Secure Element Runtime for Post-Quantum Key Encapsulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems lack robustness against quantum computing threats and fail to securely execute quantum-resistant cryptographic operations within secure element platforms.

Innovation Solution

Utilizing a secure element (SE) hardware processor to execute encapsulation and key agreement algorithms within a SE platform runtime environment, combining legacy and quantum-resistant cryptographic algorithms to generate shared secrets for secure message encryption, while isolating operations within separate logical secure elements (LSEs) to contain vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If quantum-resistant cryptographic algorithms are implemented in a secure element platform, then post-quantum security is enhanced, but device complexity increases

Engineering Contradiction:
Improvepost-quantum securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines legacy cryptographic algorithms with quantum-resistant cryptographic algorithms within the same secure element platform. The runtime environment dynamically selects and executes appropriate algorithms based on the specific cryptographic operation required, allowing the system to maintain both traditional security protocols and post-quantum security capabilities without requiring separate hardware systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure element platform is designed with a universal runtime environment that can execute multiple types of cryptographic algorithms including both legacy and quantum-resistant algorithms. This multi-functional architecture allows a single device to perform diverse cryptographic operations across different security requirements, reducing overall system complexity while enhancing security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple cryptographic algorithms are executed in a runtime environment, then cryptographic flexibility is improved, but execution time increases

Engineering Contradiction:
Improvecryptographic flexibilityVSAvoidexecution time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The runtime environment performs preliminary actions by pre-loading and preparing multiple cryptographic algorithm implementations within the secure element. When a cryptographic operation is requested, the system can quickly select and execute the appropriate pre-prepared algorithm without requiring extensive runtime compilation or setup, thereby reducing execution time while maintaining algorithmic flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs dynamic algorithm selection where the runtime environment adaptively chooses the most appropriate cryptographic algorithm based on the specific operation requirements, security levels needed, and performance constraints. This dynamic approach allows the system to optimize execution time by selecting efficient algorithms for common operations while reserving more complex quantum-resistant algorithms for operations that specifically require them.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12632537B2Executing cryptographic operations in a secure element platform runtime environment
Publication Date: 2026.05.19 ORACLE INT CORP
  • US12632537B2 patent drawing
  • US12632537B2 patent drawing
  • US12632537B2 patent drawing

AI summary

A system performs a set of cryptographic operations at least by utilizing an API to cause execution of a set of one or more secure element (SE) applications within the SE platform runtime environment of a first computing entity. The set of cryptographic operations include generating a first shared secret, generating a ciphertext at least by encapsulating the first shared secret with a first public key associated with a second computing entity in accordance with an encapsulation algorithm, and transmitting the ciphertext from the first computing entity to the second computing entity. The second computing entity derives the first shared secret by decapsulating the ciphertext with a private key corresponding to the first public key. The first computing entity and the second computing entity then exchange at least one encrypted message, encrypted with an encryption key that includes, or is based at least in part on, the first shared secret.