Security Element Loading Authorization Through Application Type Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security elements, such as chip cards, lack robust mechanisms to verify the nature of applications being loaded, allowing improper data to be sent via secure communication channels.

Innovation Solution

A method and device for authorizing application loading on security elements by verifying the type and provider of the application using user identifiers, application types, and provider identifiers, ensuring validation through comparison and calculation of verification information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic mechanisms are used to secure communication channels, then data confidentiality and integrity are guaranteed, but the security element cannot verify the nature of incoming data

Engineering Contradiction:
Improvedata confidentiality and integrityVSAvoidability to verify application nature
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the verification process into two independent parts: cryptographic verification of data integrity and type verification of application nature. The security element maintains both cryptographic credentials for secure communication and type credentials for application verification, allowing it to independently validate both aspects without compromising either confidentiality or adaptability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the security element accepts all data through secure channels, then communication trust is maintained, but improper applications can be loaded

Engineering Contradiction:
Improvecommunication trustVSAvoidloading of improper applications
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary verification by checking the application type against stored type credentials before allowing the loading process to complete. This pre-verification step ensures that even though communication trust is maintained through cryptographic mechanisms, improper applications are blocked before they can compromise the security element.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If verification mechanisms are added to check application types, then loading security is improved, but communication complexity increases

Engineering Contradiction:
Improveloading securityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the type verification function as a separate, dedicated mechanism independent of the cryptographic verification process. By separating these functions and implementing them through distinct credential types, the system adds security without creating complex interactions between verification mechanisms, maintaining clarity and manageability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12353540B2Authorization for the loading of an application onto a security element
Publication Date: 2025.07.08 ORANGE SA
  • US12353540B2 patent drawing
  • US12353540B2 patent drawing

AI summary

A method and device for authorizing the loading of an application onto a security element that can communicate with a loading server of an application provider. The method is implemented by the security element and includes the following steps: obtaining at least one type of authorized application; obtaining the type of application to be loaded; comparing the type of application to be loaded and the type of authorized application; depending on the results of the comparison, authorizing the loading of the application.