Security Element Application Authorization via User Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security elements with installed applications face challenges in securing transactions due to limitations in modifying or reinstalling applications, leading to significant costs and time expenditures, especially when third-party providers are involved.

Innovation Solution

A method and device that authorize applications on security elements by transferring authorization information from a user verification element, comparing it against a list of requirements, and enabling execution or transaction based on user verification status without modifying the application's source or binary code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If applications are modified to meet security requirements, then transaction security is improved, but manufacturing cost and time expenditure increase significantly

Engineering Contradiction:
Improvetransaction securityVSAvoidapplication modification cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces a certification authority as an intermediary that issues digital certificates to applications. Instead of modifying applications to meet security requirements, the certification authority verifies and certifies them, providing a trusted intermediary that bridges the gap between application providers and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary certification of applications before they are deployed to security elements. The certification authority performs security verification in advance, and certified applications are stored with digital certificates, eliminating the need for costly post-deployment modifications.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If third-party providers are commissioned to modify applications, then security requirements are met, but certification costs and time expenditure increase

Engineering Contradiction:
Improvesecurity requirement complianceVSAvoidcertification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The certification authority serves as a trusted intermediary that streamlines the certification process. Third-party providers can submit applications to the certification authority, which performs automated verification and issues digital certificates, significantly reducing the time and cost compared to manual commissioning and recertification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the certification parameter from manual review and recertification to automated digital certificate verification. The security element can efficiently verify digital certificates using cryptographic methods, reducing certification time from days or weeks to seconds.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If applications are installed on security elements without modification, then deployment flexibility is improved, but transaction authorization control is weakened

Engineering Contradiction:
Improveapplication deployment flexibilityVSAvoidauthorization control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces digital certificates as an intermediary mechanism that enables unauthorized control without restricting deployment flexibility. Applications can be freely deployed to security elements, and the certification authority's digital certificates provide the necessary authorization control layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses digital certificate copying to enable authorization control. Instead of modifying applications, the system copies and verifies digital certificates associated with certified applications, allowing flexible deployment while maintaining secure authorization control through certificate validation.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP4423636B1Authorizing an application on a security element
Publication Date: 2025.12.03 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP4423636B1 patent drawingFigure 1
  • EP4423636B1 patent drawingFigure 2
  • EP4423636B1 patent drawingFigure 3

AI summary

A method according to the invention for authorizing an application (12) installed on a security element (3) comprises the steps of transferring (42) authorization information from a user verification element (100) to the security element (3), comparing (43) the authorization information with respect to at least one requirement of a list on the security element (3); and selecting (45) the application (12) on the security element (3) and/or carrying out (46) a transaction using the application (12) provided that the authorization information meets the requirements of the list.