Secure Element Post-Issuance Domain Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure elements in communication devices are pre-personalized and pre-configured during manufacturing, limiting their capacity utilization and flexibility for post-issuance operations, as they are linked to a single entity, preventing service providers from offering new services and users from accessing required applications due to security and management constraints.
Innovation Solution
A method for dynamic post-issuance operations on secure elements, allowing creation of new security domains, loading applications, and management functions remotely, by collecting and sending specific data to the controlling party via communication devices, enabling previously unknown parties to collaborate and reconfigure the secure element's content post-manufacturing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the storage area of the secure element is linked to a single entity (SE issuer) and used exclusively by this entity, then security and control are improved, but the utilization of storage capacity and adaptability to new services deteriorate
Solution Approach 1:
The secure element's storage area is divided into multiple security domains, each of which can be independently managed by different entities. The first security domain is managed by the SE issuer, while the second security domain can be managed by service providers or other authorized parties. This segmentation allows the system to maintain security through controlled access while improving adaptability by enabling multiple services to coexist in separate domains.
Solution Approach 2:
The system enables dynamic post-issuance operations where security domains can be created, modified, or transferred after the secure element is issued. Service providers can dynamically establish their own security domains and manage applications without requiring reconfiguration of the entire secure element, thereby improving adaptability while maintaining security through controlled dynamic operations.
2Ease of manufacture
If the secure element is pre-personalized and pre-configured during manufacturing, then the initial security and functionality are improved, but the ability to reconfigure content and adapt to changing demands deteriorates
Solution Approach 1:
The secure element is pre-personalized during manufacturing with initial security settings and a first security domain established by the SE issuer. This preliminary action ensures secure initial configuration and establishes the foundation for future operations. The pre-configured structure includes mechanisms that enable subsequent post-issuance operations to add or modify security domains without compromising the initial security setup.
Solution Approach 2:
The system supports dynamic post-issuance operations where additional security domains can be created and configured after manufacturing. Service providers can install applications and configure security parameters dynamically, allowing the secure element to adapt to changing service demands while maintaining the security integrity established during initial manufacturing.
3Reliability
If the entire storage area is exclusively managed by the SE issuer, then control and security are improved, but the economic utilization of storage capacity and ability to offer new services deteriorate
Solution Approach 1:
The storage area is segmented into multiple security domains with distinct control rights. The SE issuer maintains control over the first security domain, while service providers can be granted control over additional domains. This segmentation enables shared control models that improve storage capacity utilization by allowing multiple entities to deploy services simultaneously, while maintaining security through controlled access rights for each domain.
Solution Approach 2:
The system introduces intermediary mechanisms that enable service providers to establish and manage their own security domains with the authorization of the SE issuer. These intermediary structures allow delegated control where service providers can economically utilize storage capacity for their services while the SE issuer maintains overall security oversight and control through the first security domain.
4Ease of operation
If pre-loaded applications are installed on the secure element during manufacturing, then initial functionality is improved, but the ability to download and install new applications post-issuance deteriorates
Solution Approach 1:
The system segments the secure element into multiple security domains where the first domain contains pre-loaded applications for initial functionality, while subsequent domains can be dedicated to post-issuance applications downloaded from remote servers. This segmentation allows both pre-configured functionality and flexible post-issuance application deployment to coexist without interfering with each other, improving both ease of operation and adaptability.
Solution Approach 2:
The system enables dynamic addition of security domains and applications after issuance. Service providers can download applications and configure new security domains post-issuance, allowing the secure element to evolve and adapt to new service requirements. The dynamic mechanism maintains the pre-loaded initial applications while enabling flexible future extensions through controlled post-issuance operations.
Data Source
AI summary
The invention relates to a method for enabling post issuance operation on a secure element connectable to a communication device. The method allows an SE controlling party to perform remotely operations such as creation of new security domains for an external party, loading, and installation of applications of an external party and management functions including personalization and activation of applications loaded on the SE for an external party. The method includes the steps of:collecting data stored on the SE suitable for identification of the SE and data for contacting the SE controlling party;creating an initial data packet from the collected data,sending the data packet to a party which can be the external party, an agent of the external party, the SE controlling party, an agent of the SE controlling party.The invention further relates to a communication device and a software application for implementing the method.


