Applet Distribution via Stakeholder Certification and Encrypted Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for distributing applets in secure environments do not provide mechanisms for stakeholders to obtain revenue and lack access control configuration, leading to underutilization of secure hardware and increased collaboration costs between developers and OS vendors.

Innovation Solution

A method where a stakeholder certifies applets, generates an applet key, and issues an encrypted token to a host for installation in a secure environment, allowing the secure environment to configure access control without sharing the secure environment key, enabling stakeholders to control access and revenue generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the ObC approach is used for applet distribution, then applets can be installed in secure environments, but stakeholders cannot obtain revenue and lack control over access

Engineering Contradiction:
Improveapplet distribution capabilityVSAvoidloss of revenue control and access management
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies preliminary action by requiring stakeholders to pre-certify applets and pre-configure access control policies before distribution. The stakeholder certifies the applet and creates an access control policy that specifies which applications can access the applet, establishing control mechanisms in advance rather than allowing unrestricted installation as in ObC

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a stakeholder as an intermediary between the applet developer and the secure environment. The stakeholder acts as a mediator that controls the distribution process, issues certificates, and manages access policies, preventing direct unrestricted access that would eliminate revenue opportunities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If OS vendors control access to secure code, then security is maintained, but developers face additional collaboration costs and reduced flexibility

Engineering Contradiction:
Improvesecurity enforcementVSAvoidcollaboration overhead and cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts access control functionality from the OS vendor domain and places it in the stakeholder domain. Instead of requiring OS vendors to configure and manage access control policies for each applet, the stakeholder independently manages access control, separating these responsibilities and reducing collaboration complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The stakeholder assumes multiple roles including applet certification, access control policy management, and distribution coordination, making the stakeholder a universal authority that handles previously分散 responsibilities across multiple parties

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If secure environment keys are shared for applet installation, then installation is simplified, but security control is reduced

Engineering Contradiction:
Improveapplet installation processVSAvoidsecure environment protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by providing different levels of access control to different applications. The access control policy specifies which applications can access which applets, creating localized security permissions rather than universal access, maintaining security while enabling controlled distribution

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3048553B1Method for distributing applets, and entities for distributing applets
Publication Date: 2019.06.26 FRAUNHOFER GESELLSCHAFT ZUR FORDERUNG DER ANGEWANDTEN FORSCHUNG EV
  • EP3048553B1 patent drawingFigure 1~2

AI summary

The application discloses a method and a system, as well as entities for distributing applets. In one embodiment, the method includes certifying an applet, a, by a stakeholder, S, by (a) submitting, by a developer, D, the applet, a, and an applet policy, P, to the stakeholder, S, for certification; (b) generating, by the stakeholder, an applet key, Ka, certifying the applet, and storing the applet key, Ka, and the certified applet, ea; and installing the applet in a secure environment, E, connectable to a host, H, by (a) sending, by the host, a secure environment identifier, idE, and an applet identifier, ida, to the stakeholder and requesting, by the host, a token, Ta, from the stakeholder, wherein the token is encrypted using a secure environment key, KE, and the encrypted token includes at least the applet key; (b) receiving the token, by the host; (c) sending, by the host, the certified applet and the token to the secure environment; (d) installing, by the secure environment, the certified applet in the secure environment using information extracted from the token.