Secure Element Reset via Key Escrow for Mobile Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current NFC systems have a tight coupling between secure elements and Trusted Service Managers (TSMs), limiting users to a single TSM and service provider, preventing them from changing or clearing secure element associations and data, which restricts service choices and privacy when transferring or exchanging devices.
Innovation Solution
A method and system that allows users to reset or clear secure elements by receiving encrypted reset requests, decrypting, and verifying authorization, enabling the removal of user-specific data and keys, and allowing selection of new service providers through a key escrow service or central TSM, facilitating secure wiping and reassignment of secure devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure element is tightly coupled to a single TSM with dedicated keys, then security is improved, but user flexibility and service provider selection are reduced
Solution Approach 1:
The patent introduces a key escrow service as an intermediary between the secure element and TSMs. The key escrow service holds the communication keys and can selectively provide them to authorized TSMs, allowing users to change service providers while maintaining security through controlled key distribution rather than tight coupling to a single TSM
Solution Approach 2:
The patent segments the key management function by separating the secure element's communication keys from the TSM. Instead of direct coupling, the keys are divided and held by the key escrow service, which can selectively release them to authorized TSMs, enabling multiple service providers while maintaining security
2Reliability
If secure element data is permanently stored, then service functionality is maintained, but user privacy and device transferability are compromised
Solution Approach 1:
The patent enables users to discard their personal data and keys from the secure element when transferring or selling devices. The reset mechanism allows complete clearing of user-specific information while preserving the secure element's ability to be重新 provisioned with new data and keys for the next user, facilitating device transferability
3Ease of operation
If reset functionality is added to clear secure element data, then user privacy and device transferability are improved, but security risks from unauthorized reset increase
Solution Approach 1:
The patent implements preliminary authorization verification before allowing secure element reset. The system checks whether the reset request is properly authorized through authentication mechanisms before executing the data clearing operation, preventing unauthorized reset while enabling legitimate device transfers
Solution Approach 2:
The patent incorporates feedback mechanisms to verify authorization for reset operations. The system provides feedback about the authorization status and requires confirmation before executing the reset, ensuring that only authorized users can clear their data while preventing malicious or accidental resets
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods are described herein for supporting end users of a mobile device, such as a mobile phone, to reset a secure element associated with the communication device. The reset process may include clearing the secure element, associated memories, and storage devices of any user specific or personalized information associated with the user. The reset process may also include removing or resetting keys or other identifiers within the secure element that associate the mobile device with a particular secure service provider. According to various embodiments, a computer-implemented method for resetting a secure element within a network device may include receiving an encrypted reset request message at the secure element, decrypting the encrypted reset request message using a communication key, verifying authorization for the reset request message, and atomically clearing parameters associated with the secure element.