Secure Element Authentication for Communication Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems lack secure authentication methods for users, particularly in scenarios involving external devices and web servers, which can lead to unauthorized access and resource misuse.
Innovation Solution
The use of a secure element, such as a Universal Integrated Circuit Card (UICC), and a secure device processor (SDP) as a secure authentication platform, which stores and processes digital credentials like passwords, pin numbers, and biometric data to verify user identity and securely authenticate users across communication devices and external entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used without a secure element, then device complexity is reduced, but security reliability deteriorates due to unauthorized access risks
Solution Approach 1:
The authentication system is segmented into distinct functional components: a secure element (separate secure processor and secure memory) for credential storage and verification, and a main device processor for application execution. This segmentation isolates security-critical functions in a protected environment, preventing unauthorized access while maintaining overall system functionality.
Solution Approach 2:
The secure element acts as an intermediary between the user credential input and the authentication verification process. It receives credentials from the device processor, performs secure verification against stored baseline credentials, and returns authentication results without exposing the baseline credentials to the main processor or external entities.
2Ease of operation
If baseline credentials are stored in accessible memory, then ease of operation is improved, but security against unauthorized access deteriorates
Solution Approach 1:
Baseline credentials are extracted from the main device memory and stored exclusively in the secure element's protected memory. This separation removes the vulnerability of storing sensitive credentials in accessible memory, while the secure element maintains fast verification capabilities through dedicated hardware and optimized secure storage.
Solution Approach 2:
The secure element creates an inert, isolated environment for credential storage and processing. The secure memory is protected from external access, and the secure processor operates in a trusted execution environment that prevents tampering, effectively creating a security enclave that shields credentials from harmful external factors.
3Adaptability or versatility
If external entities can access baseline credentials, then adaptability of authentication system is improved, but security reliability deteriorates
Solution Approach 1:
Instead of providing access to the actual baseline credentials, the system creates and provides authentication tokens or derived credentials to external entities. The secure element generates these copies based on the baseline credentials without exposing the originals, enabling external entities to perform authentication while maintaining credential protection.
Solution Approach 2:
The system transitions from a single-dimension authentication model (direct credential access) to a multi-dimensional model where baseline credentials remain in the secure element while derived authentication data is provided to external entities. This dimensional separation allows versatile authentication support while maintaining the security boundary of the original credentials.
Data Source
AI summary
A system that incorporates the subject disclosure may perform, for example, receiving a baseline credential and an external credential, mapping the external credential to the baseline credential in a secure element memory, receiving a request for an authentication from a secure device processor of the communication device where the request for the authentication includes a user credential inputted into the communication device, comparing the user credential with the baseline credential to verify the authentication, and providing the authentication and the external credential to the secure device processor without providing the baseline credential to enable the secure device processor to provide the external credential to an external entity device that is remote from the communication device. Other embodiments are disclosed.


