Data storage device for mobile device and method of routing traffic
The data storage device with a proactive controller and secure element facilitates secure and efficient data exchange, addressing compatibility and security issues in SIM cards, enabling expanded functionality and compatibility with various devices.
Patent Information
- Application Number
- PCT/RU2025/050154
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-31
- Filing Date
- 2025-05-30
- Publication Date
- 2025-12-04
AI Technical Summary
Existing SIM cards with variable memory face challenges in data exchange with modern mobile operating systems, leading to temporary locking and security risks, and existing solutions like eSIMs and virtual SIMs require manual data transfer and are not universally compatible with all devices.
A data storage device with a proactive controller that integrates a secure element and a controller, enabling efficient routing between the mobile device and the secure element through multiple data exchange lines, allowing for direct communication and preventing overload or blocking.
Ensures secure and expanded functionality of data storage devices by allowing seamless data exchange, preventing device resets, and supporting interactions with external services and applications without requiring manual data transfer.
Smart Images

Figure 00000027_0000 
Figure 00000027_0001 
Figure 00000028_0000
Abstract
Description
Mobile Storage Device and Traffic Routing Method Field of technology
[0001] The present invention relates to the field of terminal technologies and, in particular, to communication circuits with data storage devices, as well as with associated devices and control methods. State of the art
[0002] Modern SIM cards can store not only operator profiles and payment apps, but also additional third-party apps unrelated to the operator or bank. For example, a user can use the card as a secure identifier to access their accounts, sign transactions, and document transactions. Therefore, loading such apps onto the SIM card allows for expanded functionality while simultaneously keeping these apps secure.
[0003] In particular, a SIM card with variable memory and a method for using it are known, disclosed in application No. EP1596615A1 (published on 16.11.2005; IPC: H04W 88 / 02; H04W 8 / 20; H04W 92 / 08; H04Q 7 / 32). The SIM card of a mobile phone contains identification and authentication data for non-mobile networks stored in one memory area, data for mobile radio networks in another, and other elements, including data on non-cash payments, in a third.
[0004] However, a disadvantage of using such a SIM card is the inability to exchange data with it using many modern mobile operating systems. When attempting to exchange data via third-party applications, the mobile device may temporarily lock itself, recognizing such data exchange as unauthorized access to the data stored in the SIM card's security element. Therefore, using this type of SIM card with variable memory is pointless and unsafe without special routing settings.
[0005] To improve SIM card functionality while maintaining accessibility, various SIM card communication schemes are being developed, including third-party devices embedded in the mobile device or SIM card chip, or virtual or electronic SIM card (eSIM) technology. However, all of these have a number of drawbacks.
[0006] A communication circuit with a SIM card, a corresponding device and a control method are known, disclosed in application No. W02024012020A1 (published on 18.01.2024; IPC: H04I 1 / 3816). The circuit comprises a processor, a switching unit, a first card slot, and an eSIM chip. The input portion of the switching unit, the first output portion, and the second output portion are respectively connected to the processor, the first card slot, and the eSIM chip. The processor is used to control the switching unit, which selects a connection to the first card slot upon receiving the first message; or the processor is used to control the switching unit to connect to the eSIM chip upon receiving the second message. Thus, the switching unit enables shared use of the SIM card interface, enabling communication with both the eSIM card and the physical SIM card. The processor does not require an additional interface, so the size and area occupied do not change. In addition, the circuit, with or without the eSIM chip added to it, can use the same processor, and thus the joint design simplifies manufacturing.
[0007] A drawback of the described technical solution is the use of an eSIM chip. An eSIM is a virtual SIM card, so when changing a phone or smartphone, the user must transfer data from the eSIM to the new device manually, as, unlike a physical SIM card, an eSIM does not have a transferable tangible form. Furthermore, this scheme requires an embedded eSIM chip in the mobile device, and therefore cannot be used in all mobile devices. Furthermore, in the described routing scheme, the switch only routes traffic to the physical SIM card or eSIM; it does not offer a routing option capable of facilitating data exchange with the SIM and / or eSIM chip for mobile devices whose operating systems do not provide direct access to these chips.
[0008] A method for independent management of secure elements is also known, described in application No. WO2012154780A2 (published November 15, 2012; IPC: H04L 9 / 00; H04L 9 / 32). An independent secure element manager (ISEM) routes secure payloads without modifying the secure payloads and without knowledge of the encryption keys used to encrypt the secure payloads. Secure payloads from multiple issuers and multiple TSMs can coexist in one or more secure elements due to control by the ISEM.
[0009] The disadvantage of the described technical solution is that it provides the ability to interact with the user's mobile device only in embodiments in which the secure element is stored on the card. Memory, in particular on a MicroSD, i.e., not on a SIM card, since implementing a secure element in a MicroSD is extremely difficult and expensive. Moreover, the implementation of a smart card implemented in a MicroSD does not pose the problems of SIM-based smart cards, since all operating systems support data exchange with memory cards, but not all with SIM chips. Furthermore, the analog does not specify the ability of the controller to interact with the mobile device in embodiments in which the secure element is stored on the SIM card. Consequently, data exchange with a SIM-based smart card may lead to a temporary blocking of the phone or smartphone if there is no response from the SIM card, since the phone / smartphone or the SIM card's mobile operator may identify the lack of a response as a potential threat to the data contained on the SIM card.
[0010] In addition, a communication chip built into a SIM card is known from the prior art, protected by patent No. EP3082375B1 (published 12.02.2020; IPC: G06K 19 / 077; H04M 1 / 02; H04W 12 / 08; H04W 12 / 00). The chip comprises a baseband central processor, a first protocol interface, a switch and a SIMZone module. The said baseband central processor is connected to the first protocol interface, and the switch is connected to the SIMZone module, the first protocol interface and the IF1 interface. The switch and the said SIMZone module are always in a state of communication with each other, and when the said switch is in a state of communication with the first protocol interface, the SIMZone module is used to provide the functionality of the SIM card for the said baseband central processor. When the switch is in the communication state via the IF1 interface, the SIMZone module is used to receive data written via the IF1 interface. [UN] The disadvantage of this analog is that it exposes routing between two security elements (SIM cards), one of which may have an interface different from ISO7816, such as in the standard dual-card deployment of a SIM card and an eSIM. Furthermore, the routing scheme must be implemented in the mobile device and does not apply to routing within the SIM card, requiring modification of the user's mobile device.
[0012] Also known is an embedded method for creating a multi-virtual SIM card based on a virtual SIM card, disclosed in patent application No. CN108040349A (published on 15.05.2018; IPC: H04W 36 / 00; H04W 36 / 14; H04W 88 / 06). The method includes the following steps: first, an area is divided in a reliable execution environment for storing fixed stored data, temporarily stored data, Network-related information and the corresponding service code for multiple virtual SIM cards are used. The mobile phone sends the IMSI to the server; the server generates a random number group for transmission; and the mobile phone sends the random number to the TEE via the security channel. By configuring the built-in multi-virtual SIM card, various virtual SIM cards can be switched according to the user's current network status to achieve a more seamless mobile connection, ensuring continued use of the equipment in its normal mode.
[0013] The disadvantage of the described technical solution is the use of a virtual SIM card (or SoftSIM). Therefore, when changing a phone or smartphone, the user will need to transfer data from the SoftSIM to the new device manually, as, unlike a physical SIM card, a SoftSIM has no tangible embodiment. Therefore, this solution reveals a method for creating and routing data within an immaterial SoftSIM.
[0014] Also known are adhesive thin SIM cards, disclosed, in particular, in application No. WO2016168965A1 (published October 27, 2016; IPC: G06K 19 / 07). The described smart card has a contact side and contains a plurality of smart card contact points. An auxiliary mounting structure is formed by a plate and contains a first housing portion, a second housing portion, a folding line, and a thin plastic film. The smart card can be easily attached to the user identification module card using the auxiliary mounting structure without aligning the contact points.
[0015] The disadvantage of such thin smart cards is that they require the user to perform additional steps, such as sticking one SIM card onto another. Furthermore, the analog describes a standard routing scheme between two SIM cards, which does not solve the problem of exchanging data with the SIM chip in operating systems that do not provide access for such exchange. The essence of the invention
[0016] The objective of the present invention is to create and develop a data storage device for a mobile device and a method for routing traffic, that is, a method for using a data storage device by routing data between its elements, ensuring the expansion of the functionality of data storage devices.
[0017] This problem is solved by the claimed invention through the technical result of expanding the functionality of data storage devices while maintaining the security of data storage. This technical result is achieved, among other things, through: • the ability to integrate a proactive controller into a data storage device; • the ability to send a response from the proactive controller to the mobile device upon receiving a request from the mobile device.
[0018] More specifically, the technical result is achieved by a data storage device for a mobile device, including a secure element and a controller connected to the secure element. The secure element includes data and is configured to process it. A first data exchange line is provided between the mobile device and the controller, and a second data exchange line is provided between the secure element and the controller. The controller, in turn, is configured to: (1) receive requests from the mobile device; (2) receive responses from the secure element; (3) determine the current operating status of the secure element; (4) generate and send requests to the secure element; and (5) generate and send responses to the mobile device.
[0019] The secure element is required for the secure storage of various data, including authentication data, and applications. The controller, in turn, is necessary for establishing efficient routing between device elements and third-party elements, including the mobile device. The presence of a first data link between the mobile device and the controller is necessary to ensure the ability to receive requests from the mobile device, as well as to send responses to the mobile device. The second data link between the controller and the secure element is necessary for sending requests (from the mobile device or internal controller requests) to the secure element, as well as for receiving responses from the secure element. Determining the current operating status of the security element, in turn, is necessary to prevent Security element overload. This allows for one-by-one requests to be sent to the security element. One of the controller's most important functions is the ability to generate and send responses to the mobile device. This is necessary to ensure the ability to use the storage device not only within its original logic but also to expand its capabilities without the risk of resetting the security element by the mobile device.
[0020] A third data line may be provided between the mobile device and the secure element, and the device may include a switch connected to the first and third data lines and configured to switch between the data lines. This allows for a direct data exchange route between the mobile device and the secure element, speeding up their interactions and reducing the load on the controller. The controller may be connected to the third data line and configured to detect the presence or absence of ongoing data exchange on the third data line and control the switch. This allows the controller to continuously monitor the current status of the exchange and the operation of the secure element and control routing, thereby increasing the efficiency of the device.
[0021] The controller can also be configured to generate and send an additional request to the secure element via the second data link or an additional response to the mobile device via the first data link while data is currently being exchanged via the third data link. This may be necessary when the controller has its own additional logic for specific types of responses and / or requests. The controller can also be configured to send an additional request via the second data link and / or an additional response via the first data link in the time interval between sending the request and receiving the response via the third data link. This avoids interference with the data exchange between the secure element and the mobile device and prevents data loss.
[0022] Additionally, the controller can be configured to change the switch position to the first data link when there is no ongoing data exchange on the third data link. This allows the controller to interact with the secure element without the risk of interrupting the mobile device's interaction.
[0023] The controller can be additionally connected to a fourth data link, capable of exchanging data with external services and / or applications. The controller can also be configured to facilitate data exchange between the secure element and external services or applications by sending requests from the external service or application to the secure element and transmitting responses from the secure element to the external service or application via the fourth data link. This will further expand the potential applications of such a data storage device.
[0024] The controller can also be configured to accumulate requests received from the mobile device when data is exchanged via the second and fourth data lines. This will prevent the loss of requests received from the mobile device while the controller is interacting with the security element.
[0025] A fifth data exchange line can be implemented between the security element and the controller using a different interface than the first, second, third, and fourth data exchange lines. This increases the flexibility of the controller's request generation, as it can generate and transmit a larger number of different request types to the security element.
[0026] The technical result is also achieved by routing traffic between a mobile device and a data storage device. According to the method, upon receiving a request from a mobile device to a secure element of a data storage device, the data storage device's controller determines the current status of the secure element. If the secure element is busy, the controller generates and sends a response in the form of an intermediate status to the mobile device via the first data link. If the secure element is available, the controller sends a request from the mobile device to the secure element and then sends a response to the mobile device.
[0027] Determining the current status allows for the selection of further routing logic, preventing simultaneous requests to the security element from two or more sources. Furthermore, if the security element is busy, the controller generates and sends a response in the form of an intermediate status to the mobile device, preventing the activation of mobile device logic that would lead to blocking and / or resetting. Security element. If the security element is available, the request is forwarded to it, and the response received is sent to the mobile device. This ensures data exchange between the specified elements.
[0028] The controller can additionally receive requests from an external service or application via a fourth data exchange line. This allows the storage device to interact with third-party services and applications not intended by the bank or operator that issued the storage device. Then, if no request is received from the mobile device, a request to exchange data with an external application or service can be generated via the controller and sent to the secure element.
[0029] Upon receiving a request from a mobile device, if a response from the secure element has not yet been received, a response can be generated and sent to the mobile device as an intermediate status via the controller. This prevents interruption of the secure element's processing and overload, while also preventing the mobile device from activating the reset logic for the secure element. Furthermore, requests to the secure element received from the mobile device via the first data link can be accumulated by the controller. This prevents the loss of requests from the mobile device and forwards them to the secure element via the second data link once it has completed its current processing.
[0030] The controller can also be used to change the switch position so that requests from the mobile device are forwarded to the secure element directly via the third data link. This will speed up the data exchange between the secure element and the mobile device. The controller can also monitor the third data link. Then, if there is no data exchange via the third data link, the controller can change the switch position so that requests from the mobile device are forwarded to the secure element via the controller via the first data link.
[0031] Additionally, if there is a request and / or response via the third data line, the controller can send an additional request to the secure element via the second data line or an additional response to the mobile device via the first data line. This may be necessary when the controller has its own additional logic for certain types of responses and / or requests. In this case, the additional request via the second data line and / or An additional response via the first data exchange line may be sent in the time interval between sending the request and receiving the response via the third data exchange line.
[0032] Additionally, requests can be sent from the controller to the security element via the fifth data link using a different interface than the first, second, third, and fourth data links. This increases the flexibility of the controller's request generation, as it can generate and transmit a larger number of different request types to the security element. Description of drawings
[0033] The subject matter of the present application is described point by point and clearly stated in the claims. The above-mentioned objectives, features, and advantages of the invention are apparent from the following detailed description, taken in conjunction with the accompanying drawings, which show:
[0034] Fig. 1 is a schematic view of the configuration of a data storage device for a mobile device according to the present invention.
[0035] Fig. 2 is a schematic view of a second embodiment of the configuration of a data storage device for a mobile device according to the present invention.
[0036] Fig. 3 is a schematic view of a third embodiment of the configuration of a data storage device for a mobile device according to the present invention.
[0037] Fig. 4 is a schematic view of a fourth embodiment of the configuration of a data storage device for a mobile device according to the present invention.
[0038] Fig. 5 is a schematic view of a fifth embodiment of the configuration of a data storage device for a mobile device according to the present invention.
[0039] Fig. 6 is a schematic view of a sixth embodiment of a data storage device configuration for a mobile device according to the present invention.
[0040] Fig. 7 is a schematic view of a seventh embodiment of a data storage device configuration for a mobile device according to the present invention.
[0041] These figures are explained by the following positions: Position 1 - the first data exchange line (between the controller and the mobile device); Position 2 - the second data exchange line (between the controller and the safety element); Position 3 - the third data exchange line (between the mobile device and the security element); Position 4 - the fourth data exchange line (between the controller and an external service or application); Position 5 - the fifth data exchange line (between the controller and the safety element); Position 10 - data storage device; Position 11 - safety element; Position 12 - controller; Position 13 - switch; Position 20 - mobile device; Position 30 - external service or application. Detailed description of the invention
[0042] The following detailed description of the invention includes numerous implementation details to provide a clear understanding of the present invention. However, one skilled in the art will readily understand how the present invention may be used with or without these implementation details. In other instances, well-known methods, procedures, and components have not been described in detail to avoid unnecessarily obscuring the features of the present invention.
[0043] Furthermore, it is clear from the foregoing description that the invention is not limited to the embodiment described. Numerous possible modifications, changes, variations, and substitutions, while preserving the spirit and form of the present invention, are apparent to those skilled in the art.
[0044] Within the context of the present invention, a mobile device 20 refers to any portable computing device that acts as a master device in an interaction. In particular, such a device may include a mobile phone, smartphone, tablet, terminal, including a payment terminal, a biometric sensor in a smart card or access control system, other access control system locks, etc.
[0045] In the context of the present invention, data exchange lines (1-5) refer to logical data exchange lines. A person skilled in the art will readily understand how to construct physical connections that will ensure the described interaction between the device elements along the logical data exchange lines. It is important to note that in the Figures, the dotted lines represent logical data exchange lines, while the dashed lines represent possible arrangements for the physical data exchange lines. If a logical response line coincides with a physical line, both are shown by a single dashed line.
[0046] A data storage device 10 for a mobile device 20 includes a secure element 11 and a controller 12 connected to the secure element 11. The secure element 11 includes data and is configured to process it. A first data exchange line 1 is provided between the mobile device 20 and the controller 12, and a second data exchange line 2 is provided between the secure element 11 and the controller 12. The controller 12, in turn, is configured to: (1) receive requests from the mobile device 20 to the secure element 11; (2) receive responses from the secure element 11 to the mobile device 20; (3) determine the current operating status of the secure element 11; (4) generate and send requests to the secure element 11; and (5) generate and send responses to the mobile device 20.
[0047] Data storage device 10 can be implemented in a SIM card form factor, inserting directly into mobile device 20 and performing the functions of the SIM card. This optimizes space and reduces the number of components required for the operation of mobile device 20. This integrated approach allows users to not only communicate but also securely store and process data directly at the SIM card level.
[0048] Furthermore, the data storage device 10 can be implemented as a separate chip integrated into the mainboard of the mobile device 20 or as a separate module. This gives manufacturers and developers greater flexibility in choosing the appropriate form factor and integration method for their products. This approach also allows for tailoring to the specific device and user needs, ensuring optimal functionality and ergonomics.
[0049] The primary function of the security element 11 is to provide authentication and encryption of data transmitted between the data storage device 10 and other devices (in particular, the mobile device 20 and the controller 12). It generates and stores unique authentication keys, Necessary to verify identity data and ensure the confidentiality of transmitted information. Furthermore, the security element plays a vital role in protecting against unauthorized network access and preventing fraud. It protects against copying or counterfeiting of the storage device 11 and prevents unauthorized use of data and applications on the device.
[0050] Security element 11 on the SIM card is also responsible for managing access to communication services and controlling network resource usage. It may contain information about subscriptions to data plans, restrictions on the use of certain services, and other parameters that determine the user's access to the network.
[0051] It is important to note that within the framework of the present invention, the controller 12 and the security element 11 can be implemented within the framework of a single chip, i.e. the controller 12 can be embedded in the chip of the security element 11, or the controller 12 can be a separate device connected to the security element 11.
[0052] Controller 12 (or microcontroller) is an electronic or digital control device. It is necessary for direct management of traffic routing within data storage device 10. To ensure effective control, controller 12 must have the following functionality.
[0053] Controller 12 must be configured to receive requests from mobile device 20 to security element 11. Controller 12 must also be configured to determine the current operating status of security element 11. This is necessary to avoid overloading security element 11 by allowing for one request to be sent to security element 11 at a time. However, if security element 11 is busy and, as a result, it is unable to transmit a request from mobile device 20 to it at that moment, controller 12 must be able to generate and send a response to mobile device 20 itself. Controller 12 may respond with an intermediate status indicating that security element 11 still requires time for processing.This is necessary to ensure the possibility of using the data storage device 10 not only within the framework of the original logic, but also to expand the possibilities of its use without the risk of resetting the security element 11 by the mobile device 20.
[0054] Also, the controller 12 must be configured with the ability to receive responses from the security element 11 to the mobile device 20. This is necessary in some routes for the subsequent transmission of the response to the mobile device 20. In addition, the controller 12 must be configured with the ability to generate and send requests to the security element 11. This allows for expanding the application capabilities of the data storage device.
[0055] The secure element is required for the secure storage of various data, including authentication data, and applications. The controller, in turn, is necessary for establishing efficient routing between device elements and third-party elements, including the mobile device. The presence of a primary data link between the mobile device and the controller is necessary to ensure the ability to receive requests from the mobile device and to send responses to the mobile device. A secondary data link between the controller and the secure element is necessary for sending requests (from the mobile device or internal controller requests) to the secure element and for receiving responses from the secure element. Determining the current status of the secure element, in turn, is necessary to prevent overloading the secure element. This allows for sending requests to the secure element one at a time.One of the controller's most important functions is the ability to generate and send responses to the mobile device. This is necessary to ensure the ability to use the data storage device not only within its original logic but also to expand its capabilities without the risk of the mobile device resetting the security element.
[0056] The described device 10 operates as follows. Upon receiving a request from mobile device 20 to secure element 11, the request first arrives at controller 12 via first data line 1. Controller 12 forwards the request to secure element 11 via second data line 2. Secure element 11 processes the request and generates a response for mobile device 20. The generated response is sent by secure element 11 to mobile device 20 via controller 12 via second data lines 2 and first data lines 1. As a result, mobile device 20 is unaware of the presence of additional controller 12 and sees only secure element 11.If no responses from the secure element 11 (or responses simulating responses from the secure element 11) were to reach the mobile device 20, there would be a risk of blocking the ability to use the mobile device 20, since such an anomaly would be regarded as an attempt to gain unauthorized access to the secure element 11. In general, the above-described option is similar to a standard interaction, for example, between the mobile device 20 (phone or smartphone) and the secure element 11 of the SIM card. or a mobile device 20 (payment terminal) and a security element 11 of a bank card, but differs in the presence of a controller 12 used as an intermediary in this interaction option.
[0057] Alternatively, interaction may occur between controller 12 and secure element 11. This may be particularly necessary when secure element 11 of a SIM card, in addition to the operator profile, or secure element 11 of a smart card, in addition to the payment application and / or biometric data, also stores additional applications unrelated to the operator or bank. For example, such a data storage device 10 may be used as a secure identifier for accessing user accounts, or for signing transactions and documents when storing the corresponding data and applications in secure element 11. In this case, since secure element 11 is always a slave element, and mobile device 20 may not be able to send the necessary actions to secure element 11, it is necessary for controller 12 to be able to send the corresponding requests.Thus, in this situation, the controller 12 determines the operating status of the safety element. 11. If the safety element is busy, then the controller 12 waits and periodically determines the operating status. When it is determined that the safety element 11 is free, then the controller 12 generates a corresponding request to the safety element 11. The safety element 11 processes the request and generates a response for the controller 12. In this case, if while the safety element 11 was busy processing the controller's request 12, a request arrives from mobile device 20. Since requests from mobile device 20 pass through controller 12, controller 12, knowing that secure element 11 is busy processing its request, can respond to mobile device 20 with an intermediate status, indicating that more time is needed to process the request. This enables mobile device 20 to avoid the reset logic of secure element 11, which is a protective mechanism in the event that secure element 11 does not respond within the expected time.
[0058] Between the mobile device 20 and the security element 11, a third data exchange line 3 may additionally be provided, as shown in Fig. 2. In this case, the data storage device 10 must include a switch 13 connected to the first 1 and third 3 data exchange lines and configured with the ability to switch between the data exchange lines (1 and 3). This option speeds up the process of data exchange between the mobile device 20 and the security element 11, since a direct route is built between them that does not pass through controller 12. However, precisely because the requests and responses do not pass through the controller 12, it is preferable in this case for the controller 12 to be connected to the third data exchange line 3, as shown in Fig. 3, and to be configured with the possibility of determining the presence or absence of current data exchange on the third data exchange line 3 and controlling the switch 13 based on the presence or absence of current exchange.
[0059] In this case, if the controller 12 has no requests to the secure element 11, then the controller 12 can command the switch 13 to change its position so that the mobile device 20 and the secure element 11 communicate directly with each other. In this case, the controller 12 will listen to the exchange. When the exchange between the mobile device 20 and the secure element 11 via the third data exchange line 3 stops, then the controller 12 can send a command to the switch 13 to switch to a position in which requests from the mobile device 20 will be sent to the controller 12 via the first data exchange line 1. In this case, the controller 12 can send its requests to the secure element 11 via the second data exchange line 2, responding to the mobile device 20 with an intermediate status upon receiving requests from it.
[0060] The above-described scheme is optimal, as each element of data storage device 10 and mobile device 20 communicate directly via established data exchange lines. This avoids delays in the data exchange process. However, the technical result of expanding the functionality of data storage devices while maintaining the security of their data storage, as well as preventing the possible reset of security element 11 or its complete blocking by mobile device 20, is also achieved in an embodiment without switch 13 and third data exchange line 3. Moreover, because controller 12 can listen to third data exchange line 3 and analyze the traffic, it can determine the time when a request is made, when a response is received, and when a response to a request from security element 11 is received.It also becomes possible for him to know at what point there is no exchange between the mobile device 20 and the security element 11 and the third exchange line 3 is free.
[0061] The controller 12 can be further configured with the ability to generate and send an additional request to the security element 11 via the second data exchange line 2 or an additional response to the mobile device 20 via the first data exchange line 1 in the presence of current data exchange via the third data exchange line 3. The controller 12 has such the need may arise if, in the case of exchange via the third exchange line 3, it sees requests and / or responses for which it has internal additional logic for requesting additional information from any applications inside the secure element 11. Then, knowing the current state of exchange between the mobile device 20 and the secure element 11, the controller 12 can correctly insert commands via the first 1 and second 2 data exchange lines, without disrupting the exchange between the mobile device 20 and the secure element 11. Thus, the controller 12 can be additionally configured with the possibility of sending an additional request via the second data exchange line 2 and / or an additional response via the first data exchange line 1 in the time interval between sending the request and receiving the response via the third data exchange line 3.
[0062] Due to such an exchange structure, as well as the circuit with switch 13, if necessary, controller 12 can switch the line from mobile device 20 (third exchange line 3) to itself (to the first exchange line 1) to prevent the loss of requests from mobile device 20 to security element 11, i.e. controller 12 switches to proxy mode (request buffering) and accumulates requests from mobile device 20, for example, while security element 11 processes requests from controller 12. In this case, it becomes possible for controller 12 to control requests to security element 11. Controller 12 can independently respond to mobile device 20 or, for example, insert additional - its own requests - to security element 11 via the second data exchange line 2.When the security element 11 has finished processing the request from the mobile device 20, it can forward to the security element 11 the requests from the mobile device 20 that have been accumulated earlier.
[0063] Also, the controller 12 can be additionally connected to the fourth data exchange line 4, configured to exchange data with external services and / or applications 30, as shown in Fig. 4. In this case, requests can come from external services and / or applications 30, and the controller 12 can be additionally configured to organize data exchange between the security element 11 and the external services or applications 30 by sending requests from the external service or application 30 to the security element 11 and transmitting responses from the security element 11 to the external service or application 30 via the fourth data exchange line 4. In particular, the external service 30 can request an electronic signature of the user. Then this request will arrive at the controller 12, which will then forward it to the security element 11, on which the electronic signature is stored. Other scenarios are also possible, in which external application 30 may request an identifier to access user accounts, or to sign transactions. Furthermore, external service 30 may be another operator, for example, if a single security element 11 contains multiple operator profiles. This is not possible with traditional SIM cards and bank cards, as applications are stored within the operator or bank profile. This is inconvenient, as integration with the operator or bank is required to add the application for subsequent installation. This also limits the use of storage device 10 to the active profile, which is inconvenient if the user wants to switch between multiple operators or banks within a single device.
[0064] Thus, if a fourth data exchange line 4 is present, capable of exchanging data with external services and / or applications 30, and the third data exchange line 3 is free, controller 12 can take over control and, upon requests from mobile device 20, hold it for the required time, responding with the intermediate status "more time required for processing." At the same time, it will route internal requests or those received via the fourth data exchange line 4.
[0065] Moreover, in this case, whether the third data exchange line 3 is present and controller 12 is connected to it, or not, when all requests from mobile device 20 pass through controller 12, since the controller knows which application it is currently requesting, it can route the response correctly. Otherwise, applications running on mobile device 20 will terminate with a probable error and a request to restart security element 11.
[0066] If the controller 12 has the functionality to accumulate requests from the mobile device 20 and simultaneously connects to external services and / or applications 30 via the fourth data exchange line 4, then the controller 12 routes requests received via the fourth data exchange line 4, simultaneously accumulating requests received from the mobile device 20. Upon completion of requests from the external service 30, the controller 12 makes a request to the security element 11 with one of the requests from the mobile device 20 that it has stored all this time. After receiving a response from the security element 11, the controller 12 will send a response via the first 1 or third 3 data exchange line (by controlling the switch 13 or sending the appropriate command to the security element 11). After this, he can send a command to switch 13 to move to a position that ensures data exchange via the third data exchange line 3.
[0067] If the data storage device 10 includes all of the above elements, and the controller 12 is implemented with all of the above-mentioned additional functions, then the device 10 may have a circuit shown in Fig. 5. In this case, the following options for interaction of the elements are possible.
[0068] Firstly, when a request is received from the mobile device 20, when the current exchange between the security element 11 and the controller 12 is absent, and the switch 13 is in the position in which the third data exchange line 3 is active between the mobile device 20 and the security element 11, then the request is sent directly to the security element 11. Information about the received request reaches the controller 12. If the controller 12 has additional logic, upon receipt of such a request, the controller 12 can send an additional request to the security element via the second exchange line 2 or send an additional response to the mobile device 20 via the first exchange line 1.When the security element 11 completes processing the request and sends a response to the mobile device 20, then after receiving the response by the mobile device 20, the controller 12 can move the switch 13 to the second position, which provides for sending requests from the mobile device 20 first to the controller 12, and not directly to the security element 11. Also, the controller 12 can leave the switch 13 in the initial position if it does not have its own internal requests to the security element 11 or requests coming from external services 30.
[0069] Secondly, if controller 12 has requests to secure element 11, but mobile device 20 does not, controller 12 can set the switch to a position that allows requests from mobile device 20 to be sent first to controller 12, rather than directly to secure element 11 (if it was initially in a different position). Controller 12 will then forward requests (either its own internal requests or requests from external services 30 via the fourth data exchange line 4) to secure element 11 via the second data exchange line 2. In this case, when a request from mobile device 20 is received, the request will be sent to controller 12 via the first data exchange line 1, rather than directly to secure element 11, which will prevent security element 11 from freezing and becoming overloaded.In this case, when a request is received from the mobile device 20 to the controller 12 by the security element 11, the controller 12 can respond to the mobile device 20 with an intermediate status indicating that the security element 11. busy processing. Such responses will mimic responses from secure element 11 to avoid blocking or initiating a restart of secure element 11 by mobile device 20. Controller 12 will also accumulate requests received from mobile device 20, and upon completion of processing of controller 12's request, secure element 11 will forward requests received from mobile device 20 to secure element 11.
[0070] Thus, controller 12 organizes proactive communication across multiple data lines. The fourth data line 4 can be either a wired or wireless connection, such as Wi-Fi or BLE. This makes it possible to build a unified communication interface with an API for third-party applications on mobile device 20 or external services and applications 30 (for identification).
[0071] In this case, if storage device 10 is a SIM card, it can act as a "cold wallet" for storing the key pair for signing transactions. Controller 12 can then initiate a call to the user interfaces provided by the SIM Toolkit (STK). This interface is used when the operator wants to send a mandatory message and blocks the interface of mobile phone or smartphone 20. This can, for example, be used as a second authentication factor for the transaction.
[0072] Another option is for the SIM card to scan the air for any devices / beacons, such as BLE or Wi-Fi, and send notifications about them to the SIM card app. A public transport ticketing system based on this principle could be built using the Be-In-Be-Out (BIBO) principle. That is, controller 12 would receive a payment request via the fourth data exchange line 4 from external service 30 and forward it to the security element.
[0073] Furthermore, it's important to note that the nature of mobile device 20, storage device 10, and external service 30 may vary depending on the specific application. Specifically, for in-store payment, mobile device 20 may be a payment terminal, and storage device 10 may be a bank card with the additional elements described above embedded (either directly in the chip or connected to it). Alternatively, this could be a telephone or smartphone and a SIM card. In the case of a SIM card, the additional elements may also be either embedded directly in the chip or connected to it.
[0074] Data storage device 10, implemented in the form factor of a SIM card, interacts with a mobile phone, smartphone, or tablet as follows. When the SIM card is inserted into the slot of mobile device 20, contacts or a chip on device 20 connect with the corresponding contacts or a chip on the SIM card. This allows mobile device 20 to read information stored on the SIM card, as well as write data to it. When mobile device 20 initiates the process of turning on or connecting to a telecom operator's network, it interacts with the SIM card, reading the data necessary for authentication on the network. This data may include a network identifier, a subscriber identifier, authentication keys, and other information necessary for establishing communication. After successful completion of the identification process, mobile device 20 can use the information on the SIM card to make calls, send messages, and access the telecom operator's services.Thus, interaction between the mobile device and the SIM card is accomplished through physical contact or contactless reading of information using special chips and contacts, ensuring the necessary functionality and communication within the operator's network. Requests from the mobile device 20, the controller, and external services and / or applications 30 will be routed according to the logic described above.
[0075] This solution can also be used in various IoT device configurations. For example, a known biometric identification option on payment cards or access cards involves the cardholder placing a finger on a sensor, which acts as a mobile device 20 within the framework of the present invention, initiating communication with a secure element 11. At this point, the sensor sends data for identification, and the card either responds positively (in the case of authentication) or prohibits it. An additional unit can analyze the data exchanged between the sensor and secure element 11 and, if the response is positive, also send its own request to secure element 11, verifying what needs to be done next, for example, to receive instructions to open an electronic lock. This option significantly simplifies and reduces the cost of existing secure IoT devices.
[0076] Another possible application for the described device 10 is its use as a commission-free payment and transfer device. In this case, controller 12 can be configured to debit funds stored on secure element 11. It is also important to note that controller 12 can store debited funds in its memory. This may be necessary, for example, to debit subscription fees from secure element 11 for use. device 10 (for example, if device 10 is a smart card, SIM card or bank card).
[0077] Another possible application for the described device 10 is its use as a storage device with scheduled actions. In this case, controller 12 can be configured to generate and send requests to secure element 11. It is also important to note that controller 12 can store the logic and schedule of such requests in its memory. This may be necessary, for example, to debit subscription fees from the balance of secure element 11 for use of device 10, generate transactions within secure element 11, or subsequently initiate exchange operations between mobile device 20 and secure element 11.
[0078] Between the security element 11 and the controller 12, a fifth data exchange line 5 may be additionally implemented using an interaction interface different from the interaction interfaces of the first 1, second 2, third 3, and fourth 4 data exchange lines. Such an embodiment is shown in Fig. 6. In particular, data exchange lines 1-4 may be implemented with a standard ISO7816 interaction interface, while the fifth data exchange line 5 may be implemented with an i2c, spi, or other known interaction interface. This increases the flexibility of the controller 12 in generating requests, since it is capable of generating and transmitting a larger number of different types of requests to the security element 11.
[0079] When all additional features of the data exchange device 11 are enabled, its basic diagram will look as shown in Fig. 7. In this case, all the interactions described above will remain unchanged, but requests and responses between the controller 12 and the security element 11 can pass through both the second 2 and the fourth 4 data exchange lines.
[0080] The data storage device 10 according to the present invention, as well as other data storage devices 10, can operate in accordance with the method of routing traffic between the mobile device 20 and the data storage device 10, disclosed in the present invention. In general, the method of routing traffic is the method of using the data storage device 10, namely the method of how data (in what sequence and what data) is transferred between the elements of the data storage device 10, as well as between the elements of the data storage device 10 and external devices and services. According to the method, a request is first received for the security element 11 of the device data storage 10 from the mobile device 20 using the controller 12 of the data storage device 10 via the first data exchange line 1. Then, the current operating status of the security element 11 is determined using the controller 12 of the data storage device 10. If the security element 11 is busy, then, using the controller 12, a response is generated and sent to the mobile device 20 in the form of an intermediate status via the first data exchange line 1. If the security element 11 is free, then first a request is sent from the mobile device 20 to the security element 11. Then, a response is sent to the mobile device 20.
[0081] Using the controller 12, requests can be additionally received from an external service or application 30 via the fourth data exchange line 4. This will allow the data storage device 10 to interact with third-party services and applications 30, interaction with which was not intended by the bank or operator to which the data storage device 10 was issued. Then, in the absence of a request from the mobile device 20, a request for data exchange with the external application or service 30 can be generated using the controller 12 and the generated request can be sent to the security element 11.
[0082] Moreover, when the security element 11 is busy processing a request from the controller 12 (internal or received from the external service 30), then upon receiving a request from the mobile device 20, if the response from the security element 11 has not yet been received, a response is generated and sent in the form of an intermediate status to the mobile device 20 using the controller 12. This allows for the processing of the security element 11 not to be interrupted and not to overload it, and at the same time prevents the logic of activating the collection of the security element 11 from the mobile device 20.
[0083] While the security element 11 is busy processing the request from the controller 12, the requests to the security element 11 received from the mobile device 20 via the first data exchange line 1 can be accumulated by the controller 12. This makes it possible to avoid losing the requests of the mobile device 20 and to forward them to the security element 11 via the second data exchange line 2 when it has finished the current processing.
[0084] Using the controller 12, they can also change the position of the switch 13 so that they can send requests from the mobile device 20 to the security element 11 via the third data exchange line 3, i.e. directly. In this case, they can listen to the third data exchange line 3 using the controller 12. Then, in the absence of data exchange on the third data exchange line 3, using the controller 12, they can change the position of the switch 13 so that requests from the mobile are sent devices 20 to the safety element 11 through the controller 12 via the first data exchange line 1. Otherwise, the switch can be left in the initial position, in which the third data exchange line 3 is active.
[0085] Additionally, if there is a request and / or response via the third data exchange line 3, the controller 12 can send an additional request to the security element 11 via the second data exchange line 2 or an additional response to the mobile device 20 via the first data exchange line 1. This may be necessary when the controller 12 has its own additional logic for certain types of responses and / or requests. In this case, an additional request via the second data exchange line 2 and / or an additional response via the first data exchange line I can be sent in the time interval between sending a request and receiving a response via the third data exchange line 3.
[0086] Additionally, requests can be sent from controller 12 to security element 11 via the fifth data exchange line 5 using an interaction interface different from the interaction interfaces of the first 1, second 2, third 3, and fourth 4 data exchange lines. This increases the flexibility of controller 12 in generating requests, since it is capable of generating and transmitting them to the security element. II a larger number of different types of requests.
[0087] It is important to note that any additional elements and functions of data storage device 10 described above may be used in device 10 individually, simultaneously, or in any combination. Implementing device 10 with any additional element will lead to the achievement of additional technical results described in the application, in addition to the primary technical result. Furthermore, any of the additional features of device 10 may be interpreted as an additional feature of the traffic routing method. Similarly, any of the additional features of the traffic routing method may be interpreted as an additional feature of data storage device 10.
[0088] These application materials present a preferred disclosure of the implementation of the claimed technical solution, which should not be used as limiting other, particular embodiments of its implementation that do not go beyond the scope of the requested scope of legal protection and are obvious to specialists in the relevant field of technology.
Claims
Invention formula 1. A data storage device for a mobile device, comprising: - a security element that includes data and is configured to process the data; and - a controller connected to the security element, wherein a first data exchange line is provided between the mobile device and the controller, and a second data exchange line is provided between the security element and the controller, wherein the controller is configured with the ability to: - receiving requests from a mobile device; - receiving responses from the security element; - determining the current operating status of the safety element; - generating and sending requests to the security element; and - generating and sending responses to a mobile device.
2. A data storage device according to claim 1, characterized in that a third data exchange line is additionally provided between the mobile device and the security element, and the device includes a switch connected to the first and third data exchange lines and configured with the ability to switch between the data exchange lines.
3. The data storage device according to claim 2, characterized in that the controller is connected to a third data exchange line and is configured to determine the presence or absence of current data exchange on the third data exchange line and control the switch.
4. The data storage device according to claim 3, characterized in that the controller is additionally configured with the possibility of generating and sending an additional request to the security element via the second data exchange line or an additional response to the mobile device via the first data exchange line in the presence of current data exchange via the third data exchange line.
5. The data storage device according to claim 4, characterized in that the controller is configured with the possibility of sending an additional request via the second data communication line and / or an additional response via the first data communication line in the time interval between sending the request and receiving the response via the third data communication line.
6. The data storage device according to paragraph 3, characterized in that the controller is configured with the ability to change the position of the switch to the first line data exchange in the absence of current data exchange on the third data exchange line.
7. A data storage device according to claim 1, characterized in that the controller is additionally connected to a fourth data exchange line, configured to exchange data with external services and / or applications.
8. The data storage device according to claim 7, characterized in that the controller is configured with the ability to organize data exchange between the security element and external services or applications by sending requests from the external service or application to the security element and transmitting responses from the security element to the external service or application via a fourth data exchange line.
9. A data storage device according to paragraph 8, characterized in that the controller is additionally configured with the ability to accumulate requests received from the mobile device, in the presence of data exchange via the second and fourth data exchange lines.
10. A data storage device according to any one of paragraphs 1-8, characterized in that a fifth data exchange line is additionally provided between the security element and the controller using an interaction interface that is different from the interaction interfaces of the first, second, third and fourth data exchange lines.
11. A method for routing traffic between a mobile device and a data storage device, whereby: upon receiving a request for a security element of the data storage device from the mobile device, the current operating status of the security element is determined using the controller of the data storage device; if the security element is busy, then, using the controller, a response in the form of an intermediate status is generated and sent to the mobile device via the first data exchange line; if the security element is free, then: - send a request from the mobile device to the security element; - send a response to the mobile device.
12. The method for routing traffic according to paragraph 11, characterized in that, with the help of the controller, requests are additionally received from an external service or application via a fourth data exchange line.
13. The method of routing traffic according to paragraph 12, characterized in that in the absence of a request from the mobile device, a request is generated for exchanging data with an external application or service using the controller and send the generated request to the security element.
14. A method for routing traffic according to I. 13, characterized in that upon receiving a request from a mobile device, if a response from the security element has not yet been received, a response in the form of an intermediate status is generated and sent to the mobile device using the controller.
15. A method for routing traffic according to I. 14, characterized in that, with the help of the controller, requests received from the mobile device via the first communication line are additionally accumulated.
16. A method for routing traffic according to any of paragraphs 11-15, characterized in that the controller is used to change the position of the switch so that requests from the mobile device are directed to the security element via a third data exchange line, while the controller is used to listen to the third data exchange line.
17. A method for routing traffic according to claim 16, characterized in that, in the absence of data exchange on the third data exchange line, the position of the switch is changed using the controller so that requests from the mobile device are directed to the security element through the controller on the first data exchange line.
18. The routing method according to claim 16, characterized in that, if there is a request and / or response via the third data exchange line, the controller sends an additional request to the security element via the second data exchange line or an additional response to the mobile device via the first data exchange line.
19. The routing method according to claim 18, characterized in that an additional request via the second data exchange line and / or an additional response via the first data exchange line are sent in the time interval between the sending of the request and the receipt of the response via the third data exchange line.
20. A method for routing traffic according to any of paragraphs 11-19, characterized in that requests are additionally sent from the controller to the security element via the fifth data exchange line using an interaction interface different from the interaction interfaces of the first, second, third, and fourth data exchange lines.
Citation Information
Patent Citations
SIM card with variable memory
EP1596615A1
Systems and methods for managing a session of a protocol data unit (PDU) adapted to an application
RU2758457C2
Method and system for creating multi-mobile environments and numbers on one handset with one sim card
RU2768566C1
Independent secure element management
US20120291095A1
Communication chip integrated with SIM card
US20160248463A1