Security Element Loading Authorization Through Application Type Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security elements, such as chip cards, lack robust mechanisms to verify the nature of applications being loaded, allowing improper data to be sent via secure communication channels.
Innovation Solution
A method and device for authorizing application loading on security elements by verifying the type and provider of the application using user identifiers, application types, and provider identifiers, ensuring validation through comparison and calculation of verification information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic mechanisms are used to secure communication channels, then data confidentiality and integrity are guaranteed, but the security element cannot verify the nature of incoming data
Solution Approach 1:
The patent segments the verification process into two independent parts: cryptographic verification of data integrity and type verification of application nature. The security element maintains both cryptographic credentials for secure communication and type credentials for application verification, allowing it to independently validate both aspects without compromising either confidentiality or adaptability.
2Reliability
If the security element accepts all data through secure channels, then communication trust is maintained, but improper applications can be loaded
Solution Approach 1:
The patent implements preliminary verification by checking the application type against stored type credentials before allowing the loading process to complete. This pre-verification step ensures that even though communication trust is maintained through cryptographic mechanisms, improper applications are blocked before they can compromise the security element.
3Reliability
If verification mechanisms are added to check application types, then loading security is improved, but communication complexity increases
Solution Approach 1:
The patent extracts the type verification function as a separate, dedicated mechanism independent of the cryptographic verification process. By separating these functions and implementing them through distinct credential types, the system adds security without creating complex interactions between verification mechanisms, maintaining clarity and manageability.
Data Source
AI summary
A method and device for authorizing the loading of an application onto a security element that can communicate with a loading server of an application provider. The method is implemented by the security element and includes the following steps: obtaining at least one type of authorized application; obtaining the type of application to be loaded; comparing the type of application to be loaded and the type of authorized application; depending on the results of the comparison, authorizing the loading of the application.

