Secure Token Management via Secure Element Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing token management systems are insecure, as tokens can be easily replicated and used fraudulently, allowing malicious applications to obtain and distribute token information, leading to unauthorized transactions.

Innovation Solution

A secure token management system utilizing a secure element and a secure device processor, which performs cryptographic operations to create and manage encrypted tokens, adding identification information and performing additional encryption to generate a modified secure token, ensuring token authenticity and validity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If tokens are stored in device memory for transaction use, then transaction convenience is improved, but token security deteriorates as malicious applications can access and replicate token information

Engineering Contradiction:
Improvetransaction convenienceVSAvoidtoken security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the device into two distinct security zones: secure element memory (highly protected, isolated from malicious applications) and application memory (accessible by applications but cannot store tokens). This segmentation allows tokens to be stored securely while still enabling convenient transactions through controlled access mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a token management application as an intermediary layer between the secure element memory and the external world. This intermediary handles all token operations (storage, retrieval, transmission) without exposing the actual token data to malicious applications, thus maintaining both security and operational convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If token information is made accessible to applications for transaction processing, then transaction functionality is improved, but fraud risk increases as tokens can be replicated and distributed

Engineering Contradiction:
Improvetransaction functionalityVSAvoidfraud risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive token information from the application environment and stores it exclusively in the secure element memory, which is isolated from malicious applications. The token management application can access tokens only through controlled interfaces that prevent replication, thus maintaining transaction functionality while eliminating fraud risk.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary anti-action by establishing security controls before any token access can occur. The secure element memory enforces access policies that allow tokens to be used for transactions but prevent copying or extraction, proactively blocking potential fraud before it can happen.

Inventive Principle:
Principle #9Preliminary anti-action

3Device complexity

If traditional token storage methods are used in device memory, then implementation simplicity is maintained, but security vulnerabilities arise allowing token replication by malicious applications

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent adds a new dimensional layer of security by introducing the secure element memory as a separate, protected storage dimension. Instead of relying solely on software-based security in the application memory, the solution moves token storage to a hardware-backed secure dimension that is physically isolated from malicious applications, thus improving security without significantly complicating the overall implementation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9419961B2Apparatus and method for managing use of secure tokens
Publication Date: 2016.08.16 AT&T INTELLECTUAL PROPERTY I L P
  • US9419961B2 patent drawing
  • US9419961B2 patent drawing
  • US9419961B2 patent drawing

AI summary

A system that incorporates the subject disclosure may perform, for example, operations including receiving an encrypted secure token from a secure token application function that is remote from the communication device, storing the encrypted secure token in a secure element memory of the secure element, accessing user input requesting the encrypted secure token where the secure device processor is separate from the secure element and is in communication with the secure element, generating a modified secure token by adding identification information to the encrypted secure token and by performing a second encryption of the encrypted secure token with the identification information, receiving the modified secure token from the secure element, and providing the modified secure token to a receiving device. Other embodiments are disclosed.