Secure Element Key Derivation for Resource Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing resource management systems for smart cards require multiple keys to manage and configure resources, which complicates the distribution chain and security, especially after the secure element is put on the market, as multiple parties are involved and need access to various keys for managing Virtual Cards.
Innovation Solution
A method where a licensor stores a resource management key and derivation function in the secure element, generating a wholesale key for the licensee, allowing efficient configuration and validation of resources using a validation key, ensuring that only authorized parties can configure and access the resources, thereby reducing the number of keys needed and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple keys are used to manage Virtual Cards in the distribution chain, then security and access control for different parties are improved, but device complexity and key management complexity increase
Solution Approach 1:
The patent transforms the key management approach by changing the parameter of key derivation. Instead of managing multiple independent keys, a single master key is used with a derivation function that generates different operational keys (wholesale key, validation key) as needed. This parameter change reduces key management complexity while maintaining security through cryptographic derivation.
Solution Approach 2:
The master key stored in the secure element serves multiple functions: it derives the wholesale key for license configuration, generates validation keys for configuration verification, and enables the secure element to independently validate configurations after detachment. This multi-functionality eliminates the need for separate key management systems for each party in the distribution chain.
2Adaptability or versatility
If the secure element is detached from the licensor after being put on the market, then independence and flexibility are improved, but security validation capability is worsened
Solution Approach 1:
The licensor performs preliminary actions by storing both the master key and the derivation function directly in the secure element before detachment. This preliminary configuration enables the secure element to independently generate and validate configuration requests without requiring continuous connection to the licensor, thus maintaining security validation capability while achieving operational independence.
Solution Approach 2:
The secure element is equipped with the derivation function and master key to perform self-validation of configuration requests. Instead of relying on external validation from the licensor, the secure element can independently verify configurations using its own cryptographic capabilities, achieving self-service security validation that maintains reliability while enabling detachment and independence.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention provides a secure and efficient resource management system and a corresponding method for managing resources of a product that is put on the market by a licensor via a distribution chain. In particular, the number of keys needed for managing said resources can be reduced. At the time that the product is released to the market the exact licensing conditions of the product need not be known yet. The licensing conditions and the associated configuration of resources of the product are managed via a second key which is provided to a licensee. The licensee, however, has no knowledge of the first key and the derivation function which generates said second key based on the first key. Therefore, it is ensured that the licensee cannot claim more resources of the product than the licensor allows.