Secure Element Boot Control for Remote Device Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for protecting devices from theft or loss are often dependent on user activation and may not be effective in all scenarios, as they require network connectivity and specific prerequisites, limiting their operational reliability.
Innovation Solution
A method and device that utilize a secure element with a state machine to control the boot process of a communication device, allowing remote online state control and tracking by selecting appropriate operating system partitions based on the device's state, enabling remote initiation of tracking and positioning even when the device is in an alert state.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing protection solutions are used, then device security is improved to some extent, but operational reliability deteriorates due to dependency on user activation and network connectivity prerequisites
Solution Approach 1:
The invention performs preliminary actions by integrating the boot service directly into the device's startup process. The secure element executes the boot service automatically during device initialization, determining usability state before the operating system fully loads. This eliminates the need for user activation or network connectivity prerequisites, as the security control is established in advance during the boot process itself.
Solution Approach 2:
The device performs self-service security control through the integrated boot service. The secure element autonomously determines the usability state and controls whether the operating system should be loaded, without requiring external user intervention or network-based authentication. The device self-manages its security state based on stored credentials and policy rules.
2Ease of operation
If the device is fully usable, then user convenience is improved, but the risk of unauthorized use increases when the device is lost or stolen
Solution Approach 1:
The invention implements dynamic usability control where the device can transition between different operational states. The secure element maintains a state machine that can be in either a usable or non-usable state, and this state can be changed remotely by crediting or debiting the secure element. When debited, the device automatically enters a non-usable state during boot, preventing unauthorized use while maintaining full functionality when credited.
Solution Approach 2:
The security control is applied locally at the boot level rather than at the application or user interface level. The secure element embedded in the device locally determines usability by executing the boot service and controlling operating system loading. This local control mechanism prevents unauthorized use at the hardware level without affecting user convenience when properly authorized.
3Loss of information
If tracking solutions using accounts and connectivity are implemented, then device tracking capability is improved, but device complexity increases due to multiple prerequisites
Solution Approach 1:
The invention extracts the security and tracking control functionality from the operating system and application layer, and places it directly in the secure element at the hardware level. The state machine and boot service reside in the secure element, independent of the operating system. This extraction eliminates the need for complex account systems and network connectivity prerequisites, as the control mechanism is self-contained in the secure element and operates during the boot process before the full OS loads.
Data Source
Figure 1~2
Figure 3
AI summary
Method for controlling usability of a communication device (1) comprising a processing unit (2) including a memory for storing computer code, a modem (11), an access circuit (12) connected to the modem for cellular network authentication and access, and a secure element (12) connected to the access circuit, comprising the steps of: initiating boot of the processing unit and the secure element at power up of the device; executing a boot service in the secure element; determining a current state of a state machine in the secure element; and booting a partition of an operating system, which partition is selected dependent on said current state.