Secure Element Authentication Without Device-Server Pairing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for securing communication between devices equipped with secure elements and remote servers require pre- or post-association, pairing, or dynamically linking supply chains, which complicates manufacturing and increases security risks.
Innovation Solution
A method for securing communication between a device and a remote server using asymmetric cryptography, where device and server key materials are generated independently based on device and server profile data and secure element data, with public data only being reported for association, allowing secure communication without pre- or post-association.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-association or post-association methods are used to secure communication between device and remote server, then security is improved, but device complexity and manufacturing complexity increase
Solution Approach 1:
The patent applies preliminary action by pre-generating key material in the secure element during secure element manufacturing, before the device is assembled. This key material is embedded in the secure element and automatically used when the device communicates with the remote server, eliminating the need for complex post-association key exchange procedures and reducing manufacturing complexity.
Solution Approach 2:
The secure element performs self-service by independently generating and managing authentication credentials without requiring external intervention during device manufacturing or activation. The secure element autonomously establishes secure communication with the remote server using pre-configured key material, eliminating the need for manual pairing or complex supply chain linking procedures.
2Reliability
If pre-association or post-association methods are used to secure communication, then security is improved, but supply chain dynamics become more complex
Solution Approach 1:
The patent applies preliminary action by pre-generating key material in the secure element during secure element manufacturing, before the device is assembled. This key material is embedded in the secure element and automatically used when the device communicates with the remote server, eliminating the need for complex post-association key exchange procedures and reducing manufacturing complexity.
Solution Approach 2:
The secure element performs self-service by independently generating and managing authentication credentials without requiring external intervention during device manufacturing or activation. The secure element autonomously establishes secure communication with the remote server using pre-configured key material, eliminating the need for manual pairing or complex supply chain linking procedures.
3Reliability
If verified association with explicit activation is used, then security is improved, but productivity decreases due to additional validation steps
Solution Approach 1:
The patent applies preliminary action by pre-generating key material in the secure element during secure element manufacturing, before the device is assembled. This key material is embedded in the secure element and automatically used when the device communicates with the remote server, eliminating the need for complex post-association key exchange procedures and reducing manufacturing complexity.
Solution Approach 2:
The secure element performs self-service by independently generating and managing authentication credentials without requiring external intervention during device manufacturing or activation. The secure element autonomously establishes secure communication with the remote server using pre-configured key material, eliminating the need for manual pairing or complex supply chain linking procedures.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Method for securing a communication between a remote server and a device equipped with a secure element, - device side profile data being stored in the device, - device side secure element data being stored in the secure element, - image data comprising : - server side profile data being stored in the remote server, - server side secure element data being stored in the remote server, or being retrievable from the remote server, the method comprising the steps of: a- associating the device with the secure element, b- generating, on the device side, a device key material, c- reporting the association to the remote server, d- generating, on the remote server side, a server key material e- authorizing a communication between the device and the remote server, after an authentication based at least on the basis of a comparison between the device key material and the server key material.