Secure Element Credential Segmentation for Content Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies lack effective solutions for securely managing the accessibility, download, storage, and consumption of content and applications on electronic devices, particularly in ensuring confidentiality and security of private information.
Innovation Solution
The use of a secure element, such as a universal integrated circuit card (UICC), and a Secure Device Processor (SDP) as a secure download platform, which provides a secure means of browsing, downloading, storing, and rendering content and applications by utilizing secret and non-secret credentials and permissions, ensuring secure authentication and access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If content and applications are made accessible from various sources, then user convenience and content availability are improved, but security and confidentiality of private information deteriorate
Solution Approach 1:
The system segments credentials into two distinct types: secret credentials (stored in secure element) and non-secret credentials (stored in device memory). This segmentation allows the system to access content from multiple sources while maintaining security by isolating sensitive authentication data from the main processing environment.
Solution Approach 2:
A secure element acts as an intermediary component between the content access system and the credentials. It securely stores secret credentials and participates in authentication processes without exposing the credentials to the main device processor, thereby enabling content availability while preserving security.
2Reliability
If secret information is stored in a secure element, then security and confidentiality are improved, but device complexity increases
Solution Approach 1:
The system merges the secure element with the device's existing authentication and content access mechanisms. Rather than creating a completely separate security subsystem, the secure element is integrated into the existing credential verification processes, reducing overall system complexity while maintaining enhanced security.
Solution Approach 2:
The secure element is designed to handle multiple credential types and support various authentication scenarios. By making the secure element universal, the system can manage different types of content and applications through a single security infrastructure, thereby reducing complexity compared to having separate security mechanisms for each content type.
3Reliability
If dual verification process is implemented, then access security is improved, but processing time and operational complexity increase
Solution Approach 1:
The system performs preliminary verification using non-secret credentials stored in device memory before initiating the more time-consuming verification using secret credentials from the secure element. This preliminary check can quickly reject unauthorized access attempts without requiring the full dual verification process, thereby reducing average processing time while maintaining security.
Solution Approach 2:
The secure element autonomously performs verification of secret credentials without requiring intervention from the main device processor or user input. This self-service capability streamlines the dual verification process by handling the security-critical portion independently and efficiently, reducing overall processing time and operational complexity.
Data Source
AI summary
A system that incorporates the subject disclosure may perform, for example, receive secret information and non-secret information from a secure download application function, provide a request for a first verification to a secure element where the first verification is associated with access to content and/or an application that is accessible via the secure download application function, receive the first verification which is generated by the secure element based on the secret information without providing the secret information to the secure device processor, receive the non-secret information from the secure element, and generate a second verification for the access based on the non-secret information, where the content and/or application is accessible from the secure download application function responsive to the first and second verifications. Other embodiments are disclosed.


