Secure Element Access Right Code Generation for Trusted Application Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure elements like SmartMX devices restrict trusted applications from accessing other installed applications, limiting the development of new NFC services by preventing access to sensitive APIs, even for Service Providers trying to provide their own trusted applications.

Innovation Solution

A method where the Service Provider requests an access right code from the Trusted Service Manager, which is then used by the wallet application to gain access to its own applications stored in the secure element, while maintaining security by preventing access to other Service Providers' applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the service manager restricts access to stored applications, then security is improved, but the ability of trusted applications to access their own applications deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating access rights based on the relationship between applications. The service manager evaluates whether a trusted application belongs to the same service provider as the stored application, and grants access selectively based on this local classification. This allows trusted applications of the same provider to access each other while maintaining security against cross-provider access.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The service manager acts as an intermediary between trusted applications and stored applications. Instead of allowing direct access or complete blocking, the service manager mediates by evaluating access requests, checking provider relationships, and selectively granting access rights. This intermediary role enables controlled access that resolves the contradiction between security and operational capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the service manager prevents all access to stored applications, then security is improved, but the development of new NFC services deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidservice development capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by making access rights configurable and changeable rather than static. The service manager can dynamically adjust access policies based on the specific trusted application, the stored application, and their provider relationships. This dynamic access control enables the system to adapt to new NFC services and business models while maintaining security through configurable policies.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of access rights from a fixed state to a configurable state. By allowing the service manager to modify access policies based on provider relationships and application types, the system can adapt to evolving NFC service requirements. This parameter change enables new services to be enabled without compromising the fundamental security architecture.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If trusted applications are allowed unrestricted access to all stored applications, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the access space into distinct segments based on service provider boundaries. The service manager segments access rights so that trusted applications can access stored applications within the same provider segment, but are blocked from accessing applications in other provider segments. This segmentation resolves the contradiction by enabling convenient access within trusted boundaries while preventing unauthorized cross-boundary access.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9608989B2Method, system, trusted service manager, service provider and memory element for managing access rights for trusted applications
Publication Date: 2017.03.28 NXP BV
  • US9608989B2 patent drawing
  • US9608989B2 patent drawing
  • US9608989B2 patent drawing

AI summary

A method for granting trusted applications (SP1_WL) of a Service Provider (SP1, SP2)access to applications (appSP1.1, appSP1.2; appSP2.1) of that Service Provider (SP1, SP2) that have been stored in a secure element (SE) comprises: the Service Provider (SP1, SP2) transmits a request (REQ1) for granting access to its applications to a Trusted Service Manager (TSM); the Trusted Service Manager (TSM) generates an access right code (AC1) and transmits it to both the Service Provider (SP1, SP2) and a service manager (SM) in the secure element (SE); the Service Provider (SP1, SP2) generates the trusted application (SP1_WL), provides it with the access right code (AC1) and sends it to the secure element (SE); the trusted application (SP1_WL) connects to the service manager (SM) with the access right code (AC1) whereupon the service manager (SM) grants the wallet (SP1_WL) access to the applications (appSP1.1, appSP1.2; appSP2.1).