Secure Element Device Authentication Without Supply-Chain Pairing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for securing communication between devices with secure elements require pre- or post-association, pairing, or dynamically linking supply chains, which complicates manufacturing and increases security risks.
Innovation Solution
A method for securing communication between a device and a remote server using asymmetric cryptography, where device and server key materials are generated independently based on public and private keys, with only public data exchanged during association, eliminating the need for secure communication between supply chains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-association or post-association methods are used to secure device profiles, then security against profile copying and disclosure is improved, but device complexity and manufacturing complexity increase due to required pairing and dynamic linking of supply chains
Solution Approach 1:
The patent applies preliminary action by pre-generating secure element data and storing it in the remote server before the device is even manufactured. This allows the device to be securely personalized without requiring complex pre-association or post-association procedures, as the secure element data is already prepared and waiting in the server.
Solution Approach 2:
The patent extracts the secure element data from the device manufacturing process and stores it independently in the remote server. This separation allows the device to be manufactured without complex pairing procedures, as the secure element data is obtained directly from the server during device initialization rather than requiring complex association protocols.
2Reliability
If verified association with explicit activation is used, then security validation is improved, but productivity decreases due to required connection or logging system validation before device functionality
Solution Approach 1:
The patent performs the association validation in advance by pre-storing secure element data in the remote server. This eliminates the need for time-consuming validation connections or logging systems during device activation, as the association is effectively pre-validated and stored ready for immediate use.
Data Source
AI summary
A method for securing a communication between a remote server and a device equipped with a secure element, device side profile data being stored in the device, and device side secure element data being stored in the secure element. The image data includes server side profile data being stored in the remote server, server side secure element data being stored in the remote server, or being retrievable from the remote server. The method includes associating the device with the secure element, generating, on the device side, a device key material, reporting the association to the remote server, generating, on the remote server side, a server key material, authorizing a communication between the device and the remote server, after an authentication based at least on the basis of a comparison between the device key material and the server key material.


