Secure Domain Digital Key Management via Segmented Instances
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for a method to manage digital keys in an integrated manner across businesses to improve interoperability and enhance security.
Innovation Solution
The method involves a secure domain in an electronic device transmitting a certificate to multiple service providers, receiving certificates from them, authenticating signed data, decrypting encrypted keys, and storing them in separate instances for each service provider.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If digital keys are integrated into mobile devices using wireless communication technology, then user convenience is improved, but security risks increase due to potential hacking of the electronic device
Solution Approach 1:
The system divides digital key management into separate instances within the secure domain, where each service provider has its own isolated instance. This segmentation prevents a security breach in one instance from compromising other instances, thereby maintaining security while enabling multiple digital key functions in a single device.
Solution Approach 2:
The patent introduces a secure domain as an intermediary layer between the application and the digital keys. The secure domain acts as a trusted mediator that manages key generation, storage, and access control, preventing direct access to keys and reducing security risks while maintaining user convenience.
2Reliability
If digital keys are managed individually by different businesses, then each business can maintain its own security standards, but interoperability between different service providers deteriorates
Solution Approach 1:
The secure domain is designed as a universal platform that can host multiple instances for different service providers. Each instance maintains its own security policies and key management methods, while the overall secure domain provides a unified interface for interoperability across different businesses and services.
Solution Approach 2:
The patent introduces a new dimensional structure by organizing digital keys in a multi-instance architecture within the secure domain. This dimensional organization allows each business to operate independently in its own instance while the secure domain provides the overarching framework for cross-business interoperability.
3Device complexity
If multiple digital keys are stored in the same secure area, then device complexity is reduced, but the risk of key exposure increases
Solution Approach 1:
The secure area is segmented into multiple isolated instances, each containing digital keys for specific service providers. This segmentation maintains relatively simple device architecture while preventing key exposure risk by ensuring that compromise of one instance does not affect other instances.
Data Source
Figure 1~2
Figure 3~4a
Figure 4b
AI summary
Provided is a method performed by a first electronic device, for managing keys for accessing a plurality of services, the method comprising: creating a plurality of instances corresponding to each of a plurality of service providers (SPs) in an applet, wherein the applet is installed in a security domain (SD); storing a data for a secure channel to an instance, the instance being used to a service provider (SP), wherein the data is received from the service provider; generating a ultra wide band (UWB) session key for a second electronic device based on the stored data; generating a scrambled timestamp sequence (STS) based on the UWB session key; and performing a secure ranging using the STS.