Secure Element Application Management via Remote Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Near Field Communication (NFC) technologies lack a satisfactory solution for managing applications on secure elements when a secure element reader attempts to interact with a secure element that does not have a matching application.

Innovation Solution

A method is introduced where the secure element verifies incoming user application commands, determines if a matching application is present, and if not, establishes a communication channel with a remote application manager server to handle the absent application, utilizing the Bearer Independent Protocol for communication and allowing the server to retrieve and send the necessary application instance state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the secure element processes application requests locally, then the response time is fast, but the secure element cannot handle absent applications and has limited processing capability

Engineering Contradiction:
Improveapplication handling capabilityVSAvoidsecure element complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a remote application manager server as an intermediary that handles absent application requests. When the secure element cannot fulfill a request locally, it delegates to the server via a communication channel, allowing the system to handle applications beyond the secure element's local capabilities without increasing the secure element's complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extends the application handling capability from a single local dimension to a distributed dimension by establishing communication channels with a remote server. This allows the secure element to access applications stored remotely, effectively adding another dimension to the application management architecture.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Quantity of substance

If the secure element maintains all application states locally, then application access is fast, but the secure element has limited storage capacity

Engineering Contradiction:
Improveapplication storage capacityVSAvoidsecure element energy consumption
Core Design Contradiction:
Quantity of substanceVSUse of energy by moving object

Solution Approach 1:

The patent extracts application state data from the secure element's local storage and transfers it to the remote application manager server. This allows the secure element to maintain only essential local state while storing the bulk of application data remotely, effectively increasing the available storage capacity without proportionally increasing local energy consumption for data retention.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments application management into two parts: local handling of immediate requests and remote storage of application states. The secure element maintains minimal local state for rapid response, while the server handles the bulk of application data storage and retrieval, dividing the storage burden across multiple locations.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the secure element implements strict application verification, then application security is improved, but the processing time increases

Engineering Contradiction:
Improveapplication authentication securityVSAvoidapplication verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs application verification and authentication in advance before the actual application execution. By validating application identifiers and establishing secure communication channels beforehand, the system ensures security is maintained while minimizing verification time during actual application use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the secure element verifies application authenticity and provides feedback to the remote server about the verification status. This allows for efficient verification processes where authentication results are quickly communicated and used to determine whether to proceed with application execution.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2508014B1Methods, secure element, server, computer programs and computer program products for improved application management
Publication Date: 2018.04.04 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2508014B1 patent drawingFigure 1
  • EP2508014B1 patent drawingFigure 2~3
  • EP2508014B1 patent drawingFigure 4

AI summary

It presented a method, performed in a secure element, the secure element being arranged to enable user applications of the secure element to verify authenticity of incoming user application commands. The method comprises the steps of : receiving a command from a secure element reader for a user application on the secure element, the command comprising an application identifier of the user application; determining whether there is a matching user application in the secure element; invoking the matching user application; and establishing, when there is an absence of any matching user applications, a communication channel with a remote application manager server and sending an absent user application message to the application manager server indicating that the user application has been requested on the secure element. A corresponding secure element, method for an application manager server and application manager server are also presented.