Secure Domain Digital Key Management via Segmented Instances

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a method to manage digital keys in an integrated manner across businesses to improve interoperability and enhance security.

Innovation Solution

The method involves a secure domain in an electronic device transmitting a certificate to multiple service providers, receiving certificates from them, authenticating signed data, decrypting encrypted keys, and storing them in separate instances for each service provider.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital keys are integrated into mobile devices using wireless communication technology, then user convenience is improved, but security risks increase due to potential hacking of the electronic device

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides digital key management into separate instances within the secure domain, where each service provider has its own isolated instance. This segmentation prevents a security breach in one instance from compromising other instances, thereby maintaining security while enabling multiple digital key functions in a single device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure domain as an intermediary layer between the application and the digital keys. The secure domain acts as a trusted mediator that manages key generation, storage, and access control, preventing direct access to keys and reducing security risks while maintaining user convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital keys are managed individually by different businesses, then each business can maintain its own security standards, but interoperability between different service providers deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidinteroperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secure domain is designed as a universal platform that can host multiple instances for different service providers. Each instance maintains its own security policies and key management methods, while the overall secure domain provides a unified interface for interoperability across different businesses and services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a new dimensional structure by organizing digital keys in a multi-instance architecture within the secure domain. This dimensional organization allows each business to operate independently in its own instance while the secure domain provides the overarching framework for cross-business interoperability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Device complexity

If multiple digital keys are stored in the same secure area, then device complexity is reduced, but the risk of key exposure increases

Engineering Contradiction:
Improvedevice complexityVSAvoidkey exposure risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The secure area is segmented into multiple isolated instances, each containing digital keys for specific service providers. This segmentation maintains relatively simple device architecture while preventing key exposure risk by ensuring that compromise of one instance does not affect other instances.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4312448B1Method and electronic device for managing digital keys
Publication Date: 2025.04.30 SAMSUNG ELECTRONICS CO LTD
  • EP4312448B1 patent drawingFigure 1~2
  • EP4312448B1 patent drawingFigure 3~4a
  • EP4312448B1 patent drawingFigure 4b

AI summary

Provided is a method performed by a first electronic device, for managing keys for accessing a plurality of services, the method comprising: creating a plurality of instances corresponding to each of a plurality of service providers (SPs) in an applet, wherein the applet is installed in a security domain (SD); storing a data for a secure channel to an instance, the instance being used to a service provider (SP), wherein the data is received from the service provider; generating a ultra wide band (UWB) session key for a second electronic device based on the stored data; generating a scrambled timestamp sequence (STS) based on the UWB session key; and performing a secure ranging using the STS.