Secure Element Activation via Contactless Registry Service Applet
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile payment systems lack secure and efficient mechanisms for temporarily activating the secure element in portable electronic devices for authorized transactions, potentially leading to unauthorized access and data compromise.
Innovation Solution
The implementation of a secure electronic device with a contactless registry service (CRS) applet that detects user input, such as a double button press, to initiate and manage payment transactions, ensuring that the secure element is only activated after authorized input and deactivating it if no transaction is completed within a set time frame.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the secure element is continuously activated to enable payment transactions, then transaction availability is improved, but security risk increases due to potential unauthorized access
Solution Approach 1:
The secure element transitions between inactive and active states dynamically based on user input and authorization status. The system activates the secure element only when needed (upon detecting valid user input and receiving authorization) and deactivates it afterward, creating a dynamic state change that balances availability with security.
Solution Approach 2:
The system performs preliminary validation by detecting user input (such as double button press) and asserting flags before activating the secure element. This preliminary action ensures that only authorized users can trigger secure element activation, preventing unauthorized access while maintaining transaction availability when proper authentication occurs.
2Speed
If the secure element is activated without user input verification, then transaction speed is improved, but security control is worsened
Solution Approach 1:
The system implements preliminary user input detection (such as double button press) and flag assertion before secure element activation. This preliminary verification step ensures security control is maintained while allowing rapid transaction processing once authorization is confirmed, balancing speed with security.
3Ease of operation
If the secure element remains active for extended periods, then transaction convenience is improved, but exposure to harmful factors increases
Solution Approach 1:
The secure element operates in periodic cycles rather than continuous activation. It activates only when user input is detected and authorization is received, performs the transaction, and then deactivates. This periodic operation pattern minimizes exposure to harmful factors while maintaining transaction convenience when needed.
Solution Approach 2:
The system dynamically adjusts the secure element's operational state based on real-time conditions. Rather than remaining continuously active for convenience, the secure element transitions between inactive and active states only when properly authenticated, reducing exposure to unauthorized access while maintaining convenience for legitimate transactions.
Data Source
AI summary
A system for provisioning credentials onto an electronic device is provided. The user device may include a secure element and a corresponding trusted processor. A contactless registry service (CRS) applet running on the secure element may be used to manage the activation of one or more associated payment applets during a mobile payment transaction. The CRS applet may include at least a user input received flag and an authorization received flag. The user input received flag may be asserted in response to detecting a required user input for initiating payment. The authorization received flag may be asserted when the trusted processor sends an activation request to the secure element. A payment applet should only be activated when at least one of the user input received flag and the authorization received flag has been asserted.


