qKey Server Context Coupling Secure Element
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional smartcard and SIM card solutions face challenges in securely coupling context to PIN entry and storing assets due to the high cost and limited availability of Finread readers, making them unsuitable for widespread use on devices like tablets.
Innovation Solution
The qKey method tightly couples context and PIN entry by using a secure element with sole control technology, optionally including a second screen, to ensure secure storage and operation of assets, utilizing a qKey server to manage communication and authentication, thereby preventing man-in-the-middle attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Finread readers are used to securely couple context to PIN entry, then security is improved, but cost increases and availability decreases
Solution Approach 1:
The patent replaces the expensive Finread reader hardware with a software-based qKey solution that replicates the security functionality. The qKey application on the device creates a virtual secure element, copying the security functions of Finread readers without requiring the expensive physical hardware, thereby reducing cost and increasing availability while maintaining security
Solution Approach 2:
The patent substitutes the mechanical/hardware-based Finread reader system with a software-based qKey implementation. By replacing the physical secure reader hardware with a software solution running on standard devices like tablets, the system eliminates the need for expensive specialized hardware while achieving the same security objectives through software-controlled secure element operations
2Reliability
If context is sent directly to secure element, then security is improved, but device compatibility and scalability are limited
Solution Approach 1:
The patent introduces the qKey server as an intermediary component between the device application and the secure element. The qKey API acts as a mediator that receives context from applications, communicates with the secure element, and manages authentication workflows. This intermediary layer enables the secure system to work across different device platforms and configurations without compromising security, as the qKey server handles platform-specific variations
Solution Approach 2:
The qKey solution is designed to be universally applicable across multiple device types and platforms. The qKey API provides a standardized interface that works with various secure elements and device configurations, making the solution scalable from tablets to other devices. The modular architecture with qKey server, qKey API, and secure element components can be adapted to different hardware and software environments
Data Source
AI summary
The invention relates to a method for tightly coupling context to a secure pin and securely storing an asset in hardware. The method comprises a step of sending the context to a secure element, a step of ensuring that the context is shown to a user, and a step of acquiring user consent by performing an authentication check. Further, the method comprises a step of combining an authentication result with the secured context, and a step of performing an operation on the context with the asset if the authentication was successful.

