Secure Element Time Validation via External Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Public Key Infrastructure (PKI) environments, there is a need to improve the recognition of expired certificates and ensure the validity of certificates, CRLs, and OCSP stapling messages, particularly in securing communications for secure elements (SEs) like embedded universal integrated circuit cards (eUICCs), where resource constraints limit the ability to maintain revocation lists and check for certificate expiration and compromise.

Innovation Solution

The use of time information in SEs to enhance security by obtaining and storing time information from authenticated messages or trusted interfaces, which can be used to check for certificate expiration, validate CRLs and OCSP stapling messages, and manage certificate revocation, with mechanisms such as periodic updates, opportunistic parsing, and storage in memory or eUICC security domains, and employing multi-check architectures involving blockchain consensus to prevent tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the SE stores and checks certificate expiration dates and revocation information, then the security against compromised or expired certificates is improved, but the device complexity and resource consumption increase

Engineering Contradiction:
Improvecertificate validity verificationVSAvoidSE resource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the time-checking function from the SE by obtaining the current time from an external authenticated message or trusted interface rather than maintaining a local clock. This allows the SE to verify certificate expiration and revocation status without storing extensive time-related data or maintaining complex time-synchronization mechanisms, thereby reducing device complexity while maintaining reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary time verification by checking the current time against certificate expiration dates and revocation information before processing transactions. This preliminary check prevents the SE from processing invalid certificates, improving security without requiring the SE to continuously monitor or store extensive certificate validity data

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the SE maintains updated revocation lists and checks certificate status, then the detection of compromised certificates is improved, but the loss of time and computational resources increase

Engineering Contradiction:
Improvecertificate compromise detectionVSAvoidvalidation processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by performing only essential time-based validity checks (comparing current time with expiration dates) rather than comprehensive verification of all certificate attributes. This selective approach enables the SE to detect compromised and expired certificates while minimizing the time and computational resources required for validation

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If the SE uses local clock for time-based security checks, then the independence and speed of validation is improved, but the accuracy and synchronization of time information deteriorates

Engineering Contradiction:
Improvelocal time validation speedVSAvoidtime synchronization accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary trusted time source that provides authenticated time information to the SE. This mediator enables the SE to obtain accurate and synchronized time data without maintaining its own clock, ensuring both the speed of local validation and the precision of time synchronization by relying on externally provided trusted time references

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10680833B2Obtaining and using time information on a secure element (SE)
Publication Date: 2020.06.09 APPLE INC
  • US10680833B2 patent drawing
  • US10680833B2 patent drawing
  • US10680833B2 patent drawing

AI summary

A secure element (SE) with a notion of time useful for checking secure items is disclosed herein. Use of Public Key Infrastructure (PKI) with secure elements is improved by verifying secure items used by an SE. Methods of obtaining time information by the SE include push, pull, opportunistic, local interface, and multi-check methods. The SE uses the time information to evaluate arriving and stored public key certificates and to discard those which fail the evaluation. The SE, in some embodiments, uses the time information in cooperation with certificate revocation lists (CRLs) and/or online certificate status protocol (OCSP) stapling procedures. A multi-check architecture is provided herein by which more than entity is involved in checking a time value before the time value reaches the SE. The multi-check architecture uses both PKI and blockchain techniques.