Secure Element Digital Key Authentication Without Provider Burden
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital key technologies face security vulnerabilities and burden service providers with complex operations, requiring a secure and efficient method for processing and authenticating digital keys.
Innovation Solution
A secure element (SE) with a communication interface, memory, and processor is used to process and authenticate digital keys, including generating, removing, and managing keys, while providing service-specific authentication and management through a service-provider-specific service performance manager.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If digital keys are stored in mobile devices using conventional methods, then user convenience is improved, but security vulnerabilities increase due to exposure to hacking
Solution Approach 1:
The system segments the digital key management function into a separate secure element (SE) that is physically or logically isolated from the main mobile device processor. The SE contains dedicated hardware for key storage and authentication operations, preventing attackers from accessing keys through software vulnerabilities in the main device. This segmentation allows the mobile device to provide convenient user interface while the SE provides secure key management.
Solution Approach 2:
The secure element acts as an intermediary between the mobile device and the authentication server. Instead of the mobile device directly communicating with the server for key operations, the SE mediates these communications by receiving requests from the mobile device, performing secure authentication operations using stored keys, and returning results. This intermediary role protects the keys from exposure during communication.
2Device complexity
If digital keys are unilaterally stored in mobile devices by service providers, then key management is simplified, but service provider burden and processing time increase
Solution Approach 1:
The secure element performs authentication operations in advance by pre-storing cryptographic keys and authentication data from the service provider. When a user needs authentication, the SE can immediately perform cryptographic operations using these pre-loaded credentials without requiring real-time communication with the service provider's server. This preliminary action eliminates waiting time for server responses while the service provider only needs to initially provision the SE.
Solution Approach 2:
The secure element provides self-service capabilities by autonomously performing authentication operations using stored credentials. The SE can independently generate cryptographic signatures, verify authentication tokens, and manage key operations without requiring service provider intervention for each operation. This self-service approach reduces the service provider's operational burden while maintaining security through the SE's isolated environment.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A secure element (SE) for processing a digital key includes a communication interface for communicating with a host, a memory for storing programs and data for processing the digital key, and a processor for executing the programs stored in the memory to receive a digital key processing request from a target device, determine whether a service is providable to the target device, by using a service-provider-specific service performance manager, process the digital key by using a digital key manager based on digital key processing information stored in the memory, upon determining that a service is providable to the target device, issue a digital key processing certificate by using the service-provider-specific service performance manager based on authentication information stored in the memory, and transmit the digital key processing certificate to at least one of a service provider and the target device.