Secure Element Personalization Using HSM Shared-Secret Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for personalizing secure elements in mobile devices result in the Secure Element manufacturer losing control over the personalization process, making them vulnerable to misuse by the mobile device manufacturer.
Innovation Solution
A method involving a shared secret between the Secure Element and a Hardware Security Module (HSM) is established before installation, allowing encryption and decryption of the operating system outside the mobile device, ensuring the Secure Element manufacturer retains control over the personalization process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the Secure Element is permanently installed in the mobile device and personalized by the device manufacturer, then the personalization process becomes simpler and faster, but the Secure Element manufacturer loses control over the personalization process and becomes vulnerable to misuse
Solution Approach 1:
The patent applies preliminary action by establishing a shared secret between the Secure Element and HSM before the personalization process begins. This pre-established cryptographic relationship ensures that the Secure Element manufacturer maintains control over the personalization process even when the device manufacturer performs the actual personalization, thus resolving the contradiction between efficiency and control.
Solution Approach 2:
The patent introduces a Hardware Security Module (HSM) as an intermediary that holds one part of the shared secret. The HSM acts as a mediator that enables secure communication and verification during personalization, allowing the Secure Element manufacturer to maintain control while enabling efficient personalization by the device manufacturer.
2Reliability
If the operating system is stored in encrypted form in external NVM storage, then the Secure Element data security is improved, but the device itself cannot decrypt or execute the Secure Element data
Solution Approach 1:
The patent applies segmentation by dividing the decryption capability into two parts: the encryption key is stored in the Secure Element while the encrypted data is stored in external NVM storage. This segmentation ensures that only the Secure Element can decrypt and execute its own data, enhancing security while maintaining operational capability.
Solution Approach 2:
The patent implements self-service by enabling the Secure Element to decrypt and execute its own encrypted operating system and data from external NVM storage. The Secure Element uses its internal key to autonomously decrypt the data it needs, eliminating the need for external decryption mechanisms and ensuring that only authorized data can be accessed.
3Reliability
If a shared secret is established between the Secure Element and HSM before installation, then the Secure Element manufacturer retains control over personalization, but the process becomes more complex
Solution Approach 1:
The patent extracts the cryptographic control mechanism into a separate Hardware Security Module (HSM) that is distinct from both the Secure Element and the mobile device. This extraction allows the shared secret establishment to occur independently during manufacturing, maintaining security control while simplifying the integration process for device manufacturers.
Data Source
Figure 1~2(d)
Figure 3~4
Figure 5~6
AI summary
The invention provides a method for personalizing an integrated Secure Element that is permanently installed in a mobile device, comprising agreeing on a shared secret between the Secure Element and an HSM, encrypting an operating system - and optionally personalization data and/or one or more profiles - in the HSM based on the shared secret and transferring the encrypted operating system to the Secure Element, as well as re-encrypting the operating system in the Secure Element for storage in the NVM memory of the mobile device.