless communication technology. Credential presentation may involve presentation of data generated by the auxiliary device 2, e.g. by the secure element of the auxiliary device 2, where the presented data is generated based on data received from the reader device 6 and credential data stored in the secure element of the auxiliary device 2.
[0043] Fig 2 is a schematic diagram illustrating components of the host device 1 and the auxiliary device 2 of Fig 1.
[0044] Looking first to the host device 1, this can e.g. be in the form of a smartphone or tablet computer. The host device 1 comprises processing circuitry 160 that is provided using any combination of one or more of a suitable central processing unit (CPU), graphics processing unit (GPU), multiprocessor, neural processing unit (NPU), microcontroller, digital signal processor (DSP), etc., capable of executing software instructions 167 stored in memory circuitry 168, which can thus be a computer program product. The processing circuitry 160 could alternatively or additionally be implemented using an application specific integrated circuit (ASIC), field programmablegate array (FPGA), etc. The processing circuitry 160 can be configured to execute the method steps of the host device 1 described with reference to Fig 4A-B below.
[0045] The memory circuitry 168 can be any combination of random-access memory (RAM) and / or read-only memory (ROM). The memory circuitry 168 also comprises non-transitory persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid-state memory or even remotely mounted memory.
[0046] A first secure element 166 is also provided for secure storage of sensitive data, such as credentials. It is to be noted that the first secure element 166 is provided in a way that its memory or processing capability is inaccessible for applications that are external to the first secure element 166, executing in the host device 1. For instance, the first secure element 166 can be provided in a separate chip from other components of the host device 1. The first secure element 166 can be provided in compliance with the security IC (integrated circuit) Platform Protection Profile PP 0084, under common criteria (ISO / IEC (International Organization for Standardization / International Electrotechnical Commission) 15408). The first secure element 166 can optionally store and execute applications within its secure environment. For instance, such applications can be used, when transferred to the auxiliary device 2, to present a credential coupled to, or included in, the application. The first secure element 166 can be used to keep credentials whose presentation is controlled by an electronic wallet application, e.g.Google Wallet, Apple Wallet, Samsung Pay, Alipay etc. on the host device 1.
[0047] The host device 1 further comprises an I / O interface 162 for communicating with external and / or internal entities. The I / O interface 162 includes a physical interface for providing a physical connection between the host device 1 and the auxiliary device 2. The physical interface can e.g. be used when the auxiliary device 2 is mechanically connected with the host device 1 and can include a galvanic connection, i.e. an unbroken conductive connection, to the auxiliary device 2. The I / O interface 162 optionally includes an NFC interface for communicating with the auxiliary device 2. The I / O interface 162 optionally includes a power interface for transferring power from the host device 1 to the auxiliary device 2. The power interface can be a conductive power interface or an inductive power interface.
[0048] A power module 161 provides electric power for the host device 1 to be able to function. The power module 161 can e.g. comprise a rechargeable battery, power management integrated circuit (PMIC). The host device 1 can comprise a display 163, e.g. in the form of a touchscreen, an LCD (liquid crystal display), an OLED (organic light emitting diode) display and / or microLED display or other suitable display technology for smart devices.
[0049] Other components of the host device 1 are omitted in order not to obscure the concepts presented herein.
[0050] Looking now to the auxiliary device 2, this can e.g. be provided in a card-like form factor that is attachable or insertable in the host device 1, as illustrated in Fig 3 and described below. The auxiliary device 2 comprises processing circuitry 60 that may be limited in power consumption and thus also in processing capability since it only needs to perform a small number of tasks, such as credential switching based on user input and optionally communicating with a reader device. The processing circuitry 60 can be provided using any combination of one or more of a suitable central processing unit (CPU), graphics processing unit (GPU), multiprocessor, neural processing unit (NPU), microcontroller, digital signal processor (DSP), etc., capable of executing software instructions 67 stored in memory circuitry 68, which can thus be a computer program product. The processing circuitry 60 could alternatively or additionally be implemented using an application specific integrated circuit (ASIC), field programmable gate array (FPGA), etc. The processing circuitry 60 can be configured to execute the method steps of the auxiliary device 2 described with reference to Fig 4A-B below.
[0051] The memory circuitry 68 can be any combination of random-access memory (RAM) and / or read-only memory (ROM). The memory circuitry 68 also comprises non- transitory persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, or solid-state memory.
[0052] A second secure element 66 is also provided for secure storage of sensitive data, such as credentials in the auxiliary device 2. It is to be noted that the second secure element 66 is provided in a way that its memory or processing capability is inaccessible for applications, external to the second secure element 66, executing in the auxiliarydevice 2. For instance, the second secure element 66 can be provided in a separate chip from other components of the auxiliary device 2. The second secure element 66 can be provided in compliance with the security IC Platform Protection Profile PP 0084, under common criteria (ISO / IEC 15408). The second secure element 66 can optionally store and execute applications within its secure environment. For instance, such applications can be used to present a credential coupled to, or included in, the application.
[0053] The auxiliary device 2 further comprises an 1 / O interface 62 for communicating with external and / or internal entities. For instance, the I / O interface 62 optionally includes an NFC interface for communicating with a reader device 6, and optionally the host device 1. The I / O interface 62 also includes a physical interface for providing a physical connection between the host device 1 and the auxiliary device 2. The physical connection comprises a conductive, i.e. galvanic, connection between the host device 1 and the auxiliary device 2. The physical interface can e.g. be used when the auxiliary device 2 is mechanically connected with the host device 1. When the auxiliary device 2 and the host device 1 are mechanically connected, the auxiliary device 2 is physically attached to the host device 1, allowing convenient and easy handling of the auxiliary device 2 as one package. The I / O interface 62 optionally includes a power interface for the auxiliary device 2 receiving power from the host device 1. The power interface can be a conductive power interface or an inductive power interface.
[0054] The auxiliary device 2 comprises a bistable display 63, e.g. an electronic paper display, that can retain a particular rendering on the display with no or negligible power consumption. The bistable display 63 can e.g. be implemented using tiny microcapsules filled with charged particles that move when an electrical charge is applied. These microcapsules are suspended in a liquid and sandwiched between two layers of transparent electrodes. When a voltage is applied to the electrodes, the particles move to the top or bottom of the capsule, making the area appear either black or white. This creates a visual image on the screen. It is to be noted that the bistable display can optionally be provided in colour, based on microcapsules in different colours. The bistable display 63 could alternatively be provided using other bistable display technologies such as memory in pixel liquid crystal display (LCD), Electrowetting technologies.
[0055] Optionally, the display is manufactured on a plastic substrate, to achieve increased toughness. It is possible to use other substrates as long as one think of the robustness of the design.
[0056] Bistable displays are very energy efficient, since power is mainly consumed when the display rendering is changed, rather than maintaining a particular rendering on the display. Moreover, due to the passive rendering elements, the bistable displays are excellent for outdoor readability and high contrast.
[0057] A user interface element 69 is provided for allowing the user 4 to interact with the auxiliary device 2. The user interface element 69 can e.g. comprise one or more push buttons, jog dials, or any other user interface element that allows the user 4 to provide user input to the auxiliary device 2. As described in more detail below, user input captured by the user interface element 69 can e.g. be used by the user 4 to select which one of multiple credentials that is to be presented by the auxiliary device 2. In one embodiment, there is a separate button for some or all of the credentials that can be stored in the auxiliary device 2, allowing the user to change to the appropriate application with a single push of button. In this case, there is optionally a small icon provided on the bistable display 63, displaying the credential that corresponds to each button. The button could be positioned under the display or next to the display. In one embodiment, the auxiliary device 2 comprises a fingerprint sensor for an additional factor of authentication, as a separate device or in the form of a capacitive touch area. In this case, the fingerprint sensor needs to perform a positive match of a presented finger, against one or more stored fingerprint templates, prior to the auxiliary device 2 being able to present a credential.
[0058] A power module 61 provides electric power for the auxiliary device 2 to be able to e.g. switch credentials on the bistable display 63. The power module 61 can e.g. be provided using a power management integrated circuit (PMIC) and a power source. The PMIC supplies the different voltages needed to run the secure element and update the bistable display 63. The power source in the power module 61 could be a battery (e.g. a thin film battery), capacitor, super capacitor, or other means of store energy and release it a given point in time. There is sufficient energy in the power source to be able to change the information of the bistable display 63 at least once. The power source inthe power module 61 can be charged e.g. through NFC (from the host device i, the reader device 6 or any other NFC interrogator), through a conductive connection (from the host device 1 or any other energy source) or from one or more solar cells of the auxiliary device 2.
[0059] Other components of the auxiliary device 2 are omitted in order not to obscure the concepts presented herein.
[0060] There are (at least) two communication interfaces 10, 11 between the host device 1 and the auxiliary device 2.
[0061] A first interface 10 is for communication between the first secure element 166 of the host device 1 and the second secure element 66 of the auxiliary device 2. This can e.g. be implemented in compliance ISO / IEC 7816, SPI (serial peripheral interface) and / or I2C (inter-integrated circuit). Communication over the first interface 10 can be end-to-end encrypted between the first secure element 166 and the second secure element 66, as described in more detail below, to prevent any sensitive credential data to be exposed during the communication between the secure elements 66, 166.
[0062] A second interface 11 is used for communication between the host device 1 and the auxiliary device 2 that does not involve the secure elements 66, 166. For instance, the second interface 11 could be used by the host device 1 to control the output on the display. The second interface 11 could e.g. be provided using SPI, I2C and / or using a proprietary low speed power interface.
[0063] One or both of the interfaces 10, 11 can also provide energy needed to interact with the auxiliary device 2. The energy is optionally provided over a separate conductive physical interface (not shown) or wireless interface. For instance, energy could be provided from the host device 1 to the auxiliary device 2 over an NFC interface or another inductive interface.
[0064] Together, the host device 1 and the auxiliary device 2 make up a system 3. In other word, the system 3 comprises the host device 1 and the auxiliary device 2.
[0065] Fig 3 is a schematic side view illustrating how the auxiliary device 2 of Fig 1 can be mechanically coupled with the host device 1 of Fig 1.
[0066] The host device 1 comprises one or more mechanical connectors 7 for fastening the auxiliary device 2 to the host device 1. The mechanical connectors 7 are any suitable type of connector that can releasably secure the auxiliary device 2 to the host device 1. For instance, the mechanical connectors 7 can be based on any one or more of a spring, a snap fastener, a magnet, etc. When the auxiliary device 2 is fastened to the host device 1, a physical connection 8 (schematically shown in Fig 3 as a physical connection between respective connectors of the auxiliary device 2 and the host device 1). The physical connection 8 can e.g. be in the form of a pogo pin and / or a spring, and the physical connection 8 is provided between the host device 1 and the auxiliary device 2 for transferring data. The physical connection 8 can provide at least two separate conductive paths between the host device 1 and the auxiliary device 2.
[0067] The auxiliary device 2 can be provided in a recess of the host device 1, to create a package (containing both the host device 1 and the auxiliary device 2) that is convenient to handle. Alternatively, the auxiliary device 2 is insertable in a slot in the host device 1. In this case, the auxiliary device 2 could e.g. be released by pushing the auxiliary device 2 further into the host device 1, which releases the auxiliary device 2, allowing a spring to eject the auxiliary device 2 sufficiently for the user 4 to pull out the auxiliary device 2. The slot embodiment would protect the physical connection 8 in a better way as these are the provided inside the host device 1.
[0068] In one embodiment, the auxiliary device 2 is flexible and can be rolled up. The auxiliary device 2 can then rolled into an open space inside the host device where the card could be rolled. The auxiliary device 2 is then provided using a flexible substrate to enable the auxiliary device 2 to be rolled up. The interface connections could be positioned inside the host device or in the outer connection point.
[0069] When the user wants to separate the auxiliary device 2 from the host device 1, the user manipulates the auxiliary device 2, the host device 1 and / or the one or more mechanical connectors 7 to release the mechanical connection between the host device 1 and the auxiliary device 2.
[0070] Figs 4A-B are swimlane diagrams illustrating embodiments of methods for enabling presentation of credentials. The swimlane diagrams can be considered to comprise a flow chart for methods performed by the host device 1 on the left and a flow chart for methods performed by the auxiliary device 2 on the right. Interaction between the host device 1 and the auxiliary device 2 is also shown. As described above, the host device 1 comprises a first secure element and the auxiliary device 2 comprises a second secure element. Furthermore, the auxiliary device 2 comprises a bistable display 63 and a user input device 69.
[0071] Looking first to Fig 4A, in a transmit credential data step 142, the host device 1 transmits credential data 20, stored in the first secure element 166, for a plurality of credentials to the auxiliary device 2 for (selective) presentation on the bistable display 63 of the auxiliary device 2. This transmission is performed by a secure function in the host device 1. The credential data 20 is transmitted over the interface 10 for communicating between the first secure element 166 and the second secure element 66 of the auxiliary device 2. The interface 10 is implemented over the physical connection 8 between the host device 1 and the auxiliary device 2.
[0072] In a receive credential data step 42, the auxiliary device 2 receives the credential data 20 for the plurality of credentials from the host device 1 over the interface 10 for communicating between the first secure element 166 of the host device and the second secure element 66 (of the auxiliary device 2). As described above, the interface 10 is implemented over a physical connection between the host device 1 and the auxiliary device 2.
[0073] It will now be described in some more detail how the credential data 20 is securely transferred from the first secure element 166 to the second secure element 66. The transfer can be triggered by the user of the host device 1 and can be managed by a host device application, optionally in co-operation with the electronic wallet application of the host device 1. Alternatively, the tasks mentioned herein performed by the host device application is performed by the electronic wallet application. Alternatively, the tasks mentioned herein performed by the host device application is performed by a respective application in the host device for each credential. Before transfer of data can occur, a shared key between the two secure elements 66, 166 can be established. Theshared key can then be used derive one or more keys for encryption and integrity protection of the credential data.
[0074] Looking now to the secure key exchange, the secure element of a new auxiliary device 2 can be personalized with a security domain where the credential data will reside. This may, for example, be a security domain of the secure element issuer or a dedicated security domain of a service provider. Such a service provider may for example be the manufacturer of the auxiliary device 2. The security domain can be personalized with cryptographic credentials for secure key exchange. Examples of cryptographic credentials are a symmetric key shared with a trusted service manager (TSM) or an asymmetric elliptic curve key pair, optionally with an associated certificate, and a trusted certificate or public key. Typically, the TSM controls the security domain and assists in a secure key exchange between the two secure elements 66, 166. For example, the secure element issuer or manufacturer of the auxiliary device 2 may act as the TSM.
[0075] The secure key exchange can be triggered from a host device application that communicates with the secure element of the auxiliary device 2 and retrieves information about the second secure element 66 (in the auxiliary device 2), including the address of the TSM. The host device application establishes a communication with the TSM and relays communication between the secure second element 66 and the TSM. The TSM and the second secure element 66 establishes a secure channel (e.g. after the TSM has performed remote authentication and / or remote attestation of the secure element) using the cryptographic credentials.
[0076] When the TSM also controls the first secure element 166 (of the host device 1), a secure channel is established between the TSM and the first secure element 166 in a similar way using the cryptographic credentials of the first secure element 166 . Using the two secure channels to the two secure elements, the TSM then generates and provides a shared key between the two secure elements. For example, the TSM can generate a random symmetric key and securely provide that key to the two secure elements 66, 166 over the respective secure channels. Alternatively, the TSM instructs each secure element 66, 166 to generate an elliptic key pair and provide the public key to the TSM. The TSM then forwards the public key to the other secure element 66, 166 andinstructs each secure element to perform a Diffie-Hellman key agreement and use the resulting Diffie-Hellman secret as the shared key. If the two secure elements have different TSMs, then the two TSM can have an agreement that allow them to establish secure communication and relay the key exchange.
[0077] As an alternative without the use of a TSM, the second secure element 66 (of the auxiliary device 2) can be configured with an elliptic curve key pair, and the public key could be printed in form of a QR (quick response) code for the host device to scan. The QR code can e.g. be provided on the packaging of the auxiliary device 2 or on a card provided inside the packaging of the auxiliary device 2. Alternatively, the public key is contained in a certificate issued by the manufacturer of the auxiliary device 2, and is obtained from the second secure element by the host device application. The host device application could then provide the public key to the first secure element 166 (of the host device), possibly after verifying the certificate using a root CA (certificate authority) certificate (e.g. downloaded from the CA website), and trigger the first secure element 166 to generate an elliptic curve key pair and return its public key. The host device application then provides the generated public key to the second secure element 66. Both secure elements can then derive a Diffie-Hellman shared secret that is used as shared key.
[0078] In order to protect against a man-in-the-middle, the host device application could provide a random challenge generated by the first secure element 166 to the second secure element 66, and request the second secure element 66 to compute a MAC (message authentication code) using a key derived from the shared key. The MAC is provided by the host device application to the first secure element 166 , that can then verify the MAC to ensure there is no man-in-the-middle. In the case with no TSM, once a shared key is securely established, a new key cannot be established without wiping all installed card data, e.g. by resetting the auxiliary device 2.
[0079] In a store credential data step 43, the auxiliary device 2 stores the credential data in the second secure element 66.
[0080] In a release step 144, the host device 1 releases a mechanical connection with the auxiliary device 2 based on user manipulation to release the auxiliary device 2 from the host device 1.
[0081] In a release step 44 (corresponding to the release step 144 of the host device 1), the auxiliary device 2 releases the mechanical connection with the host device 1 based on user manipulation to release the auxiliary device 2 from the host device 1. After the auxiliary device 2 is released, it is operable in stand-alone mode.
[0082] In one embodiment, a timer is started when the auxiliary device 2 is released from the host device 1, and when the timer expires, all credentials are wiped from the auxiliary device 2. The timer is reset when the auxiliary device 2 is again physically engaged with the host device 1. The use of the timer ensures that the credentials of the auxiliary device 2 are unusable after a certain time, e.g. if the auxiliary device 2 is lost. Optionally, the length of the timer depends on context, such as time and location. For example, the host device can set a shorter timer if auxiliary device is released late a Friday night at the pub where the risk of losing the auxiliary device might be increased. Alternatively or additionally, the length of the timer depends on the type of credential. For instance, a loyalty card can be subject to a longer timer period than a payment card.
[0083] In a receive user input step 45, the auxiliary device 2 receives user input via the at least one user input device 69 to select one of the plurality of credentials. Hence, the user input is to indicate which one of the plurality of credentials is to be presented on the bistable display 63.
[0084] In a present credential step 46, the auxiliary device 2 presents a representation of the selected one of the plurality of credentials, based on the credential data, on the bistable display 63.
[0085] Looking now to Fig 4B, only new or modified steps compared to what is shown in Fig 4A will be described.
[0086] In an optional provide energy step 138, the host device 1 provides energy 16 to the auxiliary device 2. As described above, the energy can be provided over a conductive connection and / or an inductive connection.
[0087] In an optional receive energy step 38, the auxiliary device 2 receives the energy 16 from an external device. The external device can be the host device 1 or a reader device 6.
[0088] In an optional transmit apps step 140, the host device 1 transmits, for each one of the at least one credential data, an application comprising executable code. When the user of the host device requests a credential to be available for use on the auxiliary device 2, the application (e.g. Java applet for secure elements) for the particular credential can thereby securely be provisioned, from the second secure element to the first secure element (of the auxiliary device 2).
[0089] In an optional receive apps step 40, the auxiliary device 2 receives, for each one of the at least one credential data, an application comprising executable code. The applications can be received from the first secure element 166 , i.e. transmitted in the transmit app step 140. Alternatively, the applications can be provided from the TSM to the second secure element 66 using the secure channel mentioned above between these two entities. The executable code can be code that is executable directly by the processing circuitry 60 of the auxiliary device 2, or the executable code can be code that is executable in a virtual machine (e.g. Java virtual machine) that is provided in the auxiliary device 2. In order to manage and switch between multiple credentials at the auxiliary device 2, one application is provided per credential within the second secure element 66.
[0090] In an optional store apps step 41, the auxiliary device 2 stores the application for each one of the at least one credential data in the second secure element 66. When a new application is received, the auxiliary device 2 optionally first checks if there is sufficient space in the second secure element 66 to store the received application. If there is not enough space, the new application can be prevented from being stored. Alternatively, one application in the second secure element is removed to make space for the new application. The application that is removed can e.g. be the applications that was least recently used.
[0091] The credential data and applications are encrypted and integrity protected by the first secure element 166 using key(s) derived from the shared key established asdescribed above. For example, AES (Advanced Encryption Standard)-128-CCM (counter with cipher block chaining message authentication) or AES-128-GCM (Galois / Counter Mode) may be used to encrypt and integrity protect the data. Once received, the second secure element 66 decrypts and verifies the credential data. Upon successful verification, the credential data is installed, and when an application is used, linked with the correct application of the secure element. For example, each application supports provisioning of its card data or there is a dedicated application for provisioning of card data for all applications.
[0092] The user of the host device 1 may request the credential data and applications to be removed (wiped) from the application(s) on the auxiliary device 2. Optionally, the application linked to the card may still reside (unusable without credential data) on the card in case the user decides to use its card on the auxiliary device 2 at a later point in time. For example, due to limited number of credentials that the auxiliary device 2 can keep.
[0093] In an optional deactivate credentials step 143, the host device 1 deactivates, in the host device 1, the credentials corresponding to the credential data 20 transmitted to the auxiliary device 2. In this way, the credentials that have been transferred to the auxiliary device 2 are unusable in the host device 1 by itself. This increases security of the host device 1. For instance, if the user of the host device 1 lends out the host device 1 to someone, the host device 1 is no longer usable to present the credentials that have been transferred to the auxiliary device 2.
[0094] In an optional communicate with reader step 48, the auxiliary device 2 communicates with a reader 6 using the I / O interface (e.g. based on NFC). This is performed to enable the reader to validate at least part of the credential data.
[0095] Using embodiments presented herein, it is provided a physical multicredential device (the auxiliary device 2) that replaces plastic cards and reduces exposure of personal data when using an unlocked smartphone. The auxiliary device 2 provides a low-power detachable display device, acting as a stand-alone smart card, where the credential is dynamically selectable.
[0096] Fig 5 is a schematic diagram showing functional modules of the auxiliary device 2 of Fig 1 according to one embodiment. The modules are implemented using software instructions such as a computer program executing in the auxiliary device 2. Alternatively or additionally, the modules are implemented using hardware, such as any one or more of an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or discrete logical circuits. The modules correspond to the steps in the methods illustrated in Figs 4A-B that are performed by the auxiliary device 2.
[0097] An energy receiver 78 corresponds to step 38. An app receiver 80 corresponds to step 40. An app storer 81 corresponds to step 41. A credential data receiver 82 corresponds to step 42. A credential data storer 83 corresponds to step 43. A releaser 84 corresponds to step 44. A user input receiver 85 corresponds to step 45. A credential presenter 86 corresponds to step 46. A reader communicator 88 corresponds to step 48.
[0098] Fig 6 is a schematic diagram showing functional modules of the host device 1 of Fig 1 according to one embodiment. The modules are implemented using software instructions such as a computer program executing in the host device 1. Alternatively or additionally, the modules are implemented using hardware, such as any one or more of an ASIC, an FPGA, or discrete logical circuits. The modules correspond to the steps in the methods illustrated in Figs 4A-B that are performed by the host device 1.
[0099] An energy provider 178 corresponds to step 138. An app transmitter 180 corresponds to step 140. A credential data transmitter 182 corresponds to step 142. A deactivator 183 corresponds to step 143. A releaser 184 corresponds to step 144.
[0100] Fig 7 shows one example of a computer program product 90 comprising computer readable means. On this computer readable means, a computer program 91 can be stored in a non-transitory memory. The computer program can cause processing circuitry to execute a method according to embodiments described herein. In this example, the computer program product 90 is in the form of a removable solid-state memory, e.g. a Universal Serial Bus (USB) drive. As explained above, the computer program product could also be embodied in a memory of a device, such as the computerprogram product 64 or the computer program product 164 of Fig 2. While the computer program 91 is here schematically shown as a section of the removable solid-state memory, the computer program can be stored in any way which is suitable for the computer program product, such as another type of removable solid-state memory, or an optical disc, such as a CD (compact disc), a DVD (digital versatile disc) or a Blu-Ray disc.
[0101] The aspects of the present disclosure have mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the invention, as defined by the appended patent claims. Thus, while various aspects and embodiments have been disclosed herein, other aspects and embodiments will be apparent to those skilled in the art. The various aspects and embodiments disclosed herein are for purposes of illustration and are not intended to be limiting, with the true scope being indicated by the following claims.
Claims
CLAIMS1. A method for enabling presentation of credentials, the method being performed by an auxiliary device (2) configured to communicate with a host device (1) comprising a first secure element, the auxiliary device (2) comprising a bistable display (63), a second secure element (66) and a user input device (69), the method comprising: receiving (42) credential data for a plurality of credentials from the host device (1) over an interface (10) for communicating between the first secure element (166) of the host device and the second secure element (66), wherein the interface (10) is implemented over a physical connection between the host device (1) and the auxiliary device (2); storing (43) the credential data in the second secure element (66); releasing (44) a mechanical connection with the host device (1) based on user manipulation to release the auxiliary device (2) from the host device (1); receiving (45) user input via the at least one user input device (69) to select one of the plurality of credentials; and presenting (46) a representation of the selected one of the plurality of credentials, based on the credential data, on the bistable display (63).
2. The method according to claim 1, wherein the auxiliary device (2) further comprises an input / output, I / O, interface (62) for near-field communication, wherein the method further comprises: communicating (48) with a reader using the I / O interface, for the reader to validate at least part of the credential data.
3. The method according to claim 1 or 2, further comprising: receiving (40), for each one of the at least one credential data, an application comprising executable code; and storing (41) the application for each one of the at least one credential data in the second secure element (66).
4. The method according to any one of the preceding claims, further comprising: receiving (38) energy from an external device, being the host device (1) or a reader device (6).
5. An auxiliary device (2) for enabling presentation of credentials, the auxiliary device (2) being configured to communicate with a host device (1) comprising a first secure element, the auxiliary device (2) comprising: a bistable display (63); a second secure element (66): a user input device (69); processing circuitry (60); and memory circuitry (64) storing instructions (67) that, when executed by the processing circuitry, cause the auxiliary device (2) to: receive credential data for a plurality of credentials from the host device (1) over an interface (10) for communicating between the first secure element (166) of the host device and the second secure element (66), wherein the interface (10) is implemented over a physical connection between the host device (1) and the auxiliary device (2); store the credential data in the second secure element (66); release a mechanical connection with the host device (1) based on user manipulation to release the auxiliary device (2) from the host device (1); receive user input via the at least one user input device (69) to select one of the plurality of credentials; and present a representation of the selected one of the plurality of credentials, based on the credential data, on the bistable display (63).
6. The auxiliary device (2) according to claim 5, further comprising an input / output, I / O, interface (62) for near-field communication, and instructions (67) that, when executed by the processing circuitry, cause the co-auxiliary device (2) to: communicate with a reader using the I / O interface, for the reader to validate at least part of the credential data.
7. The auxiliary device (2) according to claim 5 or 6, further comprising instructions (67) that, when executed by the processing circuitry, cause the co-auxiliary device (2) to: receive, for each one of the at least one credential data, an application comprising executable code; and store the application for each one of the at least one credential data in the second secure element (66).
8. The auxiliary device (2) according to any one of claims 5 to 7, further comprising instructions (67) that, when executed by the processing circuitry, cause the co-auxiliary device (2) to: receive energy from an external device, being the host device (1) or a reader device (6).
9. A computer program (67, 91) for enabling presentation of credentials, using an auxiliary device (2) configured to communicate with a host device (1) comprising a first secure element, the auxiliary device (2) comprising a bistable display (63), a second secure element (66) and a user input device (69), the computer program comprising computer program code which, when executed on the auxiliary device (2) causes the auxiliary device (2) to: receive credential data for a plurality of credentials from the host device (1) over an interface (10) for communicating between the first secure element (166) of the host device and the second secure element (66), wherein the interface (10) is implemented over a physical connection between the host device (1) and the auxiliary device (2); store the credential data in the second secure element (66); release a mechanical connection with the host device (1) based on user manipulation to release the auxiliary device (2) from the host device (1); receive user input via the at least one user input device (69) to select one of the plurality of credentials; and present a representation of the selected one of the plurality of credentials, based on the credential data, on the bistable display (63).
10. A computer program product (64, 90) comprising a computer program according to claim 9 and a computer readable means comprising non-transitory memory in which the computer program is stored.
11. A method for enabling presentation of credentials, the method being performed by a host device (1) comprising a first secure element (166), the host device (1) being configured to communicate with an auxiliary device (1) comprising an bistable display (63) and a second secure element (66), the method comprising: transmitting (142) credential data, stored in the first secure element (166), for a plurality of credentials to the auxiliary device (2) for presentation on a bistable displayfirst secure element (166) and the second secure element (66) of the auxiliary device (2), wherein the interface (10) is implemented over a physical connection between the host device (1) and the auxiliary device (2); and releasing (144) a mechanical connection with the auxiliary device (2) based on user manipulation to release the auxiliary device (2) from the host device (1).
12. The method according to claim 11, further comprising: transmitting (140), for each one of the at least one credential data, an application comprising executable code.
13. The method according to claim 11 or 12, further comprising: providing (138) energy to the auxiliary device (2).
14. The method according to any one of claims 11 to 13, further comprising: deactivating (143), in the host device (1), the credentials corresponding to the credential data transmitted to the auxiliary device (2).
15. A host device (1) for enabling presentation of credentials, the host device (1) comprising: a first secure element (166), the host device (1) being configured to communicate with an auxiliary device (1) comprising an bistable display (63) and a second secure element (66); processing circuitry (160); and memory circuitry (164) storing instructions (167) that, when executed by the processing circuitry, cause the host device (1) to: transmit credential data, stored in the first secure element (166), for a plurality of credentials to the auxiliary device (2) for presentation on a bistable display (63) of the auxiliary device (2) over an interface (10) for communicating between the first secure element (166) and the second secure element (66) of the auxiliary device (2), wherein the interface (10) is implemented over a physical connection between the host device (1) and the auxiliary device (2); and release a mechanical connection with the auxiliary device (2) based on user manipulation to release the auxiliary device (2) from the host device (1).
16. The host device (1) according to claim 15, further comprising instructions (167) that, when executed by the processing circuitry, cause the host device (1) to: transmit, for each one of the at least one credential data, an application comprising executable code.
17. The host device (1) according to claim 15 or 16, further comprising instructions (167) that, when executed by the processing circuitry, cause the host device (1) to: provide energy to the auxiliary device (2).
18. The host device (1) according to any one of claims 15 to 17, further comprising instructions (167) that, when executed by the processing circuitry, cause the host device (1) to: deactivate, in the host device (1), the credentials corresponding to the credential data transmitted to the auxiliary device (2).
19. A computer program (167, 91) for enabling presentation of credentials, the computer program comprising computer program code which, when executed on a host device (1) comprising a first secure element (166), the host device (1) being configured to communicate with an auxiliary device (1) comprising an bistable display (63) and a second secure element (66), causes the host device (1) to: transmit credential data, stored in the first secure element (166), for a plurality of credentials to the auxiliary device (2) for presentation on a bistable display (63) of the auxiliary device (2) over an interface (10) for communicating between the first secure element (166) and the second secure element (66) of the auxiliary device (2), wherein the interface (10) is implemented over a physical connection between the host device (1) and the auxiliary device (2); and release a mechanical connection with the auxiliary device (2) based on user manipulation to release the auxiliary device (2) from the host device (1).
20. A computer program product (164, 90) comprising a computer program (167, 91) according to claim 19 and a computer readable means comprising non-transitory memory in which the computer program is stored.
21. A system (3) comprising an auxiliary device (2) and a host device (1), for enabling presentation of credentials, the auxiliary device (2) and the host device (1) being configured to communicate with each other, the auxiliary device (2) comprising: a bistable display (63); a second secure element (66): a user input device (69); processing circuitry (60); and memory circuitry (64) storing instructions (67) that, when executed by the processing circuitry, cause the auxiliary device (2) to: receive credential data for a plurality of credentials from the host device (1) over an interface (10) for communicating between a first secure element (166) of the host device and the second secure element (66), wherein the interface (10) is implemented over a physical connection between the host device (1) and the auxiliary device (2); store the credential data in the second secure element (66); release a mechanical connection with the host device (1) based on user manipulation to release the auxiliary device (2) from the host device (1); receive user input via the at least one user input device (69) to select one of the plurality of credentials; and present a representation of the selected one of the plurality of credentials, based on the credential data, on the bistable display (63); the host device (1) comprising: the first secure element (166); processing circuitry (160); and memory circuitry (164) storing instructions (167) that, when executed by the processing circuitry, cause the host device (1) to: transmit the credential data, stored in the first secure element (166), for the plurality of credentials to the auxiliary device (2) for presentation on the bistable display (63) of the auxiliary device (2) over the interface (10) for communicating between the first secure element (166) and the second secure element (66) of the auxiliary device (2), wherein the interface (10) is implemented over the physical connection between the host device (1) and the auxiliary device (2); andrelease the mechanical connection with the auxiliary device (2) based on user manipulation to release the auxiliary device (2) from the host device (1).
Citation Information
Patent Citations
Digital wallet device for virtual wallet
EP2747015A2
Method for Replacing Traditional Payment and Identity Management Systems and Components to Provide Additional Security and a System Implementing Said Method
US20140108241A1
Accessory interface system
US20140189821A1
Detachable electronic payment device
US20210019726A1
Methods and arrangements for a smart card wallet and uses thereof
US6250557B1