Dual Secure-Element Device Access Control Against Unauthorized Use

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for protecting devices from theft or loss are often dependent on user activation and may not effectively prevent unauthorized use, especially for non-communication devices, as they require network connectivity and account-based tracking methods that can be circumvented.

Innovation Solution

A system comprising a first control module with a modem for wireless communication and a secure element, and a second secure element for authentication, which sets a usability state based on communication between the two elements, inhibiting the device's operation if not authenticated, thereby partially or fully disabling it.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing password based solutions are used to protect a device, then the device is protected to some extent, but the protection can be overcome and does not provide robust security

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication robustness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system is segmented into multiple independent components: a first secure element (SE1) that cannot be extracted from the device, and a second secure element (SE2) that can be extracted. The device requires both SE1 and SE2 to be present and communicating for full operation, creating a multi-layered security architecture that goes beyond simple passwords

Inventive Principle:
Principle #1Segmentation

2Reliability

If existing tracking solutions using accounts and connectivity are implemented, then device tracking is enabled, but the solutions are dependent on many prerequisites and can be circumvented

Engineering Contradiction:
Improvedevice tracking capabilityVSAvoidprerequisites for operation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The second secure element (SE2) is designed to be extractable from the device, allowing it to be removed and used in another device. This extraction capability enables the authentication system to function without requiring continuous network connectivity or account-based tracking infrastructure, simplifying the operational prerequisites

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If a security module requires network connectivity for authentication, then remote authentication is enabled, but the device cannot function as a stand-alone unit

Engineering Contradiction:
Improveremote authentication capabilityVSAvoidstand-alone operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The first secure element (SE1) acts as an intermediary that enables local authentication between the device and the second secure element (SE2). SE1 cannot be extracted and remains in the device, providing a trusted local authentication mechanism that does not require network connectivity, while still allowing the device to function as a stand-alone unit

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If the device is fully usable when lost or stolen, then the owner can access information, but the device will probably not be returned to its rightful owner

Engineering Contradiction:
Improvedevice accessibilityVSAvoiddevice recovery probability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements preliminary anti-action by requiring both secure elements to be present and authenticated for the device to function. If one secure element is removed or the device is stolen, the authentication fails and the device becomes inoperable, preventing unauthorized use and increasing the likelihood of recovery

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3560160B1Modular system for controlling usability of a device
Publication Date: 2022.02.09 SONY GROUP CORP
  • EP3560160B1 patent drawingFigure 1~2
  • EP3560160B1 patent drawingFigure 3

AI summary

System for controlling usability of an electronic device (1), which host device comprises a processing unit (2), the system comprising a first control module (10), connected to the processing unit, said first control module comprising a modem (11) for communicating with a cellular network, and an access circuit (101) connected to the modem for cellular network access, which access circuit comprises a first secure element (12); a second control module (41) comprising a second secure element (411), configured to communicate with the first secure element over a communication link; wherein said access unit is configured to realize a state machine configured to set a usability state dependent on communication between the first secure element and the second secure element, and to control the device in accordance with said usability state.