Personalizing Security Elements via Digital Control Commands

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for personalizing security elements, such as SIM cards or eUICCs, require physical equipment and secure environments, leading to high technical effort and potential security risks, as they necessitate the use of dongles that can be lost or stolen, and often require secure environments for data transfer.

Innovation Solution

A method that uses personalization control commands to write data directly into a secure data memory of the security element, eliminating the need for physical hardware and ensuring secure, one-time use of personalization data, which is generated dynamically or embedded securely, using white-box cryptography to prevent unauthorized access and reuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical equipment (dongle) is used to personalize security elements, then personalization data can be provided to the security element, but technical effort increases and security risks arise from potential loss or theft of the physical key

Engineering Contradiction:
ImprovesecurityVSAvoidtechnical effort
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the personalization data from physical hardware (dongle) and transfers it to a digital format that can be transmitted via air interface. The security element is personalized by receiving personalization control commands containing the data directly, eliminating the need for physical contact devices and reducing both technical complexity and security risks associated with physical key loss or theft.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical/physical system (dongle insertion, physical contact) with an electromagnetic/digital system (air interface transmission, wireless communication). Personalization is achieved through signal transmission rather than physical device connection, simplifying the process and eliminating mechanical security risks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a dongle with security element is used for personalization, then secure environment is provided, but unnecessary technical effort arises from securing the dongle and requiring secure environment for data transfer

Engineering Contradiction:
Improvesecure environmentVSAvoidtechnical effort
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security element personalizes itself by receiving and processing personalization control commands directly. The system performs the personalization function autonomously without requiring an external secure environment or intermediary dongle, eliminating the technical effort needed to establish and maintain secure physical environments for data transfer.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If personalization data is provided through physical dongle, then security element can be personalized, but possibility of attack increases as physical key could be stolen or lost

Engineering Contradiction:
Improvepersonalization capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent uses digital copying of personalization data transmitted via air interface instead of physical key distribution. The personalization control commands contain the necessary data in digital form that can be transmitted securely without physical contact, eliminating the risk of physical key theft or loss while maintaining personalization capability.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3277005B1Personalization of a security element
Publication Date: 2019.09.25 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP3277005B1 patent drawingFigure 1
  • EP3277005B1 patent drawingFigure 2
  • EP3277005B1 patent drawingFigure 3

AI summary

The present invention relates to a method for personalizing a security element, for example a SIM card or a chip card for mobile phones, which makes it possible to provide personalization data to the security element with minimal technical effort. The invention further relates to a personalization system configured according to the proposed method. A computer program product is also proposed, comprising control commands that implement the method and/or operate the proposed personalization system.