Secure Element Verification Records for Long Certificate Chains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure elements in transaction systems face challenges in maintaining security and reliability while managing resource limitations, particularly in terms of data storage and transmission, especially when dealing with complex certificate chains and certification schemes.
Innovation Solution
Implementing a secure element with dynamic verification data that stores certificate references and verified data elements in a non-volatile memory, allowing for selective verification and reducing the need for repeated certificate checks, thereby enhancing security and transaction efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate chains and certification schemes are made more complex to improve security, then security level increases, but data storage requirements and transaction time increase
Solution Approach 1:
The patent extracts only the essential verification data elements from complete certificates and stores them in a verification data structure. Instead of storing entire certificate chains, the system stores verified data elements that reference the certificates, significantly reducing storage requirements while maintaining security verification capabilities
Solution Approach 2:
The system performs certificate verification in advance and stores the verified data elements for future use. By pre-verifying certificates and caching the verification results, the system avoids repeating complex verification processes in subsequent transactions, reducing both storage needs and transaction time
2Reliability
If certificate chains are lengthened to improve security, then security level increases, but transaction time increases
Solution Approach 1:
The system performs certificate chain verification beforehand and caches the verified data elements. When a transaction occurs, the system uses the pre-verified data instead of re-verification, dramatically reducing transaction time while maintaining the security benefits of comprehensive certificate chains
Solution Approach 2:
The system creates simplified copies of verified certificate data in the verification data structure. These copies contain the essential verification information without the full complexity of the original certificate chains, enabling fast verification without processing the entire chain during transactions
3Reliability
If complete certificates are verified in every transaction to maintain security, then security level increases, but resource consumption increases
Solution Approach 1:
The system extracts only the necessary verification data from complete certificates and stores it in a compact verification data structure. This extraction approach maintains security by preserving the essential verification information while dramatically reducing the computational resources needed for verification
Solution Approach 2:
The system discards the need to re-verify already-verified certificates by storing their verification results in the verification data structure. Instead of repeatedly processing complete certificates, the system recovers and reuses the cached verified data elements, reducing resource consumption in subsequent transactions
Data Source
Figure 1
Figure 2~4
Figure 5
AI summary
The present invention is related to a secure element (1) of a transaction system comprising multiple transaction partners, the secure element (1) comprising: - a communication unit (56) configured for receiving at least one certificate from a current transaction partner; - a certificate verification unit (53) configured to verify the at least one received certificate (12-2, 13-2, 14-2) and to provide a verified data element (15-2), wherein the verification unit (53) uses verification data (11, 20) stored in a non-volatile memory (54) of the secure element (1); - a transaction unit (52) using the verified data element (15-2) provided by the certificate verification unit (53) in a current transaction of the transaction system. In the present secure element the verification data (11, 20) stored in the non-volatile memory (54) comprise dynamic verification data (20); the dynamic verification data (20) comprise at least two records (22a-22c) of previous transactions of the secure element (1) in the transaction system; and the records (22a-22c) in the dynamic verification data (20) stored in the non-volatile memory (54) respectively comprise a certificate reference (H-2, H-5) of at least one previous certificate received and verified in a previous transaction.