Secure Element OS Centralized Management via Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mobile communication systems face challenges in uniformly configuring and managing secure elements (SEs) like SIM cards, leading to increased processor resource consumption, safety hazards due to independent interactions, and decreased operational convenience for adding or deleting SEs.

Innovation Solution

A secure element operating system with a configurator and protocol converter inside the mobile device, which communicates with SEs via a list for information management, verification, and interaction, and a management backstage for interfacing with a trusted service management platform to control SE operations, including addition, verification, inquiry, and deletion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional mobile communication systems manage secure elements independently, then each SE can operate autonomously, but processor resource consumption increases and safety hazards arise

Engineering Contradiction:
ImprovesafetyVSAvoidprocessor resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces an SE manager as an intermediary component that centralizes the management of multiple secure elements. The SE manager handles configuration, resource allocation, and coordination between SEs, replacing the previous model where each SE operated independently. This intermediary structure reduces processor resource consumption by consolidating management functions while improving safety through centralized control and monitoring of all SE operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If secure elements are managed independently without unified configuration, then SE operations can be simple, but operational convenience decreases when adding or deleting SEs

Engineering Contradiction:
Improveoperational convenienceVSAvoidconfiguration management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal SE manager that provides multi-functional capabilities for managing different types of secure elements (SIM cards, smart SD cards, etc.). The SE manager offers unified interfaces and standardized procedures for adding, configuring, verifying, and deleting SEs, regardless of their specific type. This universal approach improves operational convenience by providing consistent user experience while managing the complexity internally through standardized protocols and centralized control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure elements interact with the device independently, then SE autonomy is maintained, but safety hazards increase

Engineering Contradiction:
ImprovesafetyVSAvoidSE autonomy
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a feedback mechanism where the SE manager continuously monitors and coordinates SE operations. The SE manager receives status information from SEs, verifies their operations, and provides guidance or restrictions as needed. This feedback loop maintains SE autonomy for core security functions while ensuring safety through centralized oversight. The SE manager can verify SE identities, control resource access, and coordinate interactions between multiple SEs, thereby maintaining both autonomy and safety.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3001768B1Secure element (SE) operating system and method
Publication Date: 2019.10.16 CHINA UNIONPAY
  • EP3001768B1 patent drawingFigure 1~2

AI summary

The invention discloses a secure element (SE) operating system and method. The system comprises a SE configurator and a protocol converter disposed inside a mobile communication device, wherein the SE configurator communicates with one or more SEs on the mobile communication device via the protocol converter, and the SE configurator comprises a SE list for storing information on said one or more SEs.