Logical Secure Element Isolation on Shared Secure Hardware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile devices face challenges in efficiently managing multiple secure elements from different security service providers due to the inconvenience of physical swapping and increased hardware costs and complexity, particularly when integrating multiple physical slots for secure elements like SIM cards.
Innovation Solution
Implementing a firmware component on a single secure hardware platform to manage multiple logical secure elements (LSEs) through efficient message routing and isolation, using a mapping table and cryptographic keys to enforce security and reduce hardware requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple physical slots for secure elements are integrated into mobile devices, then users can access multiple secure elements from different SSPs simultaneously, but the footprint and hardware complexity increase significantly
Solution Approach 1:
The patent merges multiple secure element functionalities into a single physical secure element hardware platform. The secure element hardware is configured to host multiple logical secure elements (LSEs), each representing a different secure element from different SSPs. This consolidation eliminates the need for multiple physical slots while maintaining the ability to access multiple secure elements through software-based isolation and switching mechanisms.
Solution Approach 2:
The single secure element hardware platform is designed with universal functionality to host and execute multiple logical secure elements. The hardware includes a processor and memory that can dynamically load and switch between different LSEs, allowing one physical component to perform the functions of multiple secure elements from different providers.
2Adaptability or versatility
If multiple physical slots for secure elements are integrated into mobile devices, then users can access multiple secure elements from different SSPs simultaneously, but the hardware complexity and cost increase
Solution Approach 1:
The patent merges multiple secure element functionalities into a single physical secure element hardware platform. The secure element hardware is configured to host multiple logical secure elements (LSEs), each representing a different secure element from different SSPs. This consolidation eliminates the need for multiple physical slots while maintaining the ability to access multiple secure elements through software-based isolation and switching mechanisms.
Solution Approach 2:
The patent creates virtual copies of secure elements in the form of logical secure elements (LSEs) that run on the single hardware platform. Each LSE is a software-based representation of a physical secure element, containing the necessary code and data to emulate the functionality of the original secure element without requiring duplicate hardware.
3Adaptability or versatility
If physical swapping between different secure elements is implemented, then users can change secure elements from different SSPs, but the operation becomes inconvenient and time-consuming
Solution Approach 1:
The patent replaces the mechanical system of physical card swapping with a software-based switching mechanism. The secure element hardware includes a firmware component that manages switching between LSEs through software commands, eliminating the need for users to physically remove and insert cards. The switching is achieved by modifying processor registers and memory mappings to activate different LSEs.
Solution Approach 2:
The patent prepares multiple logical secure elements in advance on the single hardware platform, so they are ready for immediate activation. The LSEs are pre-loaded into the secure element hardware, and the firmware maintains readiness to switch between them quickly without requiring physical intervention or lengthy initialization processes.
4Adaptability or versatility
If physical swapping between different secure elements is implemented, then users can change secure elements from different SSPs, but the risk of misplacing and losing cards increases
Solution Approach 1:
The patent merges multiple secure element functionalities into a single physical secure element hardware platform. The secure element hardware is configured to host multiple logical secure elements (LSEs), each representing a different secure element from different SSPs. This consolidation eliminates the need for multiple physical slots while maintaining the ability to access multiple secure elements through software-based isolation and switching mechanisms.
Solution Approach 2:
The patent creates virtual copies of secure elements in the form of logical secure elements (LSEs) that run on the single hardware platform. Each LSE is a software-based representation of a physical secure element, containing the necessary code and data to emulate the functionality of the original secure element without requiring duplicate hardware.
Data Source
AI summary
Techniques are described herein for applying access controls to logical secure elements (LSEs) running on the same secure element hardware platform. Embodiments include a firmware component that determines whether a message targeting an LSE is authorized to trigger an operation. For example, the firmware component may verify a signature of the received message using a public key, shared secret, or other access control key. Additionally or alternatively, access control policies may be defined to constrain the load of the LSEs on the SE platform hardware and/or to prioritize LSE access. For example, the access control policies may define usage thresholds, such as maximum threshold memory and/or processor utilization rates. As another example, the access controls may restrict the active time for an LSE to a threshold duration. If access constraints are violated or the message cannot be verified, then the firmware component may delay or deny the operation.


