In-situ Secure Element Programming via Bus Reconfiguration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Embedded secure elements in devices pose challenges for programming and provisioning due to the need for intermediate network interfaces, which are slower and less reliable compared to removable secure elements.

Innovation Solution

A method and device configuration that allows in-situ programming of embedded secure elements by reconfiguring a single master and two slave devices, where one slave becomes the master to directly communicate with the on-board secure element, using digital switches to control communication paths and prevent data visibility on external lines, enabling simultaneous utilization of two secure elements on a single UART.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If embedded secure elements are used in devices, then security and integration are improved, but programming and provisioning become slower and less reliable due to intermediate network interfaces

Engineering Contradiction:
Improveprogramming reliabilityVSAvoidprogramming speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent introduces a master secure element as an intermediary device that enables direct programming of the embedded secure element through a shared communication bus. This master secure element acts as a mediator that facilitates high-speed direct communication while maintaining security, eliminating the need for slow intermediate network interfaces during the programming phase.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication bus dynamically reconfigures its topology to enable direct master-slave communication between secure elements during programming, then returns to the standard embedded configuration during operation. This dynamic reconfiguration allows the system to switch between high-speed direct programming mode and secure embedded operation mode, resolving the contradiction between programming speed and embedded security.

Inventive Principle:
Principle #15Dynamics

2Reliability

If digital switches are used to control communication paths, then security against data sniffing is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidswitching mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The master secure element serves as an intermediary that controls the digital switches, centralizing the complexity in a dedicated security device rather than distributing it throughout the system. This mediator approach maintains simple overall system architecture while enabling secure switched communication paths that prevent data sniffing on the shared bus.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2568407B1Method and system for communicating with and programming a secure element
Publication Date: 2017.10.25 ASSA ABLOY AB
  • EP2568407B1 patent drawing
  • EP2568407B1 patent drawing
  • EP2568407B1 patent drawing

AI summary

A method, device, and system are disclosed that enable the in-situ programming of an on-board secure element. A communication bus normally used to facilitate communications between the secure element and a microprocessor is borrowed to facilitate the in-situ programming with an off-board secure element. The microprocessor is disclosed to include the functionality to switch the configuration of the communication bus to enable the in-situ programming.