Secure Element Authentication Isolation via Dedicated Microcontroller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for protecting authentication information on smartphones are either insecure due to large-scale asynchronous automated stealing attacks or have usability drawbacks, such as requiring dedicated security hardware or complex baseline initialization, and are vulnerable to malware that can intercept sensitive information, including passwords and authentication credentials.

Innovation Solution

A method and system that utilize a SIM card to determine whether information requires authentication, enabling a dedicated microcontroller to securely display and input authentication information, while keeping regular operations accessible by the operating system, using a secure mode indicator and additional hardware layers to isolate and protect sensitive transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security dedicated hardware is used for authentication, then security is improved, but device complexity and usability are worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security dedicated hardware (secure element) with the smartphone's existing hardware components. The secure element is integrated into the smartphone chipset, sharing physical space and resources with the main processor and other components, thereby reducing overall device complexity while maintaining authentication security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure element is designed to perform multiple functions including authentication, key storage, and secure communication. This multi-functionality eliminates the need for separate dedicated hardware for each security function, reducing device complexity while maintaining comprehensive security protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security dedicated hardware is used for authentication, then security is improved, but ease of operation is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By integrating the secure element with the smartphone's existing interface and operating system, the patent allows users to authenticate using the same device they already interact with daily. The secure authentication process is seamlessly embedded within the familiar smartphone interface, maintaining ease of operation while enhancing security.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If software-based authentication is used on existing devices, then ease of operation is improved, but security is worsened due to malware vulnerability

Engineering Contradiction:
ImproveusabilityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into two distinct parts: a software interface layer that provides ease of operation and a hardware-based secure element that provides security. This segmentation isolates the security-critical functions in the hardware secure element, making them immune to software-based malware attacks, while the software layer maintains user-friendly interaction.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element acts as an intermediary between the user interface and the authentication process. It mediates all authentication operations, verifying credentials and managing security keys in hardware, thereby protecting against malware that might compromise software-based authentication while maintaining seamless user interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If multiple security specific hardware components are used for different banks, then authentication security is improved, but device complexity and ease of operation are worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidnumber of hardware components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal secure element that can store multiple authentication credentials and serve multiple authentication purposes. Instead of requiring separate hardware components for different banks or services, the single secure element can securely store and manage credentials for multiple authentication systems, dramatically reducing device complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3093790B1Method for real time protection against unsolicited access to authentication information known by a legitimate end-user
Publication Date: 2018.11.14 ALCATEL LUCENT SA
  • EP3093790B1 patent drawingFigure 1
  • EP3093790B1 patent drawingFigure 2
  • EP3093790B1 patent drawingFigure 3

AI summary

A method for real time protection against unsolicited access to authentication information known by a legitimate end-user, is provided. The method comprising the following steps: hardware information presentation means and an input means are exclusively accessed by a dedicated microcontroller (5), or, an input means and an additional hardware information presentation means are exclusively accessed by a dedicated microcontroller (5), said additional hardware information presentation means displaying inputted information from said input means, or, an additional hardware information presentation means and an additional input means are exclusively accessed by a dedicated microcontroller (5), said additional hardware information presentation means displaying inputted information from said input means.