Virtualized Secure Partition for NFC in Mobile Processors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile devices typically support only one secure element for near field communication (NFC) transactions, limiting flexibility and security, as the secure element resides on a separate hardware chip, restricting access and requiring a secure key for initialization.
Innovation Solution
A system and method for configuring a secure partition in a trusted security zone within the mobile device's processor, utilizing virtualization software and a near field communication transceiver to enable multiple secure partitions without a separate secure element chip, ensuring secure storage and execution through a trusted execution environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate secure element chip is used for NFC transactions, then security is ensured through hardware isolation, but device complexity increases and flexibility is limited to single secure element support
Solution Approach 1:
The patent merges the secure element functionality with the main processor by implementing a secure partition within the processor's memory space. Instead of using a separate secure element chip, the secure element is virtualized as a partition in the processor's address space, allowing multiple secure elements to coexist within a single processor without requiring additional hardware chips.
Solution Approach 2:
The processor is designed to universally support multiple secure elements through virtualization. The processor can dynamically allocate and manage multiple secure partitions, each functioning as an independent secure element, thereby providing multi-functionality where a single processor handles what traditionally required multiple separate hardware components.
2Reliability
If a separate secure element chip is used, then secure storage is provided, but adaptability is reduced to supporting only one secure element
Solution Approach 1:
The processor's address space is segmented into multiple secure partitions, each representing an independent secure element. This segmentation allows the system to support multiple secure elements by dividing the processor's memory space into isolated segments, where each segment can store credentials and execute secure applications independently while maintaining the security properties of separate hardware elements.
Solution Approach 2:
The patent transitions from a hardware-dimension solution (separate physical chips) to a software/virtualization dimension solution. By implementing secure elements as virtual partitions in the processor's address space rather than as separate physical hardware components, the system gains the ability to support multiple secure elements without increasing physical hardware complexity.
3Adaptability or versatility
If multiple secure elements are supported through separate chips, then security and storage are improved, but device complexity and cost increase
Solution Approach 1:
Multiple secure element functionalities are merged into a single processor through virtualization. Instead of requiring multiple separate secure element chips, the processor combines multiple secure element instances as virtual partitions, reducing hardware complexity while maintaining the ability to support multiple secure elements simultaneously.
Data Source
AI summary
A system on a mobile phone for configuring a secure partition in a trusted security zone is provided. The system comprises a processor and a near field communication transceiver. The processor executes virtualization software and comprises a first virtual processor and a second virtual processor, where the second virtual processor comprises the trusted security zone and the secure partition resides in the trusted security zone. The first virtual processor comprises an application which utilizes the secure partition in the trusted security zone. The second virtual processor comprises an application stored in the trusted security zone, where the application couples the near field communication transceiver to the secure partition residing in the trusted security zone and where the application enables run-time execution in the trusted security zone based on the receiving a signal from the near field communication transceiver.


