Secure Element Time Validation via External Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Public Key Infrastructure (PKI) environments, there is a need to improve the recognition of expired certificates and ensure the validity of certificates, CRLs, and OCSP stapling messages, particularly in securing communications for secure elements (SEs) like embedded universal integrated circuit cards (eUICCs), where resource constraints limit the ability to maintain revocation lists and check for certificate expiration and compromise.
Innovation Solution
The use of time information in SEs to enhance security by obtaining and storing time information from authenticated messages or trusted interfaces, which can be used to check for certificate expiration, validate CRLs and OCSP stapling messages, and manage certificate revocation, with mechanisms such as periodic updates, opportunistic parsing, and storage in memory or eUICC security domains, and employing multi-check architectures involving blockchain consensus to prevent tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the SE stores and checks certificate expiration dates and revocation information, then the security against compromised or expired certificates is improved, but the device complexity and resource consumption increase
Solution Approach 1:
The patent extracts the time-checking function from the SE by obtaining the current time from an external authenticated message or trusted interface rather than maintaining a local clock. This allows the SE to verify certificate expiration and revocation status without storing extensive time-related data or maintaining complex time-synchronization mechanisms, thereby reducing device complexity while maintaining reliability
Solution Approach 2:
The system performs preliminary time verification by checking the current time against certificate expiration dates and revocation information before processing transactions. This preliminary check prevents the SE from processing invalid certificates, improving security without requiring the SE to continuously monitor or store extensive certificate validity data
2Reliability
If the SE maintains updated revocation lists and checks certificate status, then the detection of compromised certificates is improved, but the loss of time and computational resources increase
Solution Approach 1:
The patent applies partial action by performing only essential time-based validity checks (comparing current time with expiration dates) rather than comprehensive verification of all certificate attributes. This selective approach enables the SE to detect compromised and expired certificates while minimizing the time and computational resources required for validation
3Speed
If the SE uses local clock for time-based security checks, then the independence and speed of validation is improved, but the accuracy and synchronization of time information deteriorates
Solution Approach 1:
The patent introduces an intermediary trusted time source that provides authenticated time information to the SE. This mediator enables the SE to obtain accurate and synchronized time data without maintaining its own clock, ensuring both the speed of local validation and the precision of time synchronization by relying on externally provided trusted time references
Data Source
AI summary
A secure element (SE) with a notion of time useful for checking secure items is disclosed herein. Use of Public Key Infrastructure (PKI) with secure elements is improved by verifying secure items used by an SE. Methods of obtaining time information by the SE include push, pull, opportunistic, local interface, and multi-check methods. The SE uses the time information to evaluate arriving and stored public key certificates and to discard those which fail the evaluation. The SE, in some embodiments, uses the time information in cooperation with certificate revocation lists (CRLs) and/or online certificate status protocol (OCSP) stapling procedures. A multi-check architecture is provided herein by which more than entity is involved in checking a time value before the time value reaches the SE. The multi-check architecture uses both PKI and blockchain techniques.


