Embedded Secure Element Field Personalization via Key Diversification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing procedures for personalizing secure elements are complex, time-consuming, and costly, requiring separate operations for each element and strict security measures, including the need for highly secure personalization sites due to the handling of secret data.
Innovation Solution
The secure element is configured to generate a derivation key for personalization data within itself upon loading a new operating system, allowing for remote personalization in the field and eliminating the need for pre-personalization, thereby simplifying manufacturing and enhancing security by avoiding direct transfer of secret data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure elements are personalized at the manufacturing site using existing procedures, then each element receives its specific secret data, but the process becomes complex, time-consuming, and costly requiring highly secure personalization sites
Solution Approach 1:
The patent extracts the secret data from the personalization process itself and stores it directly in the secure element during manufacturing. The personalization data is then generated locally by the secure element using its unique identifier and the stored secret data, eliminating the need for complex external personalization sites that handle sensitive data transmission.
Solution Approach 2:
The secure element performs self-personalization by generating its own personalization data using its unique identifier and the secret data already stored in its secure memory. This self-service approach eliminates the need for external personalization systems and reduces process complexity while maintaining security.
2Manufacturing precision
If secure elements are personalized at the manufacturing site, then each element has its specific data, but the process is time-consuming and reduces productivity
Solution Approach 1:
The patent performs the critical action of storing secret data in the secure element during manufacturing, before the elements are distributed. This preliminary action enables rapid local generation of personalization data at each secure element without requiring time-consuming external personalization processes, thereby increasing productivity while maintaining precision.
3Ease of operation
If secret personalization data is transferred to personalization sites, then personalization can be performed, but strict security measures and secure links are required increasing system complexity
Solution Approach 1:
The patent extracts secret data from the personalization process and stores it permanently in the secure element during manufacturing. This extraction eliminates the need for transferring sensitive personalization data to external sites, removing the requirement for secure communication links and reducing security infrastructure complexity while maintaining personalization capability.
4Productivity
If identical secure elements are manufactured in mass without personalization, then production is simplified and faster, but the elements cannot be used until personalized
Solution Approach 1:
The patent performs the preliminary action of storing secret data in each secure element during mass production. This enables the elements to be manufactured quickly in identical form, and then automatically personalized in the field using their unique identifiers and stored secret data, eliminating deployment delays while maintaining high manufacturing efficiency.
Data Source
AI summary
A method for personalizing embedded secure elements, eSE, allows for simplified manufacturing before being integrated into host devices. An eSE implements services executed by an embedded operating system, OS, whereupon it is loaded into the eSE. The non-personalized eSE comprises an OS loader and a master cryptographic key common to a plurality of secure elements. It can therefore be produced in large numbers. The OS loader obtains an operating system package from a server and installs it. In response to the installation, the OS loader generates a derivation cryptographic key by diversifying the master cryptographic key, and then the OS generates personalized data by deriving pre-personalization data with the derivation key. The eSE, deployed in the field in a simple non-personalized state, is fully personalized without exchanging secret personalized data.


