Dual Secure-Element Device Access Control Against Unauthorized Use
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for protecting devices from theft or loss are often dependent on user activation and may not effectively prevent unauthorized use, especially for non-communication devices, as they require network connectivity and account-based tracking methods that can be circumvented.
Innovation Solution
A system comprising a first control module with a modem for wireless communication and a secure element, and a second secure element for authentication, which sets a usability state based on communication between the two elements, inhibiting the device's operation if not authenticated, thereby partially or fully disabling it.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing password based solutions are used to protect a device, then the device is protected to some extent, but the protection can be overcome and does not provide robust security
Solution Approach 1:
The authentication system is segmented into multiple independent components: a first secure element (SE1) that cannot be extracted from the device, and a second secure element (SE2) that can be extracted. The device requires both SE1 and SE2 to be present and communicating for full operation, creating a multi-layered security architecture that goes beyond simple passwords
2Reliability
If existing tracking solutions using accounts and connectivity are implemented, then device tracking is enabled, but the solutions are dependent on many prerequisites and can be circumvented
Solution Approach 1:
The second secure element (SE2) is designed to be extractable from the device, allowing it to be removed and used in another device. This extraction capability enables the authentication system to function without requiring continuous network connectivity or account-based tracking infrastructure, simplifying the operational prerequisites
3Adaptability or versatility
If a security module requires network connectivity for authentication, then remote authentication is enabled, but the device cannot function as a stand-alone unit
Solution Approach 1:
The first secure element (SE1) acts as an intermediary that enables local authentication between the device and the second secure element (SE2). SE1 cannot be extracted and remains in the device, providing a trusted local authentication mechanism that does not require network connectivity, while still allowing the device to function as a stand-alone unit
4Ease of operation
If the device is fully usable when lost or stolen, then the owner can access information, but the device will probably not be returned to its rightful owner
Solution Approach 1:
The system implements preliminary anti-action by requiring both secure elements to be present and authenticated for the device to function. If one secure element is removed or the device is stolen, the authentication fails and the device becomes inoperable, preventing unauthorized use and increasing the likelihood of recovery
Data Source
Figure 1~2
Figure 3
AI summary
System for controlling usability of an electronic device (1), which host device comprises a processing unit (2), the system comprising a first control module (10), connected to the processing unit, said first control module comprising a modem (11) for communicating with a cellular network, and an access circuit (101) connected to the modem for cellular network access, which access circuit comprises a first secure element (12); a second control module (41) comprising a second secure element (411), configured to communicate with the first secure element over a communication link; wherein said access unit is configured to realize a state machine configured to set a usability state dependent on communication between the first secure element and the second secure element, and to control the device in accordance with said usability state.