Secure Element Access Rules with Local User Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems do not allow users to flexibly adapt access rules for secure elements, such as subscriber identity modules, to accommodate changes in application inventories on mobile terminals, necessitating reliance on network operator management via remote servers.

Innovation Solution

A secure element with an integrated ARA application and user interface that enables users to locally manage access rules through user commands, allowing generation, storage, deletion, or change of access rules directly on the terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote server management is used to manage ARA access rules, then centralized control and security are improved, but user convenience and adaptability deteriorate as users cannot locally adapt access rules without server intervention

Engineering Contradiction:
Improvecentralized control and securityVSAvoiduser convenience and adaptability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments access rule management into two parts: centralized ARA application storage in the secure element and localized user interface functionality. The user interface in the terminal can independently generate, modify, and delete access rules without requiring remote server intervention, while the secure element maintains centralized storage of ARA applications. This segmentation resolves the contradiction by enabling local user operations while preserving centralized security architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The user interface enables self-service access rule management by allowing users to directly generate, modify, and delete access rules through local operations. The terminal can autonomously communicate with the secure element to apply these rules without requiring remote server mediation, thereby improving user convenience and adaptability while maintaining security through the secure element's protected environment.

Inventive Principle:
Principle #25Self-service

2Reliability

If access rules are managed centrally through remote servers, then security and control are improved, but system flexibility and responsiveness to local changes deteriorate

Engineering Contradiction:
Improvesecurity and controlVSAvoidsystem flexibility and responsiveness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system separates security-critical ARA application storage in the secure element from user-operable interface functionality in the terminal. This segmentation allows the terminal to locally adapt access rules in response to changing conditions while the secure element maintains centralized security control. The divided architecture enables both security and flexibility simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access rule management system transitions from a static centralized model to a dynamic model where the terminal can actively generate, modify, and delete access rules in real-time based on local conditions. The user interface provides dynamic operations that respond to immediate user needs, while the secure element maintains the stable storage of ARA applications. This dynamic capability resolves the contradiction between security and adaptability.

Inventive Principle:
Principle #15Dynamics

3Reliability

If users must rely on remote server management for access rules, then centralized security is maintained, but user responsiveness to new applications and changes deteriorates

Engineering Contradiction:
Improvecentralized securityVSAvoiduser responsiveness time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The user interface enables immediate self-service access rule management by allowing users to directly generate, modify, and delete rules without waiting for remote server processing. Users can respond instantly to new application needs or security requirements by performing local operations, eliminating the time delay associated with remote server communication while maintaining security through the secure element's protected environment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system allows users to perform preliminary access rule setup and modification locally before any security issues arise. Users can proactively create access rules for new applications or adjust existing ones in advance, eliminating the need to wait for remote server intervention and reducing response time to security and functional requirements.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12626021B2Secure element with access rule application ARA
Publication Date: 2026.05.12 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • US12626021B2 patent drawing
  • US12626021B2 patent drawing
  • US12626021B2 patent drawing

AI summary

A secure element includes an SE application implemented therein or configured to implement an SE application therein. The secure element includes: an SE terminal interface to a terminal, in conjunction with which the secure element is able to be operated; an ARA application (ARA-X) and ARA access rules, by way of which access operations from applications implemented in the terminal to SE applications implemented or able to be implemented in the secure element via the SE terminal interface are controlled. The secure element is: an ARA user interface (ARA-UI), which is configured: to receive user commands that are input by a user on a user interface provided on the terminal or on the secure element; to forward received user commands to the ARA application; and to prompt the ARA application to apply forwarded user commands to the ARA application.