Secure Element Personalization Data Recovery via Update Agent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure elements cannot change or recover personalization data after chip production, especially after a security breach, due to the inability to update personalization data outside a certified environment during a Full Reflash process.

Innovation Solution

A method where personalization data is secured from the installed software to the update agent's memory during a Full Reflash, allowing it to be reused for personalizing a software image, enabling secure and efficient data changes and protection from deletion during the process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personalization data is secured in the update agent's memory during production phase, then security is improved, but the ability to change personalization data after chip production is lost

Engineering Contradiction:
ImprovesecurityVSAvoidability to change personalization data
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by creating a backup copy of the personalization data in the update agent's memory during production phase. This backup serves as a recovery source that can be used later if the primary personalization data is lost or compromised, enabling restoration without requiring re-personalization from external sources.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by duplicating the personalization data from its original storage location to the update agent's memory. This creates a redundant copy that can be accessed independently, allowing the system to recover personalization data without exposing the original secure storage mechanisms.

Inventive Principle:
Principle #26Copying

2Productivity

If personalization data is deleted during Full Reflash, then software can be updated, but personalization data cannot be restored

Engineering Contradiction:
Improvesoftware update capabilityVSAvoidpersonalization data
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent implements beforehand cushioning by pre-storing a backup copy of the personalization data in the update agent's memory before the Full Reflash process begins. This protective measure ensures that even if the primary personalization data is deleted during the update process, a recoverable copy already exists in the update agent's protected storage.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Ease of repair

If personalization data is stored externally during production, then it can be restored after Full Reflash, but it cannot be changed after chip production

Engineering Contradiction:
Improvedata recovery capabilityVSAvoiddata change capability
Core Design Contradiction:
Ease of repairVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by making the update agent's memory serve multiple functions: it acts as both a backup storage location during normal operation and as a source for restoring personalization data after Full Reflash. This multi-functional use eliminates the need for separate external storage mechanisms while enabling both recovery and potential updates.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240241959A1Change and recovery of personalization data in a secure element
Publication Date: 2024.07.18 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • US20240241959A1 patent drawing
  • US20240241959A1 patent drawing
  • US20240241959A1 patent drawing

AI summary

A method is provided for changing and recovering personalization data of a trusted software in a secure element and changing and restoring diversified data. The method includes the steps of providing an update agent in the secure element; storing personalization data in the installed software; performing a Full Reflash to recover or update a software or operating system comprising the steps of first securing personalization data to a memory of the update agent before, in following step, recovering or loading a software image into the secure element. The method includes as a final step personalizing the software image by the personalization data secured during the first step of the Full Reflash.