Secure Element Application Management via Remote Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Near Field Communication (NFC) technologies lack a satisfactory solution for managing applications on secure elements when a secure element reader attempts to interact with a secure element that does not have a matching application.
Innovation Solution
A method is introduced where the secure element verifies incoming user application commands, determines if a matching application is present, and if not, establishes a communication channel with a remote application manager server to handle the absent application, utilizing the Bearer Independent Protocol for communication and allowing the server to retrieve and send the necessary application instance state.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the secure element processes application requests locally, then the response time is fast, but the secure element cannot handle absent applications and has limited processing capability
Solution Approach 1:
The patent introduces a remote application manager server as an intermediary that handles absent application requests. When the secure element cannot fulfill a request locally, it delegates to the server via a communication channel, allowing the system to handle applications beyond the secure element's local capabilities without increasing the secure element's complexity.
Solution Approach 2:
The patent extends the application handling capability from a single local dimension to a distributed dimension by establishing communication channels with a remote server. This allows the secure element to access applications stored remotely, effectively adding another dimension to the application management architecture.
2Quantity of substance
If the secure element maintains all application states locally, then application access is fast, but the secure element has limited storage capacity
Solution Approach 1:
The patent extracts application state data from the secure element's local storage and transfers it to the remote application manager server. This allows the secure element to maintain only essential local state while storing the bulk of application data remotely, effectively increasing the available storage capacity without proportionally increasing local energy consumption for data retention.
Solution Approach 2:
The patent segments application management into two parts: local handling of immediate requests and remote storage of application states. The secure element maintains minimal local state for rapid response, while the server handles the bulk of application data storage and retrieval, dividing the storage burden across multiple locations.
3Reliability
If the secure element implements strict application verification, then application security is improved, but the processing time increases
Solution Approach 1:
The patent performs application verification and authentication in advance before the actual application execution. By validating application identifiers and establishing secure communication channels beforehand, the system ensures security is maintained while minimizing verification time during actual application use.
Solution Approach 2:
The patent implements feedback mechanisms where the secure element verifies application authenticity and provides feedback to the remote server about the verification status. This allows for efficient verification processes where authentication results are quickly communicated and used to determine whether to proceed with application execution.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
It presented a method, performed in a secure element, the secure element being arranged to enable user applications of the secure element to verify authenticity of incoming user application commands. The method comprises the steps of : receiving a command from a secure element reader for a user application on the secure element, the command comprising an application identifier of the user application; determining whether there is a matching user application in the secure element; invoking the matching user application; and establishing, when there is an absence of any matching user applications, a communication channel with a remote application manager server and sending an absent user application message to the application manager server indicating that the user application has been requested on the secure element. A corresponding secure element, method for an application manager server and application manager server are also presented.