Secure Element User Binding for Digital Identity Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital key sharing processes are vulnerable to attacks due to insufficient validation of key configuration parameters, leading to potential misuse of digital keys, and existing secondary factor authentication methods, such as PIN or One Time Password, negatively impact user experience and do not cover all use cases.

Innovation Solution

Implement a secure element associated with a user, utilizing a trusted authority to perform user binding, generating an authorization key based on secure element information, and incorporating user binding data into an instance CA certificate for validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a second factor authentication (PIN/One Time Password) is used to prevent attacks on the sharee or communication channel, then security is improved, but user experience deteriorates and not all use cases are covered

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a trusted authority as an intermediary that performs user binding to the secure element. This mediator validates the authorization process by confirming that the secure element is properly bound to the intended user, eliminating the need for out-of-band authentication methods like PIN or OTP while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements user binding as a preliminary action that occurs before the digital key sharing process. The trusted authority binds the user's identity to the secure element in advance, so that during key sharing, the authorization can be validated without requiring additional authentication steps from the user.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If validation of key configuration parameters is performed before attestation signing, then security is improved, but the system remains vulnerable to attacks on the sharee or communication channel

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The trusted authority acts as a mediator that performs rigorous validation of the secure element's user binding and the authorization process. This intermediary layer prevents attackers from exploiting vulnerabilities in the sharee or communication channel, as the trusted authority verifies all parameters and bindings before allowing attestation signing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the trusted authority continuously validates the authorization process, checking that the secure element is properly bound to the intended user and that all key configuration parameters are correct. This feedback loop prevents unauthorized key generation even if attackers compromise the sharee or communication channel.

Inventive Principle:
Principle #23Feedback

3Reliability

If user binding information is incorporated into instance CA certificate, then authorization validation is improved, but device complexity increases

Engineering Contradiction:
Improveauthorization validationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges user binding information directly into the instance CA certificate. By combining the user's identity binding data with the certificate authority's digital signature in a single cryptographic structure, the system achieves strong authorization validation without adding separate complex verification systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250337583A1System and Method for Digital Identity Authorization
Publication Date: 2025.10.30 BAYERISCHE MOTOREN WERKE AG
  • US20250337583A1 patent drawing
  • US20250337583A1 patent drawing
  • US20250337583A1 patent drawing

AI summary

A system including a mobile communication device configured to communicate with a secure element is disclosed herein. The mobile communication device is equipped with a secure element for improving an authorization process, comprising interface circuitry configured to communicate with a trusted authority, and processing circuitry configured to control the interface circuitry and to receive a signal from the trusted authority. The signal comprises information indicative of a user binding to the secure element.