Secure Element Certificate Generation via Primary Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The manufacturing process of electronic components is inflexible and costly due to the need for a large number of uniquely generated certificates for each component, which requires extensive diversification and increases production time.
Innovation Solution
A secure element that generates a second certificate associated with a secondary application by using a processor to electronically sign a key from a primary certificate, allowing for certificate generation directly within the secure element, reducing the need for factory-based manufacturing and personalization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificates are generated uniquely for each electronic component during factory manufacturing, then each component has its own authenticated certificate, but the manufacturing process becomes inflexible and costly with increased production time
Solution Approach 1:
A source certificate is pre-loaded into the secure element during manufacturing, serving as a template. This preliminary action enables subsequent derivative certificates to be generated quickly without requiring factory personalization for each component, thus maintaining reliability while improving productivity
Solution Approach 2:
The invention uses a source certificate as a master template that can be copied and derived into multiple derivative certificates. This copying mechanism allows rapid generation of unique certificates for each component based on the pre-existing source certificate, eliminating the need for time-consuming factory-based certificate generation for each unit
2Adaptability or versatility
If a high number of certificates are generated for diverse electronic components, then each component can be uniquely authenticated, but the personalization process becomes more expensive and time-consuming
Solution Approach 1:
The source certificate stored in the secure element serves as a universal template that can generate derivative certificates for multiple different applications and components. This multi-functionality allows a single source certificate to support diverse certificate needs without requiring separate personalization processes for each, thereby reducing manufacturing costs while maintaining adaptability
Solution Approach 2:
The derivative certificate generation process copies the essential structure and authentication data from the source certificate, adapting it for different applications. This copying approach maintains certificate diversity and adaptability while significantly reducing the cost and complexity of personalization compared to generating entirely unique certificates for each component
3Manufacturing precision
If certificates are generated during factory manufacturing, then each component receives its certificate, but the process is inflexible and increases production time
Solution Approach 1:
The source certificate is preliminarily installed in the secure element during manufacturing, but the actual derivative certificates are generated later when needed. This separates the time-critical manufacturing step from the certificate generation step, maintaining certificate uniqueness while dramatically reducing production time
Solution Approach 2:
Each derivative certificate is generated by copying and adapting the pre-loaded source certificate rather than creating it from scratch during manufacturing. This copying process ensures each certificate remains unique and properly authenticated while being generated rapidly outside the manufacturing process, thus eliminating the time loss associated with factory-based certificate generation
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a secure element (15) comprising a first means for storing (22, 24, 26) a first certificate associated with a primary application and a processor (20). According to the invention, the primary application is designed such that the processor (20) generates a second certificate associated with a secondary application when the primary application is executed by the processor (20), the second certificate being electronically signed using a key contained in the first certificate. The invention also relates to a host terminal (1), a method for generating a certificate in a secure element (15), and an associated computer program.