Secure Element Key Change for Settlement Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing terminals face challenges in reliably changing encryption keys for secure elements, particularly due to variations in semiconductor chip vendors and types, which complicates secure settlement services like electronic money transactions.

Innovation Solution

An information processing terminal with a secure element and a processing unit that changes the initial shipment key to a new encryption key, using setting information stored in a protection area, and a tamper-resistant device to manage this key change, ensuring secure and reliable operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a key change process is implemented in secure elements from different vendors and chip types, then the security of settlement services is improved, but the complexity of the key change process increases due to vendor and chip type variations

Engineering Contradiction:
Improvesecurity of settlement servicesVSAvoidcomplexity of key change process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal key change process that works across multiple secure element vendors and chip types by defining a standardized interface and information structure. The setting information format and key change methodology are designed to be vendor-agnostic, allowing the same process to function across different secure element implementations while maintaining security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameters of the key change process by storing setting information (including key derivation parameters, algorithm identifiers, and vendor-specific adaptations) within the secure element itself. This allows the system to adapt to different vendors and chip types by reading and interpreting the setting information locally, rather than requiring external configuration or complex vendor-specific procedures.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If setting information is stored in the protection area at shipment, then the key change reliability is improved, but the security risk increases due to potential exposure of key derivation information

Engineering Contradiction:
Improvekey change reliabilityVSAvoidsecurity risk of key derivation information exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the sensitive information stored in the protection area by separating actual cryptographic keys from key derivation parameters. The setting information includes metadata, algorithm identifiers, and derivation parameters rather than the keys themselves. This segmentation allows the system to store necessary configuration data while minimizing the exposure of directly usable cryptographic material.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces setting information as an intermediary layer between the stored data and the actual key derivation process. This intermediary contains the necessary parameters and instructions for key generation without exposing the derived keys or master secrets. The setting information acts as a secure configuration that guides the key change process without containing directly exploitable cryptographic material.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12095902B2Information processing terminal, information processing device, information processing method, program, and information processing system
Publication Date: 2024.09.17 FELICA NETWORKS INC
  • US12095902B2 patent drawing
  • US12095902B2 patent drawing
  • US12095902B2 patent drawing

AI summary

There is provided an information processing terminal, an information processing device, an information processing method, a program, and an information processing system which enable key change to be performed more reliably. A user terminal includes: a secure element that has a protection area in which an area in which data to be protected is stored is protected by an encryption key; and a processing execution unit that executes a process of changing, in the secure element, a first key used at a time of shipment to a second key different from the first key. Setting information which is referred to when the first key is changed to the second key is stored at the time of shipment in the protection area. A server device includes: a tamper resistant device that stores a master key serving as a master of the first key and is protected from analysis from outside; and a processing device that performs, by using the master key stored in the tamper resistant device, a process of changing the first key to the second key on the basis of the setting information. The present technology can be applied to, for example, an information processing system that provides a settlement service.