Secure Element Credential Data Storage via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The provisioning of commerce credentials on portable electronic devices is often insecure and inefficient due to the lack of secure and efficient methods for storing and managing credential service provider data in secure elements.

Innovation Solution

The method involves storing credential service provider data in a security domain of a secure element before use, establishing a secure communication channel, and generating a new security domain upon provisioning, using a secure element vendor system and commercial entity subsystem to encrypt and manage keys, thereby reducing the time and information required for credential provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credential service provider data is stored in a security domain of a secure element, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure element is divided into multiple security domains, with each domain dedicated to storing credential service provider data from specific providers. This segmentation isolates different credential types and providers into separate secure containers, enhancing security through compartmentalization while maintaining manageable complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Credential service provider data is pre-provisioned and stored in the security domain during device manufacturing or initial setup, before the device is activated or used. This preliminary action eliminates the need for real-time provisioning during operation, reducing complexity of the provisioning process while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If credential service provider data is pre-stored in the secure element, then provisioning time is reduced, but information storage requirements increase

Engineering Contradiction:
Improveprovisioning timeVSAvoidinformation storage
Core Design Contradiction:
Loss of timeVSQuantity of substance

Solution Approach 1:

Only the essential credential service provider data required for secure communication and authentication is extracted and stored in the security domain, rather than storing complete credential sets. This extraction approach minimizes storage requirements while enabling fast provisioning through the use of cryptographic keys and authentication credentials.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms large credential datasets into compact cryptographic representations (such as public keys, authentication tokens, or hashed credentials) that can be efficiently stored in the secure element. This parameter transformation maintains the security and functionality of the original credentials while dramatically reducing storage requirements and accelerating provisioning time.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10929843B2Storage of credential service provider data in a security domain of a secure element
Publication Date: 2021.02.23 APPLE INC
  • US10929843B2 patent drawing
  • US10929843B2 patent drawing
  • US10929843B2 patent drawing

AI summary

Systems, methods, and computer-readable media for efficiently storing credential service provider data in a security domain of a secure element of an electronic device are provided. In one example embodiment, an electronic device may include a secure element that, inter alia, receives credential service provider data from a secure element vendor subsystem, and that encrypts a key of the secure element with the received credential service provider data. The electronic device may also include a communications component that transmits the encrypted key to a credential service provider. Additional embodiments are also provided.