Secure Element Wireless Input Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing security solutions are inadequate in protecting sensitive content from malware with system-level privileges, particularly when using wireless input devices, as they often fail to secure content entered via wireless peripherals due to vulnerabilities in the wireless interface.

Innovation Solution

Establishing an out-of-band channel between the wireless interface and a backend receiver that bypasses the operating system, using a secure wireless stack to control the interface and encrypt data transmission, ensuring that malware cannot access the information entered via wireless peripherals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless input functionality is integrated into the main operating system, then ease of operation is improved, but security against system-level malware deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the wireless input functionality from the main operating system by integrating it directly into the secure element. This creates a separate, isolated processing path that handles wireless input data independently from the vulnerable OS layer, thereby maintaining ease of operation while improving security against system-level malware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element acts as an intermediary between the wireless interface and the operating system. It receives wireless input data, processes it securely, and only passes authenticated data to the OS, preventing malware in the OS from accessing raw wireless communication and protecting against keyloggers and rootkits.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If traditional software-based security solutions are used, then ease of manufacture is improved, but effectiveness against system-level malware deteriorates

Engineering Contradiction:
Improveease of manufactureVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces software-based security mechanisms with hardware-based security by integrating wireless input functionality directly into the secure element's hardware. This hardware-level isolation creates inherent security barriers that malware cannot compromise through software exploits, effectively countering rootkits and system-level threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If wireless interface is accessible by the operating system, then adaptability is improved, but vulnerability to malware attacks increases

Engineering Contradiction:
ImproveadaptabilityVSAvoidvulnerability to malware
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by creating different security zones within the system. The wireless interface communication occurs in a high-security zone within the secure element, while the operating system operates in a lower-security zone. Data flows securely between zones through controlled interfaces, maintaining adaptability while protecting against malware through localized security enforcement.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9705916B2Integrating wireless input functionality into secure elements
Publication Date: 2017.07.11 INTEL CORP
  • US9705916B2 patent drawing
  • US9705916B2 patent drawing
  • US9705916B2 patent drawing

AI summary

Systems and methods may provide for establishing an out-of-band (OOB) channel between a local wireless interface and a remote backend receiver, and receiving information from a peripheral device via the local wireless interface. Additionally, the information may be sent to the backend receiver via the OOB channel, wherein the OOB channel bypasses a local operating system. In one example, a secure Bluetooth stack is used to receive the information from the peripheral device.