Secure Element Credential Segmentation for Content Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies lack effective solutions for securely managing the accessibility, download, storage, and consumption of content and applications on electronic devices, particularly in ensuring confidentiality and security of private information.

Innovation Solution

The use of a secure element, such as a universal integrated circuit card (UICC), and a Secure Device Processor (SDP) as a secure download platform, which provides a secure means of browsing, downloading, storing, and rendering content and applications by utilizing secret and non-secret credentials and permissions, ensuring secure authentication and access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If content and applications are made accessible from various sources, then user convenience and content availability are improved, but security and confidentiality of private information deteriorate

Engineering Contradiction:
Improvecontent availabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments credentials into two distinct types: secret credentials (stored in secure element) and non-secret credentials (stored in device memory). This segmentation allows the system to access content from multiple sources while maintaining security by isolating sensitive authentication data from the main processing environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure element acts as an intermediary component between the content access system and the credentials. It securely stores secret credentials and participates in authentication processes without exposing the credentials to the main device processor, thereby enabling content availability while preserving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secret information is stored in a secure element, then security and confidentiality are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the secure element with the device's existing authentication and content access mechanisms. Rather than creating a completely separate security subsystem, the secure element is integrated into the existing credential verification processes, reducing overall system complexity while maintaining enhanced security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure element is designed to handle multiple credential types and support various authentication scenarios. By making the secure element universal, the system can manage different types of content and applications through a single security infrastructure, thereby reducing complexity compared to having separate security mechanisms for each content type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dual verification process is implemented, then access security is improved, but processing time and operational complexity increase

Engineering Contradiction:
Improveaccess securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary verification using non-secret credentials stored in device memory before initiating the more time-consuming verification using secret credentials from the secure element. This preliminary check can quickly reject unauthorized access attempts without requiring the full dual verification process, thereby reducing average processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The secure element autonomously performs verification of secret credentials without requiring intervention from the main device processor or user input. This self-service capability streamlines the dual verification process by handling the security-critical portion independently and efficiently, reducing overall processing time and operational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11477211B2Apparatus and method for securely managing the accessibility to content and applications
Publication Date: 2022.10.18 AT&T INTELLECTUAL PROPERTY I L P
  • US11477211B2 patent drawing
  • US11477211B2 patent drawing
  • US11477211B2 patent drawing

AI summary

A system that incorporates the subject disclosure may perform, for example, receive secret information and non-secret information from a secure download application function, provide a request for a first verification to a secure element where the first verification is associated with access to content and/or an application that is accessible via the secure download application function, receive the first verification which is generated by the secure element based on the secret information without providing the secret information to the secure device processor, receive the non-secret information from the secure element, and generate a second verification for the access based on the non-secret information, where the content and/or application is accessible from the secure download application function responsive to the first and second verifications. Other embodiments are disclosed.