Security Element Application Authorization via User Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security elements with installed applications face challenges in securing transactions due to limitations in modifying or reinstalling applications, leading to significant costs and time expenditures, especially when third-party providers are involved.
Innovation Solution
A method and device that authorize applications on security elements by transferring authorization information from a user verification element, comparing it against a list of requirements, and enabling execution or transaction based on user verification status without modifying the application's source or binary code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If applications are modified to meet security requirements, then transaction security is improved, but manufacturing cost and time expenditure increase significantly
Solution Approach 1:
The patent introduces a certification authority as an intermediary that issues digital certificates to applications. Instead of modifying applications to meet security requirements, the certification authority verifies and certifies them, providing a trusted intermediary that bridges the gap between application providers and security requirements.
Solution Approach 2:
The patent implements preliminary certification of applications before they are deployed to security elements. The certification authority performs security verification in advance, and certified applications are stored with digital certificates, eliminating the need for costly post-deployment modifications.
2Reliability
If third-party providers are commissioned to modify applications, then security requirements are met, but certification costs and time expenditure increase
Solution Approach 1:
The certification authority serves as a trusted intermediary that streamlines the certification process. Third-party providers can submit applications to the certification authority, which performs automated verification and issues digital certificates, significantly reducing the time and cost compared to manual commissioning and recertification.
Solution Approach 2:
The patent changes the certification parameter from manual review and recertification to automated digital certificate verification. The security element can efficiently verify digital certificates using cryptographic methods, reducing certification time from days or weeks to seconds.
3Adaptability or versatility
If applications are installed on security elements without modification, then deployment flexibility is improved, but transaction authorization control is weakened
Solution Approach 1:
The patent introduces digital certificates as an intermediary mechanism that enables unauthorized control without restricting deployment flexibility. Applications can be freely deployed to security elements, and the certification authority's digital certificates provide the necessary authorization control layer.
Solution Approach 2:
The patent uses digital certificate copying to enable authorization control. Instead of modifying applications, the system copies and verifies digital certificates associated with certified applications, allowing flexible deployment while maintaining secure authorization control through certificate validation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method according to the invention for authorizing an application (12) installed on a security element (3) comprises the steps of transferring (42) authorization information from a user verification element (100) to the security element (3), comparing (43) the authorization information with respect to at least one requirement of a list on the security element (3); and selecting (45) the application (12) on the security element (3) and/or carrying out (46) a transaction using the application (12) provided that the authorization information meets the requirements of the list.