Digital Key Valid Duration Management via Secure Element
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The emergence of digital keys in the automobile industry, while enhancing user convenience and expanding carsharing services, raises concerns about security due to their vulnerability to malicious use, such as hacking, as they rely on combinations with mobile terminals and lack reliable management of valid duration.
Innovation Solution
A communication system apparatus and method that includes a trusted service manager and a smart device with an embedded secure element, which manages and verifies the digital key's valid duration, preventing use after expiration and ensuring reliable security information transmission through near-field communication, using property information like valid time to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If digital key is integrated into mobile terminal for convenience, then user convenience and carsharing service expansion are improved, but security vulnerability to hacking and malicious use increases
Solution Approach 1:
The digital key system is segmented into multiple independent components: the key management server, the mobile terminal application, the vehicle control unit, and the embedded secure element. Each component performs a specific function and operates independently, reducing the attack surface for potential hackers while maintaining overall system functionality and user convenience.
Solution Approach 2:
An embedded secure element acts as an intermediary security module between the mobile terminal and the vehicle control unit. This intermediary component securely stores key information, performs authentication operations, and manages the valid duration of digital keys, thereby enhancing security without compromising the ease of operation provided by mobile terminal integration.
2Ease of operation
If digital key lacks valid duration management, then ease of use is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The key management server performs preliminary actions by pre-defining valid durations for digital keys during key issuance. The embedded secure element also pre-configures expiration time information before the digital key is activated. This preliminary establishment of validity periods ensures that keys automatically expire after a predetermined time, preventing unauthorized use while maintaining ease of operation during the valid period.
Solution Approach 2:
The embedded secure element continuously monitors the current time and compares it with the expiration time information stored in the digital key. When the current time exceeds the expiration time, the system provides feedback by rejecting authentication requests. This automatic feedback mechanism ensures that expired keys cannot be used for unauthorized access without requiring additional user intervention.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances the reliability of digital key security by preventing malicious use through valid duration management, ensuring secure communication systems and protecting against unauthorized access, thereby improving overall security in digital key-based systems.
Implementation Method 1
ensuring reliable security information transmission through near-field communication
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure relates to a technology for a sensor network, machine to machine (M2M) communication, machine type communication (MTC), and Internet of things (IoT). The present disclosure relates to an operation method of a first device in a communication system, the operation method comprising a step of receiving, from a server, security information of a second device associated with the first device, wherein the security information includes a first parameter associated with an operation of the second device, and attribute information associated with the first parameter.