Secure Element Certificate Generation via Primary Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manufacturing process of electronic components is inflexible and costly due to the need for a large number of uniquely generated certificates for each component, which requires extensive diversification and increases production time.

Innovation Solution

A secure element that generates a second certificate associated with a secondary application by using a processor to electronically sign a key from a primary certificate, allowing for certificate generation directly within the secure element, reducing the need for factory-based manufacturing and personalization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificates are generated uniquely for each electronic component during factory manufacturing, then each component has its own authenticated certificate, but the manufacturing process becomes inflexible and costly with increased production time

Engineering Contradiction:
Improvecertificate authenticationVSAvoidmanufacturing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

A source certificate is pre-loaded into the secure element during manufacturing, serving as a template. This preliminary action enables subsequent derivative certificates to be generated quickly without requiring factory personalization for each component, thus maintaining reliability while improving productivity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention uses a source certificate as a master template that can be copied and derived into multiple derivative certificates. This copying mechanism allows rapid generation of unique certificates for each component based on the pre-existing source certificate, eliminating the need for time-consuming factory-based certificate generation for each unit

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If a high number of certificates are generated for diverse electronic components, then each component can be uniquely authenticated, but the personalization process becomes more expensive and time-consuming

Engineering Contradiction:
Improvecertificate diversityVSAvoidpersonalization cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The source certificate stored in the secure element serves as a universal template that can generate derivative certificates for multiple different applications and components. This multi-functionality allows a single source certificate to support diverse certificate needs without requiring separate personalization processes for each, thereby reducing manufacturing costs while maintaining adaptability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The derivative certificate generation process copies the essential structure and authentication data from the source certificate, adapting it for different applications. This copying approach maintains certificate diversity and adaptability while significantly reducing the cost and complexity of personalization compared to generating entirely unique certificates for each component

Inventive Principle:
Principle #26Copying

3Manufacturing precision

If certificates are generated during factory manufacturing, then each component receives its certificate, but the process is inflexible and increases production time

Engineering Contradiction:
Improvecertificate uniquenessVSAvoidproduction time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The source certificate is preliminarily installed in the secure element during manufacturing, but the actual derivative certificates are generated later when needed. This separates the time-critical manufacturing step from the certificate generation step, maintaining certificate uniqueness while dramatically reducing production time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Each derivative certificate is generated by copying and adapting the pre-loaded source certificate rather than creating it from scratch during manufacturing. This copying process ensures each certificate remains unique and properly authenticated while being generated rapidly outside the manufacturing process, thus eliminating the time loss associated with factory-based certificate generation

Inventive Principle:
Principle #26Copying

Data Source

PatentEP4362394A1Secure element, associated host terminal, method for generating a certificate in a secure element and associated computer program
Publication Date: 2024.05.01 IDEMIA FRANCE SAS
  • EP4362394A1 patent drawingFigure 1
  • EP4362394A1 patent drawingFigure 2
  • EP4362394A1 patent drawing

AI summary

The invention relates to a secure element (15) comprising a first means for storing (22, 24, 26) a first certificate associated with a primary application and a processor (20). According to the invention, the primary application is designed such that the processor (20) generates a second certificate associated with a secondary application when the primary application is executed by the processor (20), the second certificate being electronically signed using a key contained in the first certificate. The invention also relates to a host terminal (1), a method for generating a certificate in a secure element (15), and an associated computer program.