Secure Element Content Management via Dual-Credential Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware can redirect secure element content downloads, compromising network access and credential security during remote management, especially when the secure element is embedded or difficult to remove, and malware on a terminal can intercept and misdirect updates.

Innovation Solution

Establishing a secure channel using session keys generated by the secure element and verifying the origin of management requests to ensure that only the intended secure element is managed, by using an independent application to provide session keys and identifiers for authentication and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote management is used to update secure element content, then maintenance and updates can be performed remotely, but malware on the terminal can intercept and redirect content downloads to wrong secure elements

Engineering Contradiction:
Improveremote management capabilityVSAvoidcontent delivery security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism where the terminal acts as a mediator that must present both its own credentials and the secure element's credentials to the remote management server. This dual-credential verification system prevents malware from redirecting content downloads because the server verifies that the terminal requesting the update is the legitimate owner of the secure element being updated, breaking the malware's ability to intercept and misdirect updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the secure element is embedded or difficult to remove, then it provides better security and integration, but malware can more easily intercept and misdirect content updates

Engineering Contradiction:
Improvesecure element integrationVSAvoidmalware interference
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the remote management server receives verification of the terminal's credentials and the secure element's credentials, then uses this feedback to authenticate the update request. The server only delivers content when both credential sets match and verify each other, creating a closed-loop security system that prevents malware from successfully intercepting or redirecting updates to embedded secure elements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10242210B2Method for managing content on a secure element connected to an equipment
Publication Date: 2019.03.26 THALES DIS FRANCE SA
  • US10242210B2 patent drawing
  • US10242210B2 patent drawing

AI summary

The invention concerns a method for managing content on a secure element connected to an equipment, this content being managed on the secure element from a distant administrative platform. According to the invention, the method consists in: establishing, at the level of the administrative platform a secure channel between the equipment and the administrative platform, thanks to session keys generated by the secure element and transmitted to the equipment; transmitting to the administrative platform a request to manage content of the secure element; and verifying at the level of the administrative platform that this request originates from the same secure element that has generated the session keys and, if positive, authorizing the management and, if negative, forbid this management.