qKey Server Context Coupling Secure Element

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional smartcard and SIM card solutions face challenges in securely coupling context to PIN entry and storing assets due to the high cost and limited availability of Finread readers, making them unsuitable for widespread use on devices like tablets.

Innovation Solution

The qKey method tightly couples context and PIN entry by using a secure element with sole control technology, optionally including a second screen, to ensure secure storage and operation of assets, utilizing a qKey server to manage communication and authentication, thereby preventing man-in-the-middle attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Finread readers are used to securely couple context to PIN entry, then security is improved, but cost increases and availability decreases

Engineering Contradiction:
ImprovesecurityVSAvoidcost and availability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces the expensive Finread reader hardware with a software-based qKey solution that replicates the security functionality. The qKey application on the device creates a virtual secure element, copying the security functions of Finread readers without requiring the expensive physical hardware, thereby reducing cost and increasing availability while maintaining security

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes the mechanical/hardware-based Finread reader system with a software-based qKey implementation. By replacing the physical secure reader hardware with a software solution running on standard devices like tablets, the system eliminates the need for expensive specialized hardware while achieving the same security objectives through software-controlled secure element operations

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If context is sent directly to secure element, then security is improved, but device compatibility and scalability are limited

Engineering Contradiction:
ImprovesecurityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces the qKey server as an intermediary component between the device application and the secure element. The qKey API acts as a mediator that receives context from applications, communicates with the secure element, and manages authentication workflows. This intermediary layer enables the secure system to work across different device platforms and configurations without compromising security, as the qKey server handles platform-specific variations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The qKey solution is designed to be universally applicable across multiple device types and platforms. The qKey API provides a standardized interface that works with various secure elements and device configurations, making the solution scalable from tablets to other devices. The modular architecture with qKey server, qKey API, and secure element components can be adapted to different hardware and software environments

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10917242B2Method, a computer program product and a qKEY server
Publication Date: 2021.02.09 UBIQU
  • US10917242B2 patent drawing
  • US10917242B2 patent drawing

AI summary

The invention relates to a method for tightly coupling context to a secure pin and securely storing an asset in hardware. The method comprises a step of sending the context to a secure element, a step of ensuring that the context is shown to a user, and a step of acquiring user consent by performing an authentication check. Further, the method comprises a step of combining an authentication result with the secured context, and a step of performing an operation on the context with the asset if the authentication was successful.