Manager Secure Element for Multi-SE Payload Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional solutions for managing multiple secure elements on smartcards rely on the mobile device's CPU, which provides limited management capabilities and is vulnerable to OS attacks, lacking support for operations like applet removal, update, or transfer between elements, and do not offer a high security level for security-critical applications.
Innovation Solution
A dedicated manager secure element is introduced, connected to other secure elements, equipped with a database for authentication, an operating system for comprehensive management, and interfaces for secure communication, enabling direct interaction and control over applets, authentication, and secure routing of payloads, thus enhancing security and functionality beyond conventional routing capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the mobile device's CPU is used to manage secure elements, then routing capabilities are provided, but management capabilities are restricted and security level is insufficient
Solution Approach 1:
A manager secure element is introduced as an intermediary component between the CPU and the secure elements. This manager SE provides enhanced security by authenticating payloads before routing them to the appropriate secure element, while the CPU retains its routing function. The manager SE acts as a security gateway that verifies authentication information and controls access to secure elements, thereby resolving the contradiction between maintaining routing ease and improving security reliability.
2Ease of operation
If the CPU provides routing capabilities, then payload routing is enabled, but applet management operations are not supported
Solution Approach 1:
The manager secure element is designed with multi-functionality to handle both routing and applet management operations. It can authenticate payloads for routing, perform authentication of secure elements, manage applet installation and updates, and control access to secure elements. This universal component consolidates multiple functions that were previously分散 between the CPU and secure elements, enabling both routing ease and comprehensive applet management versatility.
3Device complexity
If conventional CPU-based management is used, then system simplicity is maintained, but security vulnerabilities to OS attacks exist
Solution Approach 1:
The system is segmented into distinct functional components: the CPU handles high-level routing decisions, while the manager secure element handles security-critical operations such as authentication and payload verification. This segmentation isolates security functions from the general-purpose CPU, creating a dedicated security domain that is resistant to OS attacks. The manager SE maintains its own secure environment with dedicated authentication mechanisms, thereby improving security reliability without significantly increasing overall system complexity.
Data Source
Figure 1(a)
Figure 1(b)
Figure 2
AI summary
The present invention relates to methods and devices for managing a plurality of secure elements and routing payloads to secure elements. A manager secure element is provided on a device, such as a smartcard. The manager secure element is connected to a plurality of secure elements residing on the mobile device via at least one communication channel. The manager SE is configured to manage the plurality of secure elements, and to route payload received from an external device to a selected one of the plurality of secure elements.