In-situ Secure Element Programming via Bus Reconfiguration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Embedded secure elements in devices pose challenges for programming and provisioning due to the need for intermediate network interfaces, which are slower and less reliable compared to removable secure elements.
Innovation Solution
A method and device configuration that allows in-situ programming of embedded secure elements by reconfiguring a single master and two slave devices, where one slave becomes the master to directly communicate with the on-board secure element, using digital switches to control communication paths and prevent data visibility on external lines, enabling simultaneous utilization of two secure elements on a single UART.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If embedded secure elements are used in devices, then security and integration are improved, but programming and provisioning become slower and less reliable due to intermediate network interfaces
Solution Approach 1:
The patent introduces a master secure element as an intermediary device that enables direct programming of the embedded secure element through a shared communication bus. This master secure element acts as a mediator that facilitates high-speed direct communication while maintaining security, eliminating the need for slow intermediate network interfaces during the programming phase.
Solution Approach 2:
The communication bus dynamically reconfigures its topology to enable direct master-slave communication between secure elements during programming, then returns to the standard embedded configuration during operation. This dynamic reconfiguration allows the system to switch between high-speed direct programming mode and secure embedded operation mode, resolving the contradiction between programming speed and embedded security.
2Reliability
If digital switches are used to control communication paths, then security against data sniffing is improved, but device complexity increases
Solution Approach 1:
The master secure element serves as an intermediary that controls the digital switches, centralizing the complexity in a dedicated security device rather than distributing it throughout the system. This mediator approach maintains simple overall system architecture while enabling secure switched communication paths that prevent data sniffing on the shared bus.
Data Source
AI summary
A method, device, and system are disclosed that enable the in-situ programming of an on-board secure element. A communication bus normally used to facilitate communications between the secure element and a microprocessor is borrowed to facilitate the in-situ programming with an off-board secure element. The microprocessor is disclosed to include the functionality to switch the configuration of the communication bus to enable the in-situ programming.


