Secure Element Authentication Isolation via Dedicated Microcontroller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for protecting authentication information on smartphones are either insecure due to large-scale asynchronous automated stealing attacks or have usability drawbacks, such as requiring dedicated security hardware or complex baseline initialization, and are vulnerable to malware that can intercept sensitive information, including passwords and authentication credentials.
Innovation Solution
A method and system that utilize a SIM card to determine whether information requires authentication, enabling a dedicated microcontroller to securely display and input authentication information, while keeping regular operations accessible by the operating system, using a secure mode indicator and additional hardware layers to isolate and protect sensitive transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security dedicated hardware is used for authentication, then security is improved, but device complexity and usability are worsened
Solution Approach 1:
The patent merges the security dedicated hardware (secure element) with the smartphone's existing hardware components. The secure element is integrated into the smartphone chipset, sharing physical space and resources with the main processor and other components, thereby reducing overall device complexity while maintaining authentication security.
Solution Approach 2:
The secure element is designed to perform multiple functions including authentication, key storage, and secure communication. This multi-functionality eliminates the need for separate dedicated hardware for each security function, reducing device complexity while maintaining comprehensive security protection.
2Reliability
If security dedicated hardware is used for authentication, then security is improved, but ease of operation is worsened
Solution Approach 1:
By integrating the secure element with the smartphone's existing interface and operating system, the patent allows users to authenticate using the same device they already interact with daily. The secure authentication process is seamlessly embedded within the familiar smartphone interface, maintaining ease of operation while enhancing security.
3Ease of operation
If software-based authentication is used on existing devices, then ease of operation is improved, but security is worsened due to malware vulnerability
Solution Approach 1:
The patent segments the authentication system into two distinct parts: a software interface layer that provides ease of operation and a hardware-based secure element that provides security. This segmentation isolates the security-critical functions in the hardware secure element, making them immune to software-based malware attacks, while the software layer maintains user-friendly interaction.
Solution Approach 2:
The secure element acts as an intermediary between the user interface and the authentication process. It mediates all authentication operations, verifying credentials and managing security keys in hardware, thereby protecting against malware that might compromise software-based authentication while maintaining seamless user interaction.
4Reliability
If multiple security specific hardware components are used for different banks, then authentication security is improved, but device complexity and ease of operation are worsened
Solution Approach 1:
The patent implements a universal secure element that can store multiple authentication credentials and serve multiple authentication purposes. Instead of requiring separate hardware components for different banks or services, the single secure element can securely store and manage credentials for multiple authentication systems, dramatically reducing device complexity while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for real time protection against unsolicited access to authentication information known by a legitimate end-user, is provided. The method comprising the following steps: hardware information presentation means and an input means are exclusively accessed by a dedicated microcontroller (5), or, an input means and an additional hardware information presentation means are exclusively accessed by a dedicated microcontroller (5), said additional hardware information presentation means displaying inputted information from said input means, or, an additional hardware information presentation means and an additional input means are exclusively accessed by a dedicated microcontroller (5), said additional hardware information presentation means displaying inputted information from said input means.