Secure Element Transfer Device for Cryptographic Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for transferring cryptographic keys between entities lack a simple yet secure mechanism, with existing methods being either insecure or overly complex.

Innovation Solution

A method and system utilizing purpose-built computing devices with secure elements, such as tamper-resistant processors, to encode and encrypt sensitive information, allowing secure transfer via low-security communication channels like voice calls, emails, or SMS, with complementary devices at both ends for decryption and use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional secure methods (key splitting across multiple secure devices) are used, then security is improved, but device complexity and operational complexity increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function into a dedicated secure element (tamper-resistant processor) within the computing device. This secure element handles all sensitive operations (key generation, storage, encryption/decryption) internally, removing the need for complex external secure device management while maintaining high security standards.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure element acts as an intermediary between the user input and the communication output. It receives sensitive information directly from the user input, processes it securely within its tamper-resistant boundary, and only outputs encrypted data or decrypted results, never exposing raw sensitive information to the external environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If key fragments are distributed across multiple secure devices, then security is improved, but ease of operation deteriorates due to coordination requirements

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the secure element directly into the computing device, combining what were previously separate secure devices into a unified system. This integration allows the secure operations to be performed locally without requiring coordination between multiple external devices, significantly simplifying the operational process while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If sensitive information is transmitted through standard communication channels, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
ImprovesimplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary encryption of sensitive information within the secure element before transmission through standard communication channels. By pre-securing the data at the source using the tamper-resistant processor, the information remains protected throughout its journey through insecure channels, eliminating the need for secure physical delivery while maintaining security.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If cryptographic keys are written on paper and delivered physically, then security is improved against digital interception, but loss of time and operational complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical system of physical paper delivery with an electronic/digital system. Sensitive information is generated, encrypted, and transmitted electronically through standard communication channels (email, messaging, etc.), eliminating the time-consuming physical delivery process while maintaining security through cryptographic protection within the secure element.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP2406749B1Transfer device for sensitive material such as a cryptographic key
Publication Date: 2018.06.13 ASSA ABLOY AB
  • EP2406749B1 patent drawingFigure 1
  • EP2406749B1 patent drawingFigure 2
  • EP2406749B1 patent drawingFigure 3

AI summary

Mechanisms are provided for transferring sensitive information, such as cryptographic keys, between entities. Particularly, a device is provided with a user input connected directly to a secure element. The device enables a user to enter sensitive information in the user input which is then passed directly to the secure element without traversing any other element such that the secure element can encode and/or encrypt the sensitive information. Once the sensitive information has been encoded and/or encrypted by the secure element, the now secure sensitive information can be shared with other entities using familiar and popular, yet relatively unsecure, transfer methods.