Dynamic Security Element OS Module Activation via OTA
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security elements, such as SIM cards and chip cards, often come with unnecessary operating system functionalities due to uncertainty about their actual usage, leading to 'operating system overhead that can negatively impact performance.
Innovation Solution
The method allows for adjusting access authorizations to operating system modules via the air interface (OTA) after the security element is in use, enabling or disabling specific modules as needed, using a security domain and cryptographic keys to manage these changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If all functionalities are provided in the operating system when the security element is produced, then the security element is prepared for all possible areas of use, but the operating system becomes oversized and provides functionalities that are not required when the security element is actually used, adversely affecting performance
Solution Approach 1:
The patent implements dynamic configuration of the operating system by enabling activation and deactivation of individual operating system modules during operation. The security element can adapt its functionality by activating only the required modules based on actual usage scenarios, transforming the static oversized system into a dynamic, optimized configuration that maintains versatility while eliminating performance degradation from unnecessary functionalities.
Solution Approach 2:
The operating system is segmented into independent, activatable modules rather than a monolithic structure. This segmentation allows the security element to activate only the specific modules needed for particular applications (e.g., NFC module for contactless communication, contact interface module for wired communication), preventing the performance overhead of loading entire functional suites regardless of actual requirements.
2Ease of manufacture
If the operating system includes all optional functionalities from the beginning, then no additional configuration is needed after production, but the system consumes more resources and operates with unnecessary overhead
Solution Approach 1:
The patent prepares the security element during manufacture by pre-configuring the operating system with all potential functionalities available but deactivated. Module activation data is stored in the security element, enabling rapid post-manufacturing configuration through simple activation commands rather than complex setup procedures. This preliminary preparation maintains ease of manufacture while enabling efficient resource usage during operation.
Solution Approach 2:
The system changes its operational parameters by activating or deactivating specific modules based on actual usage requirements. Instead of maintaining a static high-resource configuration, the security element dynamically adjusts its resource consumption by loading only the necessary modules for current tasks, thereby reducing energy and memory usage while maintaining the capability to access all functionalities when needed.
3Adaptability or versatility
If the security element is designed to support all functionalities, then it can be used in multiple applications, but the access authorizations to operating system modules cannot be adjusted after production
Solution Approach 1:
The patent implements a feedback mechanism where the security element receives activation commands from external devices (such as servers or reader devices) and adjusts its module configuration accordingly. The system monitors actual usage patterns and receives feedback about which functionalities are required, then activates or deactivates modules based on this feedback, enabling flexible post-production configuration while maintaining multi-application capability.
Solution Approach 2:
An intermediary activation mechanism is introduced between the security element and the external control system. This intermediary layer (comprising activation data storage and command processing infrastructure) enables flexible configuration of access authorizations after production by mediating between external activation requests and internal module activation, allowing the security element to adapt to different applications without compromising security or requiring physical reconfiguration.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for operating a security element (20), preferably in the form of a chip card, having a processor and a memory, and a corresponding security element (20) are described. The memory stores an operating system (25), which comprises an operating system kernel (25a) and at least one additional operating system module (25b, 25c) for providing optional operating system functionalities, and at least one access authorization which is associated with the operating system module (25b, 25c) and determines whether the operating system module (25b, 25c) can be accessed during operation of the security element (20). In this case, the method comprises the step of changing the access authorization to the operating system module (25b, 25c) in order to provide optional operating system functionalities in response to the reception of a message from a server. The message from the server is preferably an OTA message which is preferably transmitted from the server to the security element (20) via a mobile radio network.