Secure Token Management via Secure Element Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing token management systems are insecure, as tokens can be easily replicated and used fraudulently, allowing malicious applications to obtain and distribute token information, leading to unauthorized transactions.
Innovation Solution
A secure token management system utilizing a secure element and a secure device processor, which performs cryptographic operations to create and manage encrypted tokens, adding identification information and performing additional encryption to generate a modified secure token, ensuring token authenticity and validity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If tokens are stored in device memory for transaction use, then transaction convenience is improved, but token security deteriorates as malicious applications can access and replicate token information
Solution Approach 1:
The patent segments the device into two distinct security zones: secure element memory (highly protected, isolated from malicious applications) and application memory (accessible by applications but cannot store tokens). This segmentation allows tokens to be stored securely while still enabling convenient transactions through controlled access mechanisms.
Solution Approach 2:
The patent introduces a token management application as an intermediary layer between the secure element memory and the external world. This intermediary handles all token operations (storage, retrieval, transmission) without exposing the actual token data to malicious applications, thus maintaining both security and operational convenience.
2Adaptability or versatility
If token information is made accessible to applications for transaction processing, then transaction functionality is improved, but fraud risk increases as tokens can be replicated and distributed
Solution Approach 1:
The patent extracts the sensitive token information from the application environment and stores it exclusively in the secure element memory, which is isolated from malicious applications. The token management application can access tokens only through controlled interfaces that prevent replication, thus maintaining transaction functionality while eliminating fraud risk.
Solution Approach 2:
The patent implements preliminary anti-action by establishing security controls before any token access can occur. The secure element memory enforces access policies that allow tokens to be used for transactions but prevent copying or extraction, proactively blocking potential fraud before it can happen.
3Device complexity
If traditional token storage methods are used in device memory, then implementation simplicity is maintained, but security vulnerabilities arise allowing token replication by malicious applications
Solution Approach 1:
The patent adds a new dimensional layer of security by introducing the secure element memory as a separate, protected storage dimension. Instead of relying solely on software-based security in the application memory, the solution moves token storage to a hardware-backed secure dimension that is physically isolated from malicious applications, thus improving security without significantly complicating the overall implementation.
Data Source
AI summary
A system that incorporates the subject disclosure may perform, for example, operations including receiving an encrypted secure token from a secure token application function that is remote from the communication device, storing the encrypted secure token in a secure element memory of the secure element, accessing user input requesting the encrypted secure token where the secure device processor is separate from the secure element and is in communication with the secure element, generating a modified secure token by adding identification information to the encrypted secure token and by performing a second encryption of the encrypted secure token with the identification information, receiving the modified secure token from the secure element, and providing the modified secure token to a receiving device. Other embodiments are disclosed.


