Secure Element Update Logging Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices with secure elements, such as cellular phones, face challenges in securely and efficiently updating secure element assets like payment applets and operating systems, as existing methods lack scalable and secure solutions for managing updates and maintaining user data personalization.

Innovation Solution

The system includes a secure element with a networking subsystem that receives update packages, identifies and uninstalls previous versions, installs updates, and updates a counter and log, ensuring secure and flexible dissemination of updates while personalizing user data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure element assets are updated using existing methods, then updates can be applied, but the process lacks scalability and security for managing updates while maintaining user data personalization

Engineering Contradiction:
Improvesecurity of updatesVSAvoidscalability of update management
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The update package is segmented into multiple components including asset data, personalization data, and log data. The secure element processes each segment separately, allowing scalable update management while maintaining security through structured data handling and verification at each processing stage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A structured update package format acts as an intermediary between the update source and secure element processing. This standardized format enables scalable distribution of updates while ensuring security through verified data structures that separate asset updates from personalization data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If previous versions of secure element assets are retained, then rollback capability is maintained, but storage space is consumed and version management complexity increases

Engineering Contradiction:
Improverollback capabilityVSAvoidversion management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and maintains only essential version information in the log rather than retaining full copies of previous asset versions. The log stores structured records of past versions including identifiers and timestamps, enabling rollback capability while minimizing storage consumption and simplifying version management

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of storing complete previous asset versions, the system creates simplified copies in the form of log entries that capture essential version metadata. These lightweight copies enable version tracking and rollback without the storage and complexity overhead of maintaining full asset replicas

Inventive Principle:
Principle #26Copying

3Difficulty of detecting and measuring

If a logging mechanism is implemented on the secure element, then debugging capability is improved, but the secure element's limited resources are consumed

Engineering Contradiction:
Improvedebugging capabilityVSAvoidsecure element resources
Core Design Contradiction:
Difficulty of detecting and measuringVSQuantity of substance

Solution Approach 1:

The logging mechanism implements local quality by recording only essential debugging information specific to update operations rather than comprehensive system logs. The log captures update package identifiers, asset types, and outcome status, providing sufficient debugging capability while consuming minimal secure element resources

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial logging by recording only the most critical update-related events rather than all secure element operations. This selective approach provides adequate debugging information for update issues while preserving limited secure element resources for primary security functions

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10223096B2Logging operating system updates of a secure element of an electronic device
Publication Date: 2019.03.05 APPLE INC
  • US10223096B2 patent drawing
  • US10223096B2 patent drawing
  • US10223096B2 patent drawing

AI summary

Systems, methods, and computer-readable media for logging secure element updates of an electronic device are provided. In one example embodiment, a method, at a secure element including a previously-installed secure element asset, includes, inter alia, receiving an update package, uninstalling the previously-installed secure element asset based on the received update package, installing a new secure element asset based on the received update package, and updating at least one of a counter on the secure element and a log on the secure element based on the installation of the new secure element asset. Additional embodiments are also provided.