Secure Element User Interface Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile electronic devices with integrated secure elements face security threats due to exposure of sensitive payment-related data through user interfaces, which are driven by central processing units vulnerable to attacks and manipulation.
Innovation Solution
A data processing device with a processing unit controlling user interface access and a secure element that restricts access to the user interface during application execution, using mechanisms like ARM TrustZone to isolate input/output channels within a secure environment, ensuring only authorized instructions access the interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure elements are integrated into mobile devices to securely store and process payment data, then security of payment-related data is improved, but the risk of data compromise increases because the secure element must communicate with user interfaces driven by vulnerable central processing units
Solution Approach 1:
The patent divides the system into a secure element (SE) for secure processing and a host device for user interface operations. The SE is segmented from the main processing unit, allowing it to operate in an isolated secure environment while still accessing user interfaces when needed, thus reducing the attack surface while maintaining security functionality
Solution Approach 2:
The patent introduces a user interface access controller as an intermediary component between the secure element and the user interface. This controller mediates all access requests from the SE to the user interface, filtering and authorizing requests before they reach the vulnerable user interface layer, thereby reducing direct exposure of sensitive data
2Ease of operation
If the central processing unit drives the user interface to enable flexible application execution, then ease of operation is improved, but security deteriorates because input and output data can be easily acquired and manipulated by attackers
Solution Approach 1:
The user interface access controller serves as a mediator between the secure element and the user interface. It intercepts and authorizes access requests, maintaining the user interface's operational flexibility while preventing unauthorized data acquisition and manipulation by attackers
Solution Approach 2:
The patent implements dynamic access control where the user interface access controller can enable or disable access to the user interface based on the current execution context. This allows the system to maintain ease of operation during authorized transactions while blocking access during vulnerable states, adapting the security posture dynamically
3Reliability
If access to the user interface is restricted during application execution to prevent unauthorized data access, then security is improved, but device complexity increases due to additional access control mechanisms
Solution Approach 1:
The user interface access controller is designed as a multi-functional component that handles multiple tasks: authorizing access requests, filtering data, controlling communication between the secure element and user interface, and managing execution context. By consolidating these functions into a single controller, the patent reduces overall system complexity while maintaining strong security
Data Source
AI summary
There is disclosed a data processing device for executing an application, the data processing device comprising a processing unit for controlling access to at least one user interface comprised in the data processing device, and a secure element for facilitating secure execution of the application, wherein executing the application comprises receiving input data from and/or sending output data to the user interface, and wherein the secure element is arranged to cause the processing unit to restrict the access to the user interface during execution of the application. Furthermore, a corresponding method for executing an application and a corresponding computer program product are disclosed.


