Secure Element Reset Verification via Non-Volatile Memory Indicator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure elements face challenges in maintaining secure application execution after reboot or resetting, as existing technologies do not effectively verify and update necessary information to ensure secure operation.

Innovation Solution

A secure element method that verifies and updates specific information associated with the low-level operating system at each reset operation, informing applications of the reset type and allowing them to implement protocols accordingly, ensuring secure application execution post-reset.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the secure element reboots or resets, then the system can recover from errors or improve performance, but the application execution security may be compromised

Engineering Contradiction:
Improveapplication execution securityVSAvoidreset verification mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by updating a reset indication in non-volatile memory before the reset operation occurs. This allows the indicator to be preserved through the reset, enabling verification mechanisms to detect that a reset has occurred without requiring complex post-reset analysis. The low-level operating system updates the indicator in advance, ensuring security verification can proceed smoothly after reset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism - a reset indication stored in non-volatile memory - that mediates between the reset operation and the application security verification. This intermediary preserves reset state information through the reset operation, allowing the high-level operating system and applications to verify security conditions without direct complex interaction with the low-level reset mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the secure element verifies information after reset, then application security is maintained, but the startup time and processing overhead increase

Engineering Contradiction:
Improveapplication securityVSAvoidapplication startup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the reset verification function into a separate, dedicated mechanism - the reset indication in non-volatile memory. This extraction allows the verification process to be performed efficiently by simply reading the pre-stored indicator rather than analyzing complex system state after reset. The verification is separated from the main application startup流程, reducing startup time overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies self-service by having the low-level operating system automatically update the reset indication in non-volatile memory during the reset process itself. This automatic updating eliminates the need for manual or complex post-reset verification of reset state, allowing applications to quickly check the indicator and proceed with security verification without time-consuming analysis.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If the secure element implements multiple applications, then functionality and versatility improve, but the complexity of maintaining security across all applications increases

Engineering Contradiction:
Improvemulti-application supportVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by implementing a general reset indication mechanism in non-volatile memory that serves all applications uniformly. Instead of implementing separate security verification mechanisms for each application, a single reset indicator serves the entire multi-application ecosystem. The high-level operating system can use this universal indicator to manage security for multiple applications, reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the security verification function into distinct layers: the low-level operating system updates the reset indication in non-volatile memory, while the high-level operating system and individual applications perform verification based on this indicator. This segmentation allows multiple applications to independently verify security conditions without interfering with each other, simplifying multi-application security management.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11768943B2Secure element and method for starting an application by a low-level operating system
Publication Date: 2023.09.26 STMICROELECTRONICS BELGIUM
  • US11768943B2 patent drawing
  • US11768943B2 patent drawing
  • US11768943B2 patent drawing

AI summary

The present description concerns a method of starting a first application configured to be implemented by at least one low-level operating system of a secure element, including the verification of at least a first piece of information updated after each operation of resetting of the secure element, the first piece of information being associated with the at least one low-level operating system.