Secure Element Authentication for Communication Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems lack secure authentication methods for users, particularly in scenarios involving external devices and web servers, which can lead to unauthorized access and resource misuse.

Innovation Solution

The use of a secure element, such as a Universal Integrated Circuit Card (UICC), and a secure device processor (SDP) as a secure authentication platform, which stores and processes digital credentials like passwords, pin numbers, and biometric data to verify user identity and securely authenticate users across communication devices and external entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used without a secure element, then device complexity is reduced, but security reliability deteriorates due to unauthorized access risks

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional components: a secure element (separate secure processor and secure memory) for credential storage and verification, and a main device processor for application execution. This segmentation isolates security-critical functions in a protected environment, preventing unauthorized access while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element acts as an intermediary between the user credential input and the authentication verification process. It receives credentials from the device processor, performs secure verification against stored baseline credentials, and returns authentication results without exposing the baseline credentials to the main processor or external entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If baseline credentials are stored in accessible memory, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvecredential verification speedVSAvoidunauthorized credential access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Baseline credentials are extracted from the main device memory and stored exclusively in the secure element's protected memory. This separation removes the vulnerability of storing sensitive credentials in accessible memory, while the secure element maintains fast verification capabilities through dedicated hardware and optimized secure storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure element creates an inert, isolated environment for credential storage and processing. The secure memory is protected from external access, and the secure processor operates in a trusted execution environment that prevents tampering, effectively creating a security enclave that shields credentials from harmful external factors.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Adaptability or versatility

If external entities can access baseline credentials, then adaptability of authentication system is improved, but security reliability deteriorates

Engineering Contradiction:
Improvemulti-entity authentication capabilityVSAvoidcredential protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Instead of providing access to the actual baseline credentials, the system creates and provides authentication tokens or derived credentials to external entities. The secure element generates these copies based on the baseline credentials without exposing the originals, enabling external entities to perform authentication while maintaining credential protection.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system transitions from a single-dimension authentication model (direct credential access) to a multi-dimensional model where baseline credentials remain in the secure element while derived authentication data is provided to external entities. This dimensional separation allows versatile authentication support while maintaining the security boundary of the original credentials.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10778670B2Apparatus and method for secure authentication of a communication device
Publication Date: 2020.09.15 AT&T INTELLECTUAL PROPERTY I L P
  • US10778670B2 patent drawing
  • US10778670B2 patent drawing
  • US10778670B2 patent drawing

AI summary

A system that incorporates the subject disclosure may perform, for example, receiving a baseline credential and an external credential, mapping the external credential to the baseline credential in a secure element memory, receiving a request for an authentication from a secure device processor of the communication device where the request for the authentication includes a user credential inputted into the communication device, comparing the user credential with the baseline credential to verify the authentication, and providing the authentication and the external credential to the secure device processor without providing the baseline credential to enable the secure device processor to provide the external credential to an external entity device that is remote from the communication device. Other embodiments are disclosed.