Secure Element Diagnostic Collection for False Alarm Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing NFC-based mobile payment devices face reliability issues due to false security alarms, which can lead to system resets and device unavailability, causing significant customer returns and financial losses, as these alarms are difficult to predict and eliminate during development.
Innovation Solution
A method is introduced to continuously collect diagnostic information from a device's rich execution environment and secure element, storing and analyzing potential security-related events to differentiate between genuine and false alarms, allowing for adjustments and improvements without compromising security, and enabling insights for future product design.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security countermeasures are implemented to detect security events, then security detection capability is improved, but device reliability deteriorates due to false alarms causing system resets
Solution Approach 1:
The patent implements preliminary action by collecting and storing diagnostic information before security events occur. The system continuously gathers data about system state, sensor readings, and operational parameters, so that when a security event is detected, the relevant diagnostic information is already available for analysis to determine whether it was a genuine attack or a false alarm.
Solution Approach 2:
The patent implements feedback by establishing a mechanism where diagnostic information is analyzed after security events to provide insights that feed back into the system. This feedback loop allows the system to learn from false alarms and adjust its security response behavior, reducing the impact of false alarms on device reliability while maintaining security detection capability.
2Reliability
If security events are automatically responded to by resetting the system, then security response capability is improved, but device usability deteriorates due to unexpected system resets
Solution Approach 1:
The system performs preliminary action by pre-collecting and storing diagnostic information before security events occur. When a security event triggers a system reset, the diagnostic data is already captured and can be used to analyze whether the reset was necessary, allowing for smarter security responses that preserve usability.
Solution Approach 2:
The patent implements feedback by analyzing security events and their outcomes to learn from patterns. This feedback mechanism enables the system to distinguish between genuine security threats requiring reset and false alarms causing unnecessary resets, thereby maintaining both security effectiveness and device usability.
3Reliability
If diagnostic information collection is implemented to monitor device reliability, then device monitoring capability is improved, but device complexity increases
Solution Approach 1:
The patent applies universality by designing the diagnostic information collection system to serve multiple functions. The same diagnostic collection infrastructure used for reliability monitoring also supports security event analysis, attack log generation, and future product design insights, reducing the need for separate dedicated systems.
Solution Approach 2:
The patent uses an intermediary approach by introducing a diagnostic information collection and analysis layer that mediates between the security event detection system and the overall device operation. This intermediary layer processes and analyzes data without requiring fundamental changes to the core security or operational systems.
Data Source
AI summary
A method is provided for collecting diagnostic information in a device having a rich execution environment (REE) and a secure element (SE). The method includes detecting initialization of the device. If it is determined that the initialization of the device was a result of a potential security related event, a communication component of the REE responsible for communicating with the secure element is activated if not already activated. The secure element sends a request to the communication component for diagnostic information related to the security event. The diagnostic information is received in the SE from the communication component and stored in an attack log for storing security events. An attack log is generated in the secure element including the potential security event and the related diagnostic information. The attack log and the related diagnostic information is communicated to a secure server via a secure channel.


