Secure Element Personalization via Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for personalizing secure elements are limited by incompatible data transmission standards between ID tokens and secure elements, making it difficult to utilize personalization information across devices with different communication interfaces.

Innovation Solution

A method that allows personalization of a secure element using personalization information from an ID token by implementing end-to-end encryption and authentication protocols, enabling secure data transfer between ID tokens and secure elements with different data transmission standards, such as RFID and NFC interfaces, without direct access to protected memory areas.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If personalization information is transferred directly between ID token and secure element, then personalization can be achieved, but incompatible data transmission standards prevent direct communication

Engineering Contradiction:
Improvecompatibility between different data transmission standardsVSAvoidcomplexity of data transfer mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A server acts as an intermediary between the ID token and secure element. The server receives personalization information from the ID token via a first data transmission standard, stores it, and then transfers it to the secure element via a second data transmission standard. This mediator resolves the incompatibility between different communication standards without requiring direct compatibility between the token and secure element.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The solution moves the data transfer process from a direct two-point connection (ID token to secure element) to a multi-dimensional approach involving a centralized server. Information is transferred through multiple channels and protocols via the server, adding dimensional flexibility to overcome standard incompatibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of manufacture

If protected memory areas are made accessible for personalization, then personalization information can be read and written, but security against unauthorized access is compromised

Engineering Contradiction:
Improveease of personalization processVSAvoidsecurity of protected memory areas
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

Authentication and authorization checks are performed before any access to protected memory areas. The system verifies the identity of requesting devices and validates their permissions prior to allowing read or write operations. This preliminary security action ensures that only authenticated entities can access sensitive data, maintaining security while enabling legitimate personalization operations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication protocols are implemented for secure transfer, then security is improved, but the personalization process becomes more complex

Engineering Contradiction:
Improvesecurity of personalization processVSAvoidcomplexity of authentication protocols
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is designed to be self-managing through automated verification processes. The server automatically handles authentication challenges, validates credentials, and manages session states without requiring manual intervention. This self-service approach maintains high security while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2893483B1Method for personalizing a secure element (SE) and computer system
Publication Date: 2018.09.19 BUNDESDRUCKEREI GMBH
  • EP2893483B1 patent drawingFigure 1
  • EP2893483B1 patent drawingFigure 2

AI summary

The invention relates to a method for personalizing a secure element (158) with the aid of an ID token (106), wherein the ID token has an electronic memory (118) having a protected memory area (124, 162) in which an item of personalization information is stored, wherein the protected memory area can be accessed only via a processor (128) of the ID token, and wherein the ID token has a communication interface (108) for communicating with a reader according to a first data transmission standard, wherein the secure element has an electronic memory (118') having a protected memory area (124', 162'), wherein the protected memory area can be accessed only via a processor (128') of the secure element, and wherein the secure element has a communication interface (164) for communicating with the reader according to a second data transmission standard, having the following steps: a) the personalization information is read from the ID token by an ID provider computer system (136) via a network (116), b) the personalization information read from the ID token is written to the secure element by the ID provider computer system via the network.