Secure Element Applet Access Isolation for External Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for managing access to secure elements in user devices, such as mobile phones, fail to ensure secure and differentiated access for external applications, leading to potential unauthorized access and complexity in deployment.

Innovation Solution

A secure element with a first security applet that allows external applications to register and become local administrators, granting permission-based access to their own data, with optional token authorization, ensuring secure messaging sessions and compartmentalized storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If external applications are granted access to the SE using GlobalPlatform Secure Element Access, then applications can communicate with the SE, but any data may be accessed by third parties without fine-grained control

Engineering Contradiction:
Improveaccess capabilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements fine-grained access control where each external application is granted permission to access only its own specific data (local quality) rather than all data in the SE. The security applet distinguishes between different applications and their respective data, ensuring that application A can access only data A while being blocked from data B, thus resolving the contradiction between ease of access and data security.

Inventive Principle:
Principle #3Local quality

2Reliability

If Secure Channel Protocols are used with keys stored in the Security Domain, then communication is ciphered, but any authenticated application can access any SE Applet data

Engineering Contradiction:
Improvecommunication securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the Security Domain into multiple isolated data spaces, each associated with a specific external application. Instead of a single SD controlling all SE Applets, the system creates application-specific security contexts that allow each application to authenticate only to its own data. This segmentation resolves the contradiction by maintaining communication security through authentication while preventing unauthorized access to other applications' data.

Inventive Principle:
Principle #1Segmentation

3Reliability

If multiple Security Domains are created to isolate SE Applications, then illegal access from different applications is avoided, but deployment becomes more complicated

Engineering Contradiction:
Improveaccess isolationVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent enables external applications to self-register and obtain their own security contexts without requiring complex pre-deployment configuration by the service provider. The system allows applications to autonomously establish their security domains and authenticate to the SE, eliminating the need for manual SD key distribution and reducing deployment complexity while maintaining access isolation.

Inventive Principle:
Principle #25Self-service

4Ease of manufacture

If SD keys are distributed through third-party TSM entities, then key management is facilitated, but service providers may not trust that keys have passed through secure channels

Engineering Contradiction:
Improvekey distributionVSAvoidkey security trust
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent extracts the key distribution function from third-party TSM entities and implements it directly within the secure element system. Service providers can directly provision security contexts and keys to their own applications without intermediary TSMs, eliminating the trust issue while maintaining ease of key management. The SE itself manages the secure distribution of cryptographic material to authenticated applications.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12619771B2Secure element for a device
Publication Date: 2026.05.05 THALES DIS FRANCE SA
  • US12619771B2 patent drawing
  • US12619771B2 patent drawing
  • US12619771B2 patent drawing

AI summary

A secure element for a device includes an operative system the secure element including a first security applet configure to communicate with the device operative system, wherein the first security applet is configure to accept any first external application, after performing a key registration, as a local administrator application for some first data provided by the first external application, so that no other external application may access the first data without a permission of the first external application. The disclosure also provides a telecommunications device and a method of management of secure information in such a secure element.