Logical Secure Element Isolation on Shared SIM Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices face challenges in efficiently supporting multiple secure elements from different Security Service Providers (SSPs) without increasing hardware footprint and cost, as physically swapping secure elements is inconvenient and risky, and integrating multiple physical slots is costly and complex.

Innovation Solution

Implementing a firmware component on a single secure hardware platform to manage and isolate multiple logical secure elements (LSEs), using a mapping table and cryptographic keys to route messages and enforce security, allowing multiple LSEs to run without additional hardware resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple physical secure element slots are integrated into mobile devices to support multiple secure elements from different SSPs, then the device can access multiple security services simultaneously, but the hardware footprint and manufacturing cost increase significantly

Engineering Contradiction:
Improveability to access multiple security servicesVSAvoidhardware footprint
Core Design Contradiction:
Adaptability or versatilityVSArea of stationary object

Solution Approach 1:

The patent combines multiple logical secure elements onto a single physical secure element hardware platform. The firmware layer virtualizes the secure element functionality, allowing multiple LSEs to share the same physical hardware resources including processor, memory, and cryptographic modules, thereby eliminating the need for multiple physical slots while maintaining the ability to access multiple security services

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single physical secure element hardware platform is designed to universally support multiple logical secure elements from different SSPs. The firmware component provides a universal interface that can load, manage, and switch between different LSEs, making the hardware platform multi-functional and adaptable to various security service requirements without requiring dedicated hardware for each SSP

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple physical secure element slots are integrated into mobile devices, then users can physically swap between different secure elements, but the device complexity and manufacturing cost increase

Engineering Contradiction:
Improveability to swap secure elementsVSAvoidhardware design complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of secure elements in the form of LSEs that run on the firmware layer of a single physical platform. Instead of providing multiple physical slots that require mechanical swapping, the system creates software-based representations of secure elements that can be loaded, activated, and switched through firmware management, dramatically simplifying the hardware design while maintaining the functional capability of supporting multiple secure elements

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If physical secure element cards are swapped frequently by users, then different security services can be accessed, but the risk of misplacing and losing cards increases

Engineering Contradiction:
Improveability to access different servicesVSAvoidsecurity service availability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges multiple secure element functionalities into a single integrated system where multiple LSEs reside on one physical platform. Users no longer need to physically swap cards to access different security services; instead, the firmware manages the switching between LSEs electronically, ensuring that all security services remain continuously available and eliminating the risk of losing physical cards

Inventive Principle:
Principle #5Merging (Combining)

4Area of stationary object

If a single physical secure element hardware platform supports multiple logical secure elements, then hardware footprint is reduced, but firmware complexity increases to manage isolation and switching

Engineering Contradiction:
Improvehardware footprintVSAvoidfirmware complexity
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The firmware component segments the management of multiple LSEs through structured organization of cryptographic keys, isolation mechanisms, and switching logic. Each LSE is managed as a distinct logical unit with its own key hierarchy and access controls, while the firmware provides a systematic framework for handling isolation and switching, making the complexity manageable through modular design

Inventive Principle:
Principle #1Segmentation

5Reliability

If multiple logical secure elements run on the same hardware, then security isolation between LSEs must be enforced, but additional cryptographic key management is required

Engineering Contradiction:
Improvesecurity isolationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The firmware implements segmentation of cryptographic key management by maintaining separate key hierarchies for each LSE. Each logical secure element has its own isolated key store and cryptographic operations are performed within the context of the active LSE, ensuring that keys from one LSE cannot be accessed by another. This segmented approach enforces security isolation while managing key complexity through structured organization

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12538130B2Systems and methods for running multiple logical secure elements on the same secure hardware
Publication Date: 2026.01.27 ORACLE INT CORP
  • US12538130B2 patent drawing
  • US12538130B2 patent drawing
  • US12538130B2 patent drawing

AI summary

Techniques are described herein for running multiple logical secure elements (LSEs) on the same physical secure element (SE) hardware. For example, embodiments may include running multiple logical Subscriber Identification Modules (SIM) cards on the same physical SIM card or universal integrated circuit card (UICC). Additionally or alternatively, embodiments may include running other secure element applications and services on the same SE hardware. The techniques allow for mobile devices users to access multiple security services, which may originate from different security service providers (SSPs), in a secure manner using the same SE hardware without requiring the integration of multiple physical slots on a mobile device or the physical exchange of different cards within the same slot.