Secure Element Command Filtering via Hardware Link Signal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing mono interface configuration between an application processor and a secure element in communication devices is insecure, as it cannot differentiate between commands from the application processor and other external entities, making it vulnerable to malicious attacks.

Innovation Solution

Implementing a hardware link between the application processor and the secure element to transmit a hardware signal triggered by the application processor only when sending a command, allowing the secure element to reject commands not activated by the GPIO signal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dual hardware interface is used to differentiate command sources, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidinterface complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent adds a new dimension of control by introducing a hardware link (GPIO signal) that operates independently from the existing communication interface. This hardware dimension provides binary authorization (authorized/unauthorized) that complements the communication interface, enabling the secure element to differentiate command sources without adding multiple communication interfaces. The hardware link acts as a gatekeeper that works in conjunction with the existing mono interface.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If a dual hardware interface is used to differentiate command sources, then security is improved, but development cost increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevelopment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent uses a copied/simplified version of the interface concept by reusing the existing GPIO signaling mechanism already present in the system for other purposes. Instead of creating a completely new communication interface, the solution copies the authorization function to the hardware domain using existing pins and signaling capabilities, significantly reducing development and manufacturing costs compared to implementing a full dual-interface architecture.

Inventive Principle:
Principle #26Copying

3Reliability

If a hardware link is added to transmit authorization signals, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidhardware link
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the hardware authorization function with the existing communication interface by using the same physical connection path. The hardware link is integrated into the existing interface architecture rather than being implemented as a separate parallel interface, allowing the secure element to receive both communication commands and authorization signals through the same interface pathway, thereby minimizing additional hardware complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4348470B1Secure applet access protection
Publication Date: 2025.03.05 THALES DIS FRANCE SA
  • EP4348470B1 patent drawingFigure 1~4
  • EP4348470B1 patent drawingFigure 5

AI summary

The present invention relates to a device having at least an application processor (AppP), a communication module (ComM) having a secure element (SE) that comprises a secure applicative applet (SA), said application processor (AppP) accessing the secure applicative applet (SA) in the secure element (SE) via the communication module (ComM) using a mono interface configuration, said device being further such that it comprises an hardware link (HWL) between the application processor (AppP) and the secure element (SE) to transmit an hardware signal (HWS) triggered by the application processor (AppP) only when the application processor (AppP) sends a command (C(SA)), the secure element (SE) being such that, when the hardware signal (HWS) is not activated, any received command (C(SA)) aiming the secure applicative applet (SA) is rejected.