Smartcard and Security Token Emulation with eUICC Secure Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security, identification, and transactional devices such as smart cards and key fobs are inconvenient, prone to loss, and pose security risks due to connectivity issues and storage of sensitive data on third-party servers.
Innovation Solution
Integrate smart cards and security tokens into mobile devices like smartphones, using an embedded universal integrated circuit card (eUICC) for secure data storage and processing, enabling over-the-air data injection and emulation of these devices, reducing the need for physical interaction and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If smart cards and key fobs are used for security and transactions, then security functions are provided, but convenience deteriorates due to physical form factors and connectivity issues
Solution Approach 1:
The patent combines multiple security functions (smart card, key fob, authentication token) into a single integrated device with unified processing capability. The device merges cryptographic processing, secure element functionality, and communication interfaces into one unit, eliminating the need to carry separate physical cards and key fobs while maintaining all security functions.
Solution Approach 2:
The integrated device performs multiple security functions simultaneously - it can act as a smart card for authentication, a key fob for access control, and a transactional device for payments. The processing device includes versatile cryptographic capabilities that support various security protocols and communication standards, making it universally applicable across different security scenarios.
2Ease of operation
If secret data is stored on third-party servers, then data access is enabled, but security risks increase due to connectivity problems and external storage vulnerabilities
Solution Approach 1:
The patent extracts secret data and cryptographic keys from external third-party servers and stores them locally within the secure element of the integrated device. This extraction of sensitive data from vulnerable external storage to protected internal storage eliminates dependency on server connectivity while maintaining security. The device can access stored secrets offline without exposing them to network-based attacks.
Solution Approach 2:
The integrated device acts as an intermediary between the user and external systems, maintaining local copies of secret data in a secure element. This intermediary approach allows the device to authenticate with external servers without requiring continuous connectivity to storage infrastructure, mediating between offline security requirements and online authentication needs.
3Adaptability or versatility
If multiple physical security devices are carried, then security coverage is improved, but device complexity and loss risk increase
Solution Approach 1:
The patent merges multiple separate security devices into a single integrated unit that contains multiple secure elements or virtual cards. The device consolidates what would traditionally require separate physical smart cards, key fobs, and authentication tokens into one unified device, reducing the total number of objects the user must carry and manage.
Solution Approach 2:
The integrated device employs a nested structure where multiple virtual security cards and authentication credentials are contained within a single physical device. The secure element hosts multiple isolated security environments, each capable of performing different security functions, similar to nested dolls where smaller units are contained within larger ones.
Data Source
AI summary
A method includes establishing a communicative connection between a first processing device and a second processing device, receiving a request at the first processing device, the request sent from the second processing device via the communicative connection, and processing by a cryptology portion of the first processing device, the processing by the cryptology portion of the first processing device including one or more secrets. The method further includes receiving the one or more secrets at a cryptology portion of the second processing device, processing data associated with the request, by the cryptology portion of the first processing device, the cryptology portion operative to process a result buy emulating a processing device on the cryptology portion of the first processing device to generate a reply, and sending the reply from the first processing device to the second processing device.


