Security Module Data Transfer Using Management Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile terminals lack a secure method to recover and transfer application data from one security module to another, especially after a change in security modules, requiring frequent user interaction with service providers and reinitialization of data upon updates.
Innovation Solution
A method that involves encrypting and decrypting application data using management keys to securely transfer and store it between secure memory areas within the security module, allowing for backup and reinstallation without service provider access, and includes actions like blocking or deleting data to prevent duplication and enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If application data is stored in the security module without encryption, then data access is simple and fast, but data security is compromised and confidential information cannot be protected
Solution Approach 1:
The patent introduces management keys as intermediary elements that mediate between the security module and external systems. The first management key encrypts data within the security module, while the second management key enables authorized access. This key-based intermediary system allows secure data storage while maintaining controlled access capabilities, resolving the contradiction between security and accessibility.
Solution Approach 2:
The patent changes the parameter of data protection from unencrypted storage to encrypted storage using management keys. By transforming the data protection parameter, the system achieves both security (through encryption) and controlled access (through key-based authentication), resolving the contradiction between data security and access simplicity.
2Reliability
If application data is transferred manually through service provider after security module change, then data can be recovered, but user convenience deteriorates and time consumption increases
Solution Approach 1:
The patent enables the security module to perform self-service by automatically managing its own data during transfers. The module uses its internal management keys to encrypt and protect data, and the system automatically handles data recovery without requiring manual intervention from users or service providers. This self-service capability maintains data recovery reliability while dramatically improving user convenience.
Solution Approach 2:
The patent implements preliminary action by pre-configuring the security module with management keys and establishing automated data transfer protocols before any security module change occurs. This preliminary setup enables automatic data recovery and transfer processes, eliminating the need for manual intervention during actual data transfer operations and improving both reliability and ease of operation.
3Reliability
If application data is reinitialized upon update, then application functionality is maintained, but data loss occurs and time consumption increases
Solution Approach 1:
The patent applies the discarding and recovering principle by preserving application data during updates and selectively discarding only obsolete data. The system recovers and retains valuable application data (such as user preferences and configuration information) across updates, eliminating unnecessary data loss and reducing reinitialization time while maintaining application functionality.
Solution Approach 2:
The patent implements preliminary action by pre-protecting application data with management keys before updates occur. This preliminary encryption and protection setup enables the system to quickly recover and restore data during updates without time-consuming reinitialization processes, thus reducing update time while maintaining functionality.
4Reliability
If security module uses read-protected confidential data, then data security is improved, but data accessibility deteriorates and cannot be copied
Solution Approach 1:
The patent introduces management keys as intermediary elements that enable controlled access to read-protected data. The first management key maintains the read-protection for confidentiality, while the second management key acts as an intermediary that provides authorized access and copying capabilities. This intermediary key system resolves the contradiction between data protection and data accessibility/copiability.
Solution Approach 2:
The patent changes the data access parameter from completely read-protected to key-controlled access. By introducing management keys as a new parameter, the system maintains confidentiality through encryption while enabling controlled copying and access for authorized entities, thus resolving the contradiction between protection and adaptability.
Data Source
AI summary
A method is provided for transferring data linked to an application installed on a security module associated with a mobile terminal, the data being stored in a first secure memory area of the security module, suitable for receiving a request to access the data, to read the data, and to transmit or store the data after encryption. A method is also provided for accessing these data suitable for transmitting a request to access, to receive and to decrypt the encrypted data. A security module, a management server, and a system implementing the transfer and access methods are also provided.


