Secure Element Personalization with Pre-Installation OS Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge is to personalize a secure element permanently installed in a mobile end device while maintaining control over the personalization process by the secure element and operating system manufacturers, as existing methods often relinquish this control to the end device manufacturer.

Innovation Solution

A method involving asymmetric key pairs and hardware security modules is employed to establish secure communication between the secure element and the hardware security module before installation, allowing encryption and storage of the operating system outside the secure element, ensuring only the secure element and operating system manufacturers retain control over the personalization process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the secure element is permanently installed in the mobile end device before personalization, then the end device manufacturer gains control over the personalization process, but the secure element and operating system manufacturers lose control over their own personalization data

Engineering Contradiction:
Improvecontrol over personalization processVSAvoidpersonalization control distribution
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing asymmetric key pairs and encrypting the operating system with the secure element's public key before the secure element is permanently installed in the end device. This preliminary encryption ensures that only the intended secure element can decrypt and execute the operating system, maintaining control for the secure element and operating system manufacturers even after installation. The key pair generation and encryption occur in advance, before the secure element loses its removable status.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses asymmetric cryptography as an intermediary mechanism to maintain control. The secure element's private key acts as a secret intermediary that only the secure element possesses, while the public key serves as a mediator that allows the operating system to be encrypted and stored externally. This cryptographic intermediary enables the end device manufacturer to handle the operating system while the secure element manufacturer retains control through the private key.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the operating system is stored in external non-volatile memory outside the secure element, then the secure element cannot execute it without decryption, but this requires establishing secure communication channels before installation

Engineering Contradiction:
Improvesecurity of operating system executionVSAvoidkey management infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies asymmetry through asymmetric cryptography (public-private key pairs). The secure element generates a private key that remains secret within the secure element and a corresponding public key that can be shared. The operating system is encrypted with the public key, creating an asymmetric relationship where only the holder of the private key (the secure element) can decrypt and execute the operating system. This asymmetric approach ensures reliability while managing the complexity of key distribution.

Inventive Principle:
Principle #4Asymmetry

3Ease of manufacture

If plug-in secure elements are used, then personalization can be easily performed by the secure element manufacturer, but embedded secure elements require the manufacturer to release control before installation

Engineering Contradiction:
Improvepersonalization processVSAvoidcontrol retention
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The patent applies preliminary action by performing key pair generation and operating system encryption before the secure element is permanently installed in the end device. This allows the secure element manufacturer to maintain control over the personalization process similar to plug-in elements, while enabling the use of embedded secure elements. The preliminary encryption ensures that the operating system can only be executed by the intended secure element, compensating for the loss of physical removability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12457104B2Personalization of a secure element
Publication Date: 2025.10.28 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • US12457104B2 patent drawing
  • US12457104B2 patent drawing
  • US12457104B2 patent drawing

AI summary

A method for personalizing an integrated secure element, which is permanently installed in a mobile end device. The method involves the agreement of a shared secret between the secure element and an HSM, encrypting an operating system, and possibly personalization data and/or one or several profiles, in the HSM based on the shared secret and transferring the encrypted operating system to the secure element, and re-encrypting the operating system in the secure element for storage in the NVM memory of the mobile end device.