Secure Element Runtime for Post-Quantum Key Encapsulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems lack robustness against quantum computing threats and fail to securely execute quantum-resistant cryptographic operations within secure element platforms.
Innovation Solution
Utilizing a secure element (SE) hardware processor to execute encapsulation and key agreement algorithms within a SE platform runtime environment, combining legacy and quantum-resistant cryptographic algorithms to generate shared secrets for secure message encryption, while isolating operations within separate logical secure elements (LSEs) to contain vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If quantum-resistant cryptographic algorithms are implemented in a secure element platform, then post-quantum security is enhanced, but device complexity increases
Solution Approach 1:
The patent combines legacy cryptographic algorithms with quantum-resistant cryptographic algorithms within the same secure element platform. The runtime environment dynamically selects and executes appropriate algorithms based on the specific cryptographic operation required, allowing the system to maintain both traditional security protocols and post-quantum security capabilities without requiring separate hardware systems.
Solution Approach 2:
The secure element platform is designed with a universal runtime environment that can execute multiple types of cryptographic algorithms including both legacy and quantum-resistant algorithms. This multi-functional architecture allows a single device to perform diverse cryptographic operations across different security requirements, reducing overall system complexity while enhancing security.
2Adaptability or versatility
If multiple cryptographic algorithms are executed in a runtime environment, then cryptographic flexibility is improved, but execution time increases
Solution Approach 1:
The runtime environment performs preliminary actions by pre-loading and preparing multiple cryptographic algorithm implementations within the secure element. When a cryptographic operation is requested, the system can quickly select and execute the appropriate pre-prepared algorithm without requiring extensive runtime compilation or setup, thereby reducing execution time while maintaining algorithmic flexibility.
Solution Approach 2:
The system employs dynamic algorithm selection where the runtime environment adaptively chooses the most appropriate cryptographic algorithm based on the specific operation requirements, security levels needed, and performance constraints. This dynamic approach allows the system to optimize execution time by selecting efficient algorithms for common operations while reserving more complex quantum-resistant algorithms for operations that specifically require them.
Data Source
AI summary
A system performs a set of cryptographic operations at least by utilizing an API to cause execution of a set of one or more secure element (SE) applications within the SE platform runtime environment of a first computing entity. The set of cryptographic operations include generating a first shared secret, generating a ciphertext at least by encapsulating the first shared secret with a first public key associated with a second computing entity in accordance with an encapsulation algorithm, and transmitting the ciphertext from the first computing entity to the second computing entity. The second computing entity derives the first shared secret by decapsulating the ciphertext with a private key corresponding to the first public key. The first computing entity and the second computing entity then exchange at least one encrypted message, encrypted with an encryption key that includes, or is based at least in part on, the first shared secret.


