Mobile Device Secure Element for Credential Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional mobile communication devices lack secure data storage and transmission methods, making them vulnerable to malicious access, which limits their functionality and potential uses.

Innovation Solution

A mobile communication device equipped with tamper-resistant hardware implementing a secure element for storing credentials, using public-key encryption to secure data transmission, and verifying authorization for functions like unlocking vehicles or premises, ensuring secure operations without exposing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional data storage and transmission methods are used in mobile communication devices, then device simplicity and ease of manufacture are maintained, but security and reliability deteriorate due to data being stored and transmitted in the clear

Engineering Contradiction:
Improvedata securityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the mobile device into two distinct parts: a standard processor for general operations and a separate secure element for secure credential storage and cryptographic operations. This segmentation allows the device to gain security capabilities without compromising the simplicity of the main device architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element acts as an intermediary component that handles sensitive cryptographic operations and credential storage. It mediates between the main processor and external communication channels, providing security functions without requiring the main device architecture to become complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If tamper-resistant hardware with secure elements is added to mobile devices, then security and reliability improve, but device complexity and manufacturing difficulty increase

Engineering Contradiction:
Improveaccess control securityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

By segmenting security functions into a separate secure element, the patent enables independent manufacturing and testing of the secure component. This modular approach simplifies the overall manufacturing process compared to integrating security directly into the main device chip.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element is pre-provisioned with credentials and cryptographic keys during manufacturing before being installed in the mobile device. This preliminary action ensures security is built-in from the start without requiring complex post-manufacturing security configurations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If credentials are stored in a secure element with tamper-resistant hardware, then security against malicious access improves, but the device loses flexibility in data access and processing

Engineering Contradiction:
Improvecredential protectionVSAvoiddata access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secure element serves as an intermediary that selectively provides access to credentials based on authorization. It mediates between the main processor's data access requests and the protected credential storage, granting access only when proper authentication is performed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements dynamic access control where the secure element can change its state between locked and unlocked based on authentication events. This allows the device to be flexible in normal operation while maintaining strict security when credentials are needed.

Inventive Principle:
Principle #15Dynamics

4Reliability

If public key encryption is used to secure credential transmission, then security improves, but processing time and energy consumption increase

Engineering Contradiction:
Improvedata transmission securityVSAvoidprocessing energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments cryptographic operations between the secure element (which handles key storage and private key operations) and the main processor (which handles public key encryption/decryption). This division allows security-critical operations to use energy-efficient hardware-based cryptography while maintaining overall system performance.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9026171B2Access techniques using a mobile communication device
Publication Date: 2015.05.05 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9026171B2 patent drawing
  • US9026171B2 patent drawing
  • US9026171B2 patent drawing

AI summary

Access techniques using a mobile communication device are described. In implementations, a mobile communication device comprises a processor, hardware configured to implement multi-mode wireless communication in which at least one of the modes involves telephone communication, tamper-resistant hardware implementing a secure element as storing one or more credentials, and memory having instructions stored therein. The instructions are executable by the processor to cause the mobile communication device to perform operations comprising forming a communication having data that was generated using the one or more credentials stored in the secure element, the communication to be transmitted wirelessly using the hardware implementing the multi-mode wireless communication to initiate function of a physical lock or vehicle.