Secure Element Credential Deletion Without Network
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The deletion of commerce credentials from electronic devices, particularly those with NFC capabilities, is inconvenient as it often requires network connectivity and authentication with remote systems, making it difficult to securely and permanently remove credentials without online access.
Innovation Solution
The system allows for the secure deletion of commerce credentials by updating their life cycle state locally on the device, which can then be shared with the remote subsystem upon reconnection, enabling permanent termination of functionality without initial network connectivity, using a secure element with a processor to manage the security domain elements and communicate with a trusted service manager.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If commerce credentials are deleted using conventional methods requiring network connectivity and remote authentication, then security and control are improved, but ease of operation and user convenience deteriorate
Solution Approach 1:
The system performs preliminary actions by establishing secure cryptographic credentials and trust relationships during device provisioning before the credential deletion issue arises. The trusted service manager pre-configures security domains and establishes cryptographic key pairs, enabling later autonomous deletion operations without requiring real-time network connectivity or remote authentication.
Solution Approach 2:
The electronic device is empowered to autonomously delete its own commerce credentials using locally stored cryptographic credentials and pre-established trust relationships. The device can independently verify its authority to delete credentials and execute the deletion without requiring continuous communication with remote authentication systems, making the system self-sufficient for credential management.
2Ease of operation
If commerce credentials are deleted without network connectivity, then ease of operation is improved, but reliability and security verification worsen
Solution Approach 1:
The system implements feedback mechanisms where the electronic device communicates credential deletion status to the trusted service manager when network connectivity is available. The device provides feedback about its credential state, and the trusted service manager updates its records accordingly, ensuring both parties have consistent information about credential lifecycle events.
Solution Approach 2:
The trusted service manager performs preliminary actions by pre-establishing cryptographic trust relationships and security domain configurations during device provisioning. This preliminary setup enables the device to autonomously verify and execute credential deletions offline, with the understanding that verification and synchronization will occur when connectivity is restored.
3Productivity
If security domain functionality is permanently terminated locally, then ease of operation and speed are improved, but device complexity increases
Solution Approach 1:
The patent extracts the security domain management functionality into a separate secure element component that is physically or logically isolated from the main device processor. This extraction allows the secure element to independently manage credential lifecycle events including permanent termination, while the main device can initiate deletion commands without directly managing the complex cryptographic operations.
Solution Approach 2:
The trusted service manager acts as an intermediary that simplifies the interface between the electronic device and the complex secure element infrastructure. The TSM handles the complexity of cryptographic key management, security domain provisioning, and credential lifecycle coordination, allowing the device to issue simple commands without directly managing the underlying cryptographic complexity.
Data Source
AI summary
Systems, methods, and computer-readable media for managing credentials are provided. In one example embodiment, an electronic device may include a secure element with a security domain element stored on the secure element. The electronic device may also include a processor component that may be configured to, inter alia, permanently terminate the functionality of the security domain element, after the functionality has been permanently terminated, communicatively couple the electronic device to a trusted service manager, and transmit data to the communicatively coupled trusted service manager that may be usable by the trusted service manager to determine that the functionality has been permanently terminated. Additional embodiments are also provided.


