Secure Element Application Deployment via Trusted Server Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for installing applications in secure elements of mobile communication terminals are complex, time-consuming, and costly due to the need for multiple data exchanges between various actors, which can be slowed down by the availability of these actors and require direct relationships that complicate data transmission.

Innovation Solution

A method that centralizes data flows by using a call program to establish secure domains in the secure element, facilitating data exchanges between trusted servers and ensuring secure application installation through a streamlined process involving fewer direct interactions between these servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple data exchanges are established between various actors (secure element provider, service providers, trusted servers) to ensure secure application installation, then security is improved, but the complexity of the system increases and the installation process becomes time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted server as an intermediary that centralizes the management of secure domains. Instead of requiring direct interactions between multiple actors (secure element provider, service providers, etc.), the trusted server acts as a mediator that handles all communication and coordination. This reduces system complexity by consolidating multiple data exchange channels into a single centralized point while maintaining security through the trusted server's role in managing access keys and coordinating application installation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple data exchanges are established between various actors to ensure secure application installation, then security is improved, but the installation time increases due to dependency on simultaneous availability of all actors

Engineering Contradiction:
ImprovesecurityVSAvoidinstallation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The trusted server performs preliminary actions by pre-establishing secure domains and preparing access keys before actual application installation is requested. When a service provider wants to install an application, the trusted server has already created the secure domain and is ready to provide the access key immediately. This eliminates the need for all actors to be simultaneously available during the installation process, as the trusted server has prepared everything in advance, thereby reducing installation time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If direct relationships between multiple actors are required for data transmission, then security control is improved, but the ease of operation deteriorates due to coordination difficulties

Engineering Contradiction:
Improvesecurity controlVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the roles of multiple actors into a single trusted server that handles all coordination for secure domain management. Instead of requiring the secure element provider, service providers, and other actors to establish direct relationships and coordinate separately, their functions are combined in the trusted server. This consolidation maintains security control through the trusted server's centralized management of access keys and secure domains, while dramatically improving ease of operation by eliminating the need for complex multi-party coordination.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3107030B1Method for deploying an application in a secure domain in a secure element
Publication Date: 2024.07.24 IDEMIA FRANCE SAS
  • EP3107030B1 patent drawingFigure 1

AI summary

A method for deploying an authentication application in a secure element of a communication terminal comprising an insecure processing unit executing a program that calls authentication applications. The method includes the step of transferring data via at least one communication network between a first trusted server associated with a security element provider to execute a first security element management program, a second trusted server associated with at least one authentication application provider to execute an authentication application management program, and the communication terminal, to create a secure domain in the secure element and install the authentication application therein.