Mobile Terminal Security Token Generation via Secure Element Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile terminal payment systems are vulnerable to attacks due to their continuous connection to telecommunications networks and increasing openness to the operating system, which compromises the security of electronic transactions by making sensitive data more accessible for fraudulent use.

Innovation Solution

A mechanism is established that uses a secure element in the mobile terminal to generate and manage security tokens in collaboration with a token service provider, ensuring secure identification, token generation, and encryption, limiting the tokens' usage to a single transaction and protecting them from malicious interception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the secure element is continuously connected to the telecommunications network and accessed by the operating system, then the ease of operation and functionality are improved, but the security vulnerability increases due to potential malicious attacks

Engineering Contradiction:
Improveaccessibility of secure elementVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the tokenization process into distinct phases: token generation occurs in the secure element when offline, while token usage is managed separately during online transactions. This segmentation isolates the sensitive key generation operations from the vulnerable networked environment, maintaining security while enabling continuous operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element performs preliminary token generation and stores tokens securely before they are needed for transactions. By pre-generating tokens in the protected offline environment and storing them securely, the system prepares authentication credentials in advance without exposing them to network vulnerabilities, yet maintains readiness for immediate use when needed.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If sensitive data is exchanged during electronic transactions over the network, then the functionality and convenience are improved, but the risk of data interception and fraudulent use increases

Engineering Contradiction:
Improveconvenience of electronic transactionVSAvoiddata interception risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent creates a copy of the authentication mechanism by generating tokens that represent sensitive data without transmitting the actual sensitive data itself. The secure element generates tokens that can be used in place of card numbers or other sensitive information, allowing transactions to proceed with token copies rather than exposing the original sensitive data over the network.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces tokens as an intermediary element between the sensitive data and the transaction processing system. Instead of directly exchanging sensitive data over the network, the system uses tokens as mediators that carry the necessary authentication information while protecting the underlying sensitive data from exposure during transmission and processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the EMV protocol is executed end-to-end using the secure element, then the security framework is established, but the device complexity increases due to implementation requirements

Engineering Contradiction:
Improvesecurity frameworkVSAvoidprotocol implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the most security-critical portion of the EMV protocol (token generation using secret keys) and confines it exclusively to the secure element. By removing the key generation and sensitive cryptographic operations from the general processing environment and placing them only in the protected secure element, the system maintains strong security foundations while simplifying the overall implementation architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11922384B2Method for obtaining a security token by a mobile terminal
Publication Date: 2024.03.05 ORANGE SA
  • US11922384B2 patent drawing
  • US11922384B2 patent drawing
  • US11922384B2 patent drawing

AI summary

The method of the invention comprises:an identification step (E30-E50) of identifying the user of the mobile terminal;a generation step, triggered if identification is successful, of a secure element of the terminal generating (E70) at least one identification value for the terminal by using a first secret key shared between the secure element and a token service provider device;a sending step (E100) of sending a request to the token service provider device to obtain at least one security token, the request including said at least one identification value for the terminal; anda reception step (F90) of receiving from the token service provider device said at least one security token in encrypted form, each security token being associated with a random number generated by the token service provider device and being encrypted by means of an encryption key generated for that token from the random number and from a second secret key shared between the token service provider device and the secure element of the terminal.