Logical Secure Element Isolation on Shared SIM Hardware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices face challenges in efficiently supporting multiple secure elements from different Security Service Providers (SSPs) without increasing hardware footprint and cost, as physically swapping secure elements is inconvenient and risky, and integrating multiple physical slots is costly and complex.
Innovation Solution
Implementing a firmware component on a single secure hardware platform to manage and isolate multiple logical secure elements (LSEs), using a mapping table and cryptographic keys to route messages and enforce security, allowing multiple LSEs to run without additional hardware resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple physical secure element slots are integrated into mobile devices to support multiple secure elements from different SSPs, then the device can access multiple security services simultaneously, but the hardware footprint and manufacturing cost increase significantly
Solution Approach 1:
The patent combines multiple logical secure elements onto a single physical secure element hardware platform. The firmware layer virtualizes the secure element functionality, allowing multiple LSEs to share the same physical hardware resources including processor, memory, and cryptographic modules, thereby eliminating the need for multiple physical slots while maintaining the ability to access multiple security services
Solution Approach 2:
The single physical secure element hardware platform is designed to universally support multiple logical secure elements from different SSPs. The firmware component provides a universal interface that can load, manage, and switch between different LSEs, making the hardware platform multi-functional and adaptable to various security service requirements without requiring dedicated hardware for each SSP
2Adaptability or versatility
If multiple physical secure element slots are integrated into mobile devices, then users can physically swap between different secure elements, but the device complexity and manufacturing cost increase
Solution Approach 1:
The patent creates virtual copies of secure elements in the form of LSEs that run on the firmware layer of a single physical platform. Instead of providing multiple physical slots that require mechanical swapping, the system creates software-based representations of secure elements that can be loaded, activated, and switched through firmware management, dramatically simplifying the hardware design while maintaining the functional capability of supporting multiple secure elements
3Adaptability or versatility
If physical secure element cards are swapped frequently by users, then different security services can be accessed, but the risk of misplacing and losing cards increases
Solution Approach 1:
The patent merges multiple secure element functionalities into a single integrated system where multiple LSEs reside on one physical platform. Users no longer need to physically swap cards to access different security services; instead, the firmware manages the switching between LSEs electronically, ensuring that all security services remain continuously available and eliminating the risk of losing physical cards
4Area of stationary object
If a single physical secure element hardware platform supports multiple logical secure elements, then hardware footprint is reduced, but firmware complexity increases to manage isolation and switching
Solution Approach 1:
The firmware component segments the management of multiple LSEs through structured organization of cryptographic keys, isolation mechanisms, and switching logic. Each LSE is managed as a distinct logical unit with its own key hierarchy and access controls, while the firmware provides a systematic framework for handling isolation and switching, making the complexity manageable through modular design
5Reliability
If multiple logical secure elements run on the same hardware, then security isolation between LSEs must be enforced, but additional cryptographic key management is required
Solution Approach 1:
The firmware implements segmentation of cryptographic key management by maintaining separate key hierarchies for each LSE. Each logical secure element has its own isolated key store and cryptographic operations are performed within the context of the active LSE, ensuring that keys from one LSE cannot be accessed by another. This segmented approach enforces security isolation while managing key complexity through structured organization
Data Source
AI summary
Techniques are described herein for running multiple logical secure elements (LSEs) on the same physical secure element (SE) hardware. For example, embodiments may include running multiple logical Subscriber Identification Modules (SIM) cards on the same physical SIM card or universal integrated circuit card (UICC). Additionally or alternatively, embodiments may include running other secure element applications and services on the same SE hardware. The techniques allow for mobile devices users to access multiple security services, which may originate from different security service providers (SSPs), in a secure manner using the same SE hardware without requiring the integration of multiple physical slots on a mobile device or the physical exchange of different cards within the same slot.


