Security Element Application Authorization Without Code Recertification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile devices with security elements cannot modify applications due to certification and security requirements, leading to high costs and time for recertification when third-party providers supply binary code, necessitating a solution for flexible transaction control without modifying source or binary code.
Innovation Solution
A method and device that authorize applications on security elements by transmitting authorization information from a user verification element, comparing it with a list, and selecting the application or performing transactions if the information meets the requirements, using a user verification element and security element with integrated or contactless communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If applications are supplied as binary code by third-party providers without source code access, then security requirements are met, but modification and recertification costs and time increase substantially
Solution Approach 1:
The patent separates the application binary code from the authorization control mechanism. The security element is divided into distinct components: the application binary code (which remains unchanged and certified) and the authorization information list (which can be dynamically modified). This segmentation allows the authorization criteria to be updated without touching the certified application code, thus avoiding recertification requirements while maintaining security compliance.
Solution Approach 2:
The patent introduces an intermediary authorization mechanism that acts as a mediator between the application and the execution environment. The authorization information list serves as an intermediary layer that controls application execution without modifying the application itself. This intermediary approach allows flexible control and updates without requiring changes to the certified binary code, thereby eliminating recertification needs while maintaining security.
2Reliability
If applications are modified to add access protection, then security is improved, but source code modification and re-installation are required
Solution Approach 1:
The patent implements preliminary action by pre-configuring the authorization information list with access protection criteria during the security element setup phase. Instead of modifying applications later to add protection, the authorization list is prepared in advance with all necessary access control rules. This preliminary configuration enables access protection to be applied automatically when applications are loaded, eliminating the need for subsequent source code modifications and re-installations.
Solution Approach 2:
The patent uses copying by creating a separate authorization information list that mirrors the access control requirements without copying or modifying the actual application source code. The authorization list contains references to and criteria for controlling application execution, serving as a lightweight copy of the security requirements. This approach allows access protection to be implemented by working with the authorization list copy rather than the original application code, avoiding modification complexity.
3Reliability
If certification requirements prevent application modification, then security is maintained, but flexible transaction control becomes difficult
Solution Approach 1:
The patent applies dynamics by making the authorization information list dynamically modifiable while keeping the application binary code static and certified. The authorization list can be updated, modified, and adapted to changing transaction control requirements without triggering recertification processes. This dynamic aspect allows flexible transaction control through criteria changes in the authorization list, while the static certified application code maintains security requirements. The system thus achieves both security maintenance and transaction flexibility simultaneously.
Data Source
AI summary
A method for authorizing an application installed on a security element includes the steps of transmitting authorization information from a user verification element to the security element, comparing the authorization information with at least one requirement from a list on the security element; and selecting the application on the security element and/or performing a transaction by means of the application, provided that the authorization information meets the requirements from the list.


