Secure Element Data Transfer Between Application Instances

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for upgrading applications in secure elements often result in data loss and require significant bandwidth for transferring user data between old and new instances, posing security risks and inefficiencies.

Innovation Solution

Establishing a communication channel within the secure element between instances of an old and new package, allowing the old instance to lock and transfer its data in a common transport format to the new instance, which stores it in its own format, thereby avoiding external data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user data is transferred externally via remote server during application upgrade, then data can be backed up and restored, but bandwidth consumption increases and data security is compromised

Engineering Contradiction:
Improvedata backup and restore capabilityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent introduces an intermediary data storage area within the secure element that acts as a buffer between the old and new application instances. This internal intermediary eliminates the need for external server mediation, thereby reducing bandwidth consumption while maintaining data backup and restore capabilities through the secure element's internal memory resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user data is transferred externally via remote server during application upgrade, then data can be backed up and restored, but data security is compromised due to external transmission

Engineering Contradiction:
Improvedata backup and restore capabilityVSAvoiddata security risks during transmission
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary data storage area within the secure element that acts as a buffer between the old and new application instances. This internal intermediary eliminates the need for external server mediation, thereby reducing bandwidth consumption while maintaining data backup and restore capabilities through the secure element's internal memory resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If application upgrade is performed with external data transfer, then new version can be installed, but data loss may occur and upgrade process becomes complex

Engineering Contradiction:
Improveapplication version upgrade capabilityVSAvoiduser data loss during upgrade
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent performs preliminary actions by creating a new application instance alongside the existing one and pre-establishing the data transfer mechanism through the communication channel. The old instance prepares and transfers its data to the new instance before the old instance is deleted, ensuring data preservation and enabling a smooth upgrade process without data loss.

Inventive Principle:
Principle #10Preliminary action

4Object-affected harmful factors

If communication channel is established within secure element between instances, then data security is improved and bandwidth is reduced, but device complexity increases

Engineering Contradiction:
Improvedata security during upgradeVSAvoidinternal communication channel setup
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent utilizes the existing communication channel infrastructure of the secure element, which is designed to support multiple functions including data processing and storage. By repurposing this existing multi-functional channel for inter-instance data transfer, the patent avoids adding significant structural complexity while achieving secure internal data transmission.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3022678B1Method for transferring user data between two instances of an application
Publication Date: 2019.09.11 THALES DIS FRANCE SA
  • EP3022678B1 patent drawingFigure 1
  • EP3022678B1 patent drawingFigure 2
  • EP3022678B1 patent drawingFigure 3

AI summary

The invention is a method of transferring user data from a first instance of a package to a second instance of another package corresponding to an upgraded version. The first instance stores the user data in its own storage format. The two instances are embedded in a secure element. The method comprises the steps of: establishing a direct channel within the portable secure device between the two instances, - the first instance gets in a locked state where it refuses any service requests except the communication with the second instance, prepares a pack by formatting the user data in a transport format, and automatically sends the pack to the second instance through the direct channel, the second instance retrieves the user data from the pack and stores the user data in another storage format