Secure Element Local Management for Untrusted Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing telecommunications terminals face challenges in managing trusted service applications when a network connection is unavailable or when the network lacks sufficient trust, potentially compromising security and reliability.

Innovation Solution

A secure element within the terminal manages trusted service applications, including a switching function that determines whether management should be performed locally or remotely based on terminal and network states, ensuring secure operation even without a network connection, and includes a method for authorization, verification, and cryptographic key usage for managing trusted applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If trusted service management is performed remotely over the network, then management functionality is provided, but security is compromised when the network is untrusted or unavailable

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork dependency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The secure element acts as an intermediary between the untrusted network and the trusted application management functions. It provides a secure local environment that can receive and process management commands without requiring direct trust in the network infrastructure, thus resolving the contradiction between network-based management and security requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments management functions into secure local operations within the secure element and untrusted remote operations over the network. By separating the trusted execution environment from the untrusted communication channel, the system enables network-based management while maintaining security isolation

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If trusted application management requires network connection, then remote management is enabled, but operation is interrupted when network is unavailable

Engineering Contradiction:
Improveremote management capabilityVSAvoidcontinuous operation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system dynamically adapts its operation mode based on network availability. The secure element can switch between receiving management commands remotely when the network is available and operating autonomously when the network is unavailable, providing both remote management capability and continuous operation reliability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The secure element stores trusted application code and management logic in advance within its secure memory. This preliminary preparation enables the system to execute management operations locally without real-time network connection, ensuring continuous operation while maintaining remote management capabilities when needed

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9996689B2Secure element for a telecommunications terminal
Publication Date: 2018.06.12 IDEMIA FRANCE SAS
  • US9996689B2 patent drawing
  • US9996689B2 patent drawing
  • US9996689B2 patent drawing

AI summary

A secure element, for example an improved SIM card or the like, for a telecommunications terminal, such as a mobile telephone. The secure element may implement a trusted services management application, for example, by executing the trusted services management application on a secure processor. The trusted services management application may manage at least one trusted application to be run by the telecommunications terminal, where trusted applications are used for functions requiring a high level of security such as payment, the supply of “premium” content, which may be certified or guaranteed, or guaranteeing the integrity of the terminal.