Authenticable Management Script for Secure Element Content
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for managing content on secure elements, such as smart cards and mobile devices, are complex and costly due to the need for real-time key delivery and involvement of multiple entities in application installation, updating, and security domain management.
Innovation Solution
A method involving a service provider generating and providing an authenticable management script signed with a private key and accompanied by a management certificate, which the secure element authenticates and executes to manage content, simplifying the process and reducing costs by using a public key infrastructure for secure and efficient content management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If real-time key delivery and multiple entity involvement are used for content management on secure elements, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the authentication mechanism from the content management process itself, using a separate authentication value that is verified before execution. This separates the security verification function from the management operations, reducing the complexity of real-time key delivery while maintaining security.
Solution Approach 2:
The patent introduces an authentication value as an intermediary element between the service provider and the secure element. This authentication value acts as a mediator that verifies the legitimacy of management commands without requiring direct key exchange or multiple entity involvement, thereby simplifying the overall system complexity.
2Reliability
If real-time key delivery is implemented for content management, then security is improved, but loss of time and cost increase
Solution Approach 1:
The patent applies preliminary action by pre-establishing authentication values and management scripts before actual content management operations. The authentication value is prepared in advance and attached to management commands, eliminating the need for real-time key delivery during execution and reducing time loss.
3Reliability
If multiple entities are involved in application installation and management, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent merges the functions of multiple entities into a unified authentication mechanism. Instead of requiring separate involvement from key authorities, certificate authorities, and management systems, the solution combines these functions into a single authentication value that simplifies the operational flow while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
There is disclosed a method for managing content, comprising: generating, by a service provider, an authenticable management script configured to manage content comprised in a secure element; providing, by said service provider, the authenticable management script to the secure element. Furthermore, there is disclosed a method for managing content, comprising: receiving, by a secure element, an authenticable management script for managing content comprised in said secure element; authenticating, by said secure element, said authenticable management script; executing, by said secure element, the management script if the management script is authentic. Furthermore, there are disclosed corresponding computer program products and a corresponding secure element.