Smart Card Secure Execution Environment for Complex Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure devices, such as smart cards, face limitations in functionality and capacity when executing complex applications outside the chip card, leading to inadequate data and communication security in unsecured environments.
Innovation Solution
A method and device that create a secure, autonomous environment using conventional smart cards, where applications are authenticated and executed only through sealed commands, ensuring confidentiality and integrity by using a chip card to verify the authenticity of applications and data, and restricting communication to predetermined interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If complex applications are executed outside the chip card, then functionality and capacity are improved, but data and communication security deteriorates
Solution Approach 1:
The system divides the execution environment into two distinct segments: a secure chip card segment for authentication and critical security operations, and an external device segment for application execution. This segmentation allows complex applications to run outside the chip card while maintaining security through the chip card's authentication functions, resolving the contradiction between functionality and security.
Solution Approach 2:
The chip card acts as an intermediary between the unsecured external environment and the data storage system. It provides authentication services and verifies the legitimacy of applications and data before they can access secure resources, enabling complex applications to execute externally while maintaining data security through this intermediary security layer.
2Ease of operation
If applications are executed in an open environment, then ease of operation is improved, but confidentiality and integrity of data processing deteriorates
Solution Approach 1:
The secure execution environment is nested within the open external environment. The chip card and its authentication mechanisms are embedded in the external device, creating a secure enclave that can execute applications with full operational capability while maintaining confidentiality and integrity through the nested security layer.
3Reliability
If sealed commands are used for application authentication, then data security is improved, but device complexity increases
Solution Approach 1:
The chip card performs self-service authentication by autonomously verifying sealed commands and managing its own security functions. The authentication mechanism is embedded within the chip card itself, eliminating the need for complex external authentication systems and reducing overall device complexity while maintaining high security through the chip card's intrinsic authentication capabilities.
Data Source
Figure 1
AI summary
The invention relates to an autonomous and secure environment in which complex applications can run using a traditional chip card (90), also called a smart card. For this purpose, a method for executing applications in a secure device (20) that can be connected to an external communication device (120) is provided. According to the method, a sealed command to call an application stored in the device (20) is authenticated by a chip card (90) arranged in the device. It is also checked whether the application may be executed by the device (20). Said check occurs inside the device (20, 100) but outside the chip card (90). If the application may be executed by the device (20), the application is executed in the device after successful authentication.