Embedded Secure Element for Mobile Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile banking systems lack robust security measures, making them vulnerable to tampering and unauthorized access, despite their convenience and flexibility, as they rely on conventional password protection and encryption techniques similar to those used in internet transactions, which are insufficient compared to traditional POS terminals and smartcards.
Innovation Solution
Incorporating an embedded secure element into mobile devices with a secure processor, verification/authentication unit, and cryptographic processor to create a trusted environment for secure transactions, including secure memory for sensitive data storage and processing, enhancing security through both hardware and software-based alternative features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional password protection and encryption techniques are used in mobile banking systems, then ease of operation is improved, but security is worsened
Solution Approach 1:
The mobile device is segmented into a normal processing environment and a secure element with a trusted processing environment. The secure element is a physically separate component that houses cryptographic keys and performs sensitive operations, isolating them from the main processor and storage. This segmentation ensures that even if the main system is compromised, the secure element remains protected and can independently verify transactions.
Solution Approach 2:
The secure element acts as an intermediary between the user/mobile device and external systems (banks, retailers). It mediates authentication and transaction processes by verifying credentials, signing transactions, and managing security protocols. This intermediary role protects the main system from direct exposure to security threats while maintaining operational convenience for users.
2Adaptability or versatility
If mobile phones are configured as mobile POS terminals with software applications, then adaptability is improved, but security is worsened
Solution Approach 1:
The secure element provides universal security functions that support multiple applications and services (mobile banking, contactless payments, authentication). It implements standardized interfaces and protocols that work across different banks, retailers, and devices, enabling the mobile phone to serve as a universal financial terminal while maintaining consistent security levels regardless of the specific application being used.
3Ease of operation
If NFC technology is used for contactless payment, then ease of operation is improved, but security is worsened
Solution Approach 1:
The cryptographic keys and sensitive authentication data are extracted from the main mobile device storage and placed into the separate secure element. This extraction ensures that even if the NFC communication is intercepted or the main device is compromised, the actual security credentials remain protected in the isolated secure element, which can independently manage the contactless payment process.
Data Source
AI summary
Various embodiments of the present invention relate to incorporating an embedded secure element into a mobile device, and more particularly, to systems, devices and methods of incorporating the embedded secure element into a mobile device for identity authentication, data storage and processing in trusted transactions. These trusted transactions require a high security level to protect sensitive data or programs in bank account management, purchasing orders, contactless payment, passport verification, and many other high-security applications. The secure element will provide a root of trust such that that applications running on the mobile device are executed in a controlled and trusted environment. In addition to conventional password or encryption protection, alternative security features are introduced from both software and hardware levels based on the embedded secure element. Therefore, the security level of the mobile device is not only enhanced, but also may potentially exceed that of the conventional POS terminals.


