Modular Kernel Arrangement Secure Element Recertification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy approaches to data transfer using secure elements require recertification of all kernels when any kernel is changed, leading to unnecessary time and financial costs, as core signatures for all kernels are affected, whereas only the changed kernel should require recertification.

Innovation Solution

The implementation of a secure element with modular kernels, where virtual kernel identifiers manage connections and updates without affecting other kernels' core signatures, allowing only the changed kernel to require recertification, utilizing an entry point that assigns unique identifiers and manages kernel operations independently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all kernels are recertified when any kernel is changed, then security certification is maintained across the entire system, but recertification time and costs increase unnecessarily

Engineering Contradiction:
Improvesecurity certificationVSAvoidrecertification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the kernel certification process by introducing unique identifiers that allow individual kernels to be independently tracked and recertified. Instead of treating all kernels as a monolithic system requiring full recertification, each kernel can be separately identified, updated, and recertified based on its own changes, thereby reducing unnecessary recertification time and costs while maintaining security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If all kernels are recertified when any kernel is changed, then system-wide security is ensured, but financial costs increase unnecessarily

Engineering Contradiction:
Improvesystem-wide securityVSAvoidrecertification cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent divides the certification system into independently identifiable segments using unique identifiers for each kernel. This allows the certification authority to recertify only the specific kernel that has been modified rather than requiring recertification of the entire kernel set, thereby reducing financial costs while maintaining system-wide security through targeted recertification of affected components.

Inventive Principle:
Principle #1Segmentation

3Reliability

If core signatures for all kernels are affected by any kernel change, then comprehensive security validation is achieved, but processing complexity increases

Engineering Contradiction:
Improvesecurity validationVSAvoidcertification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces unique identifiers that segment the core signature validation process. Instead of requiring comprehensive re-validation of all kernels when one kernel changes, the system can identify and validate only the specific kernel with the changed core signature. This reduces processing complexity while maintaining comprehensive security validation for the affected kernel.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces unique identifiers as intermediaries between kernel changes and certification validation. These identifiers act as mediators that allow the certification authority to efficiently track which specific kernels have changed and require recertification, simplifying the overall certification process complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240403102A1Modular kernel arrangement
Publication Date: 2024.12.05 APPLE INC
  • US20240403102A1 patent drawing
  • US20240403102A1 patent drawing
  • US20240403102A1 patent drawing

AI summary

The present application relates to devices and components including apparatus, systems, and methods to manage kernels within a secure element for performance of a data transfer.