Secure Element Credential Deletion Without Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deletion of commerce credentials from electronic devices, particularly those with NFC capabilities, is inconvenient as it often requires network connectivity and authentication with remote systems, making it difficult to securely and permanently remove credentials without online access.

Innovation Solution

The system allows for the secure deletion of commerce credentials by updating their life cycle state locally on the device, which can then be shared with the remote subsystem upon reconnection, enabling permanent termination of functionality without initial network connectivity, using a secure element with a processor to manage the security domain elements and communicate with a trusted service manager.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If commerce credentials are deleted using conventional methods requiring network connectivity and remote authentication, then security and control are improved, but ease of operation and user convenience deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidconvenience of credential deletion
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by establishing secure cryptographic credentials and trust relationships during device provisioning before the credential deletion issue arises. The trusted service manager pre-configures security domains and establishes cryptographic key pairs, enabling later autonomous deletion operations without requiring real-time network connectivity or remote authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The electronic device is empowered to autonomously delete its own commerce credentials using locally stored cryptographic credentials and pre-established trust relationships. The device can independently verify its authority to delete credentials and execute the deletion without requiring continuous communication with remote authentication systems, making the system self-sufficient for credential management.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If commerce credentials are deleted without network connectivity, then ease of operation is improved, but reliability and security verification worsen

Engineering Contradiction:
Improveindependence from network connectivityVSAvoidverification of deletion
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the electronic device communicates credential deletion status to the trusted service manager when network connectivity is available. The device provides feedback about its credential state, and the trusted service manager updates its records accordingly, ensuring both parties have consistent information about credential lifecycle events.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The trusted service manager performs preliminary actions by pre-establishing cryptographic trust relationships and security domain configurations during device provisioning. This preliminary setup enables the device to autonomously verify and execute credential deletions offline, with the understanding that verification and synchronization will occur when connectivity is restored.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If security domain functionality is permanently terminated locally, then ease of operation and speed are improved, but device complexity increases

Engineering Contradiction:
Improvespeed of credential deletionVSAvoidcomplexity of secure element management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the security domain management functionality into a separate secure element component that is physically or logically isolated from the main device processor. This extraction allows the secure element to independently manage credential lifecycle events including permanent termination, while the main device can initiate deletion commands without directly managing the complex cryptographic operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The trusted service manager acts as an intermediary that simplifies the interface between the electronic device and the complex secure element infrastructure. The TSM handles the complexity of cryptographic key management, security domain provisioning, and credential lifecycle coordination, allowing the device to issue simple commands without directly managing the underlying cryptographic complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10552830B2Deletion of credentials from an electronic device
Publication Date: 2020.02.04 APPLE INC
  • US10552830B2 patent drawing
  • US10552830B2 patent drawing
  • US10552830B2 patent drawing

AI summary

Systems, methods, and computer-readable media for managing credentials are provided. In one example embodiment, an electronic device may include a secure element with a security domain element stored on the secure element. The electronic device may also include a processor component that may be configured to, inter alia, permanently terminate the functionality of the security domain element, after the functionality has been permanently terminated, communicatively couple the electronic device to a trusted service manager, and transmit data to the communicatively coupled trusted service manager that may be usable by the trusted service manager to determine that the functionality has been permanently terminated. Additional embodiments are also provided.