Secure Element Key Derivation for Resource Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing resource management systems for smart cards require multiple keys to manage and configure resources, which complicates the distribution chain and security, especially after the secure element is put on the market, as multiple parties are involved and need access to various keys for managing Virtual Cards.

Innovation Solution

A method where a licensor stores a resource management key and derivation function in the secure element, generating a wholesale key for the licensee, allowing efficient configuration and validation of resources using a validation key, ensuring that only authorized parties can configure and access the resources, thereby reducing the number of keys needed and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple keys are used to manage Virtual Cards in the distribution chain, then security and access control for different parties are improved, but device complexity and key management complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the key management approach by changing the parameter of key derivation. Instead of managing multiple independent keys, a single master key is used with a derivation function that generates different operational keys (wholesale key, validation key) as needed. This parameter change reduces key management complexity while maintaining security through cryptographic derivation.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The master key stored in the secure element serves multiple functions: it derives the wholesale key for license configuration, generates validation keys for configuration verification, and enables the secure element to independently validate configurations after detachment. This multi-functionality eliminates the need for separate key management systems for each party in the distribution chain.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If the secure element is detached from the licensor after being put on the market, then independence and flexibility are improved, but security validation capability is worsened

Engineering Contradiction:
ImproveindependenceVSAvoidsecurity validation capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The licensor performs preliminary actions by storing both the master key and the derivation function directly in the secure element before detachment. This preliminary configuration enables the secure element to independently generate and validate configuration requests without requiring continuous connection to the licensor, thus maintaining security validation capability while achieving operational independence.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The secure element is equipped with the derivation function and master key to perform self-validation of configuration requests. Instead of relying on external validation from the licensor, the secure element can independently verify configurations using its own cryptographic capabilities, achieving self-service security validation that maintains reliability while enabling detachment and independence.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2541458B1Resource management system and corresponding method
Publication Date: 2017.10.04 NXP BV
  • EP2541458B1 patent drawingFigure 1
  • EP2541458B1 patent drawingFigure 2
  • EP2541458B1 patent drawingFigure 3

AI summary

The invention provides a secure and efficient resource management system and a corresponding method for managing resources of a product that is put on the market by a licensor via a distribution chain. In particular, the number of keys needed for managing said resources can be reduced. At the time that the product is released to the market the exact licensing conditions of the product need not be known yet. The licensing conditions and the associated configuration of resources of the product are managed via a second key which is provided to a licensee. The licensee, however, has no knowledge of the first key and the derivation function which generates said second key based on the first key. Therefore, it is ensured that the licensee cannot claim more resources of the product than the licensor allows.