Secure Element Applets for Low-Latency UWB Ranging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a method to efficiently perform secure ranging while minimizing the time required for secure ranging operations, particularly in IoT environments where digital keys are used for secure communication between electronic devices, and concerns about security and latency exist.

Innovation Solution

The method involves an electronic device using a secure element with a first and second applet to transmit and receive a ranging session key for secure ranging with a target device, employing a first communication method like BLE for connection and a second method like UWB for secure ranging, thereby reducing latency and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If secure ranging is performed using traditional methods with single applet architecture, then security is maintained, but the time required for secure ranging setup increases

Engineering Contradiction:
Improvesecure ranging setup timeVSAvoidapplet architecture complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The secure element is divided into multiple specialized applets (first applet for key generation and storage, second applet for ranging operations) to enable parallel processing and reduce setup time. Each applet handles specific functions independently, eliminating sequential bottlenecks while maintaining security through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The ranging session key is generated and stored in the first applet in advance, before the actual ranging operation is needed. This preliminary key preparation eliminates the time-consuming key generation step during the ranging setup phase, significantly reducing latency while maintaining cryptographic security.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If digital keys are stored in electronic devices for convenient access, then user convenience is improved, but security vulnerabilities increase due to potential hacking

Engineering Contradiction:
Improvedigital key access convenienceVSAvoidsecurity against hacking
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The digital key infrastructure is nested within a hardware secure element, which provides physical security boundaries. The first and second applets are nested within the secure element, creating layers of protection where the hardware envelope protects the software keys, and the key management architecture protects the actual cryptographic materials.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

A framework acts as an intermediary between the application layer and the secure element, managing key access requests and coordinating communication between the first and second applets. This intermediary layer provides controlled access pathways that maintain security while enabling convenient digital key operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12137348B2Method and apparatus by which electronic device performs secure ranging
Publication Date: 2024.11.05 SAMSUNG ELECTRONICS CO LTD
  • US12137348B2 patent drawing
  • US12137348B2 patent drawing
  • US12137348B2 patent drawing

AI summary

Provided is a method, performed by an electronic device, of performing secure ranging with a target device. The method of performing secure ranging may include receiving a connection message for communication with the target device using a first communication method through a first communicator, transmitting, by a first applet in a secure element of the electronic device, a ranging session key for the target device to a second applet in the secure element, the ranging session key being stored in the first applet, receiving a ranging session request from the target device, based on the ranging session request, obtaining, by a second communicator, the ranging session key for the target device from the second applet, and by using the ranging session key, performing secure ranging using a second communication method with the target device through the second communicator.