Secure Element User Binding for Digital Identity Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital key sharing processes are vulnerable to attacks due to insufficient validation of key configuration parameters, leading to potential misuse of digital keys, and existing secondary factor authentication methods, such as PIN or One Time Password, negatively impact user experience and do not cover all use cases.
Innovation Solution
Implement a secure element associated with a user, utilizing a trusted authority to perform user binding, generating an authorization key based on secure element information, and incorporating user binding data into an instance CA certificate for validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a second factor authentication (PIN/One Time Password) is used to prevent attacks on the sharee or communication channel, then security is improved, but user experience deteriorates and not all use cases are covered
Solution Approach 1:
The patent introduces a trusted authority as an intermediary that performs user binding to the secure element. This mediator validates the authorization process by confirming that the secure element is properly bound to the intended user, eliminating the need for out-of-band authentication methods like PIN or OTP while maintaining security.
Solution Approach 2:
The patent implements user binding as a preliminary action that occurs before the digital key sharing process. The trusted authority binds the user's identity to the secure element in advance, so that during key sharing, the authorization can be validated without requiring additional authentication steps from the user.
2Reliability
If validation of key configuration parameters is performed before attestation signing, then security is improved, but the system remains vulnerable to attacks on the sharee or communication channel
Solution Approach 1:
The trusted authority acts as a mediator that performs rigorous validation of the secure element's user binding and the authorization process. This intermediary layer prevents attackers from exploiting vulnerabilities in the sharee or communication channel, as the trusted authority verifies all parameters and bindings before allowing attestation signing.
Solution Approach 2:
The system implements feedback mechanisms where the trusted authority continuously validates the authorization process, checking that the secure element is properly bound to the intended user and that all key configuration parameters are correct. This feedback loop prevents unauthorized key generation even if attackers compromise the sharee or communication channel.
3Reliability
If user binding information is incorporated into instance CA certificate, then authorization validation is improved, but device complexity increases
Solution Approach 1:
The patent merges user binding information directly into the instance CA certificate. By combining the user's identity binding data with the certificate authority's digital signature in a single cryptographic structure, the system achieves strong authorization validation without adding separate complex verification systems.
Data Source
AI summary
A system including a mobile communication device configured to communicate with a secure element is disclosed herein. The mobile communication device is equipped with a secure element for improving an authorization process, comprising interface circuitry configured to communicate with a trusted authority, and processing circuitry configured to control the interface circuitry and to receive a signal from the trusted authority. The signal comprises information indicative of a user binding to the secure element.


