Secure Element Client Credential Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for networks and applications rely on smart cards or Common Access Cards (CACs), which can be inconvenient for users and require enterprises to issue physical cards and devices, and may compromise security if private keys are not properly managed.
Innovation Solution
An electronic device is equipped with a secure environment to generate and store unique client credentials, using a hardware certificate and a secure execution environment to ensure that private keys never leave the device, allowing for secure authentication without the need for physical cards or compromised OS frameworks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If smart cards or Common Access Cards are used for authentication, then physical tokens can be distributed to users, but device complexity and ease of operation deteriorate due to the need for physical card issuance and management
Solution Approach 1:
The patent extracts the authentication credentials (private keys and certificates) from physical smart cards and embeds them directly into the electronic device's secure element. This eliminates the need for physical card issuance, distribution, and management while maintaining authentication security. The secure element within the device generates and stores credentials locally, removing the external physical token dependency.
Solution Approach 2:
The electronic device performs self-authentication using credentials stored in its own secure element, without requiring external physical tokens or manual card insertion. The device autonomously manages its authentication credentials, generating and protecting private keys internally, which simplifies the authentication process and eliminates the need for physical card management infrastructure.
2Reliability
If private keys are stored in secure environment, then security is improved, but key management complexity increases
Solution Approach 1:
The patent merges the key generation, storage, and protection functions into a single integrated secure element within the electronic device. This consolidation simplifies key management by combining multiple security functions into one unified secure environment, reducing the complexity of managing separate key storage and protection mechanisms while maintaining high security standards.
Solution Approach 2:
The secure element within the device autonomously manages private keys without requiring external intervention or complex management infrastructure. The secure element generates keys internally, protects them through hardware-based security measures, and handles authentication operations independently, simplifying the overall key management process while maintaining strong security.
3Reliability
If hardware certificates are used, then authentication security is improved, but ease of operation worsens due to seamless integration requirements
Solution Approach 1:
The patent implements a universal authentication mechanism where the secure element can handle multiple authentication protocols and certificate types within a single hardware component. This multi-functionality allows the device to seamlessly integrate with various existing PKI systems and authentication frameworks without requiring separate hardware or complex configuration, thereby improving ease of operation while maintaining high security.
4Reliability
If credentials are generated in secure zone, then security is improved, but manufacturing complexity increases
Solution Approach 1:
The patent implements preliminary key generation during the device manufacturing process, where the secure element generates and stores private keys before the device reaches the user. This preliminary action ensures that credentials are created in a controlled secure environment during manufacturing, eliminating the need for complex post-manufacturing key distribution and installation processes, thereby reducing manufacturing complexity while maintaining high security standards.
Data Source
Figure 1
Figure 2~3b
Figure 4a
AI summary
An apparatus and method for storing authentication information on an electronic device are provided. The method includes receiving, by the electronic device, a unique key and a certificate matching the unique key in a secure environment of the electronic device, storing the unique key and the certificate matching the unique key in a secure environment of the electronic device, and wherein at least one of the unique key and the certificate matching the unique key identifies the electronic device.