Mobile Device Secure Element for Credential Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional mobile communication devices lack secure data storage and transmission methods, making them vulnerable to malicious access, which limits their functionality and potential uses.
Innovation Solution
A mobile communication device equipped with tamper-resistant hardware implementing a secure element for storing credentials, using public-key encryption to secure data transmission, and verifying authorization for functions like unlocking vehicles or premises, ensuring secure operations without exposing sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional data storage and transmission methods are used in mobile communication devices, then device simplicity and ease of manufacture are maintained, but security and reliability deteriorate due to data being stored and transmitted in the clear
Solution Approach 1:
The patent segments the mobile device into two distinct parts: a standard processor for general operations and a separate secure element for secure credential storage and cryptographic operations. This segmentation allows the device to gain security capabilities without compromising the simplicity of the main device architecture.
Solution Approach 2:
The secure element acts as an intermediary component that handles sensitive cryptographic operations and credential storage. It mediates between the main processor and external communication channels, providing security functions without requiring the main device architecture to become complex.
2Reliability
If tamper-resistant hardware with secure elements is added to mobile devices, then security and reliability improve, but device complexity and manufacturing difficulty increase
Solution Approach 1:
By segmenting security functions into a separate secure element, the patent enables independent manufacturing and testing of the secure component. This modular approach simplifies the overall manufacturing process compared to integrating security directly into the main device chip.
Solution Approach 2:
The secure element is pre-provisioned with credentials and cryptographic keys during manufacturing before being installed in the mobile device. This preliminary action ensures security is built-in from the start without requiring complex post-manufacturing security configurations.
3Reliability
If credentials are stored in a secure element with tamper-resistant hardware, then security against malicious access improves, but the device loses flexibility in data access and processing
Solution Approach 1:
The secure element serves as an intermediary that selectively provides access to credentials based on authorization. It mediates between the main processor's data access requests and the protected credential storage, granting access only when proper authentication is performed.
Solution Approach 2:
The system implements dynamic access control where the secure element can change its state between locked and unlocked based on authentication events. This allows the device to be flexible in normal operation while maintaining strict security when credentials are needed.
4Reliability
If public key encryption is used to secure credential transmission, then security improves, but processing time and energy consumption increase
Solution Approach 1:
The patent segments cryptographic operations between the secure element (which handles key storage and private key operations) and the main processor (which handles public key encryption/decryption). This division allows security-critical operations to use energy-efficient hardware-based cryptography while maintaining overall system performance.
Data Source
AI summary
Access techniques using a mobile communication device are described. In implementations, a mobile communication device comprises a processor, hardware configured to implement multi-mode wireless communication in which at least one of the modes involves telephone communication, tamper-resistant hardware implementing a secure element as storing one or more credentials, and memory having instructions stored therein. The instructions are executable by the processor to cause the mobile communication device to perform operations comprising forming a communication having data that was generated using the one or more credentials stored in the secure element, the communication to be transmitted wirelessly using the hardware implementing the multi-mode wireless communication to initiate function of a physical lock or vehicle.


