Emulated Integrated Circuit for Secure Transaction Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hardware-based solutions for authentication and secure data storage and transfer are complex, slow to deploy, and fragmented across different devices due to design constraints and hardware incompatibilities, limiting their network effect and market cohesion.

Innovation Solution

A computer-implemented method using an emulated integrated circuit that duplicates the operation of a physical integrated circuit, enabling secure transaction authorization by instantiating an emulator on a host device, configuring a guest operating system to communicate with the host operating system through an emulated network interface, and establishing secure communication channels for user input transformation and verification data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based solutions are used for authentication and secure data storage, then security is improved, but device complexity and deployment time increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of the secure element hardware through software emulation. The virtual secure element replicates the functionality of physical secure elements (HSMs, SEs, SIM cards) in software form, allowing authentication and secure data storage operations without requiring specialized hardware. This copying approach maintains security functionality while eliminating hardware complexity and incompatibility issues.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/hardware-based secure element system with a software-based virtual secure element. Instead of relying on physical integrated circuits with different instruction sets and hardware architectures, the system uses a virtual machine environment that emulates secure element functionality through software, substituting mechanical hardware operations with software-based equivalents.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based solutions are used for authentication, then security is improved, but deployment speed decreases due to manufacturing delays and lead times

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By creating virtual copies of secure elements that can be instantiated as software, the system eliminates the need for physical manufacturing and distribution of hardware secure elements. The virtual secure elements can be deployed instantly through software installation, dramatically accelerating deployment speed while maintaining security through emulated cryptographic operations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual secure element functionality is pre-built as software that can be instantly instantiated when needed. Instead of requiring lead time for hardware manufacturing and provisioning, the system has the emulation environment and secure element software ready in advance, allowing immediate deployment whenever authentication functionality is required.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If different hardware-based secure elements are used across devices, then device-specific security is achieved, but network effect and market cohesion are reduced due to fragmentation

Engineering Contradiction:
ImprovesecurityVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The virtual secure element is designed to provide universal authentication functionality across all devices running compatible operating systems. Instead of device-specific hardware secure elements with different instruction sets and protocols, the virtual implementation provides a unified interface and emulation layer that works consistently across smartphones, tablets, wearables, and other devices, creating a cohesive ecosystem.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The virtual machine environment acts as an intermediary layer between the host device and the secure element functionality. This intermediary emulates the secure element interface and protocols, allowing applications to interact with a standardized secure element API regardless of the underlying host device architecture, thereby unifying the experience across different device types and platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3186743B1System for transaction authentication
Publication Date: 2019.04.10 MAGICCUBE
  • EP3186743B1 patent drawingFigure 1
  • EP3186743B1 patent drawingFigure 2
  • EP3186743B1 patent drawingFigure 3

AI summary

Systems and methods for secure transaction authorization are provided. An emulator is instantiated on a host device and configured to emulate an integrated circuit having a different instruction set than an integrated circuit of the host device, and a guest operating system executing on the emulated integrated circuit is configured to communicate with a host operating system of the host device through an emulated network interface of the emulator. Under control of one or more guest operating system processes executing on the emulated integrated circuit, a request is received over a first secure communication channel from an application executing on the host operating system to authorize a transaction. Further, based on the received request, user input is obtained from an input device of the host device and transformed into verification data. A different second secure communication channel is established to a remote system through the emulated network interface, and a request is sent over the second channel to the remote system to authorize the transaction based on the verification data. An authorization result is received from the remote system over the second secure communication channel, and a response is sent to the application over the first secure communication channel indicating the authorization result.