Secure Element User Interface Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile electronic devices with integrated secure elements face security threats due to exposure of sensitive payment-related data through user interfaces, which are driven by central processing units vulnerable to attacks and manipulation.

Innovation Solution

A data processing device with a processing unit controlling user interface access and a secure element that restricts access to the user interface during application execution, using mechanisms like ARM TrustZone to isolate input/output channels within a secure environment, ensuring only authorized instructions access the interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure elements are integrated into mobile devices to securely store and process payment data, then security of payment-related data is improved, but the risk of data compromise increases because the secure element must communicate with user interfaces driven by vulnerable central processing units

Engineering Contradiction:
Improvesecurity of payment-related dataVSAvoidrisk of data compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the system into a secure element (SE) for secure processing and a host device for user interface operations. The SE is segmented from the main processing unit, allowing it to operate in an isolated secure environment while still accessing user interfaces when needed, thus reducing the attack surface while maintaining security functionality

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a user interface access controller as an intermediary component between the secure element and the user interface. This controller mediates all access requests from the SE to the user interface, filtering and authorizing requests before they reach the vulnerable user interface layer, thereby reducing direct exposure of sensitive data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the central processing unit drives the user interface to enable flexible application execution, then ease of operation is improved, but security deteriorates because input and output data can be easily acquired and manipulated by attackers

Engineering Contradiction:
Improveuser interface operationVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The user interface access controller serves as a mediator between the secure element and the user interface. It intercepts and authorizes access requests, maintaining the user interface's operational flexibility while preventing unauthorized data acquisition and manipulation by attackers

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamic access control where the user interface access controller can enable or disable access to the user interface based on the current execution context. This allows the system to maintain ease of operation during authorized transactions while blocking access during vulnerable states, adapting the security posture dynamically

Inventive Principle:
Principle #15Dynamics

3Reliability

If access to the user interface is restricted during application execution to prevent unauthorized data access, then security is improved, but device complexity increases due to additional access control mechanisms

Engineering Contradiction:
Improvedata protectionVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The user interface access controller is designed as a multi-functional component that handles multiple tasks: authorizing access requests, filtering data, controlling communication between the secure element and user interface, and managing execution context. By consolidating these functions into a single controller, the patent reduces overall system complexity while maintaining strong security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10853520B2Data processing device, method for executing an application and computer program product
Publication Date: 2020.12.01 NXP BV
  • US10853520B2 patent drawing
  • US10853520B2 patent drawing
  • US10853520B2 patent drawing

AI summary

There is disclosed a data processing device for executing an application, the data processing device comprising a processing unit for controlling access to at least one user interface comprised in the data processing device, and a secure element for facilitating secure execution of the application, wherein executing the application comprises receiving input data from and/or sending output data to the user interface, and wherein the secure element is arranged to cause the processing unit to restrict the access to the user interface during execution of the application. Furthermore, a corresponding method for executing an application and a corresponding computer program product are disclosed.