Electronic Token Secret Data Rebuild Method

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for initializing secret data in electronic tokens, such as SIM cards, often occur at low security levels and do not meet high security requirements, especially in machine-to-machine (M2M) domains where secure data initialization is critical and may involve switching between mobile network operators (MNOs).

Innovation Solution

A method where no part of the secret value is sent outside a high security level site; instead, a recipe and reference to stored data are sent to the token, allowing it to rebuild the secret value securely, adhering to high security standards like GSM Security Accreditation Scheme (SAS) requirements, and enabling secure switching between MNOs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If secret data is sent to electronic token at low security level site, then initialization can be performed flexibly and late in lifecycle, but security level is insufficient

Engineering Contradiction:
Improveflexibility of initialization timingVSAvoidsecurity level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The secret data is segmented into two parts: a first part stored securely in the electronic token during manufacturing, and a second part generated later by combining the first part with additional data. This segmentation allows the token to be initialized late in the lifecycle (improving adaptability) while the critical secret component remains protected in high-security manufacturing (maintaining security level).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first part of the secret data is prepared and stored in the electronic token during high-security manufacturing, before the token is deployed. This preliminary action ensures that the critical secret material is established under secure conditions, while allowing flexible initialization of the complete secret data later when combined with additional information.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If SIM card is welded to wireless module at early stage, then integration is achieved, but secret data remains uninitialized and security is compromised

Engineering Contradiction:
Improveintegration efficiencyVSAvoidsecurity level
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The electronic token is prepared with the first part of the secret data during high-security manufacturing, but the complete secret data is not finalized until later when additional data is provided. This allows the token to be physically integrated early (improving ease of manufacture) while the security-critical secret data is completed under controlled conditions later (maintaining security level).

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The secret data in the electronic token is dynamic rather than static - it evolves from containing only the first part to containing the complete secret data when combined with additional information. This dynamic approach allows early physical integration while delaying the finalization of secret data until security conditions are appropriate.

Inventive Principle:
Principle #15Dynamics

3Reliability

If secret value is encrypted and sent through secured channel, then some security is improved, but security level is still not satisfactory

Engineering Contradiction:
Improvesecurity levelVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The critical secret component (first part of secret data) is extracted and stored in the electronic token during high-security manufacturing, separate from the additional data that will be provided later. This extraction eliminates the need for complex encrypted transmission mechanisms, as the critical secret material never leaves the secure manufacturing environment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The electronic token itself performs the security function by securely storing the first part of the secret data and later combining it with additional data to generate the complete secret value. This self-service approach eliminates the need for external secured transmission channels and complex encryption mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2380329B1Method of managing sensitive data in an electronic token
Publication Date: 2018.07.25 THALES DIS FRANCE SA
  • EP2380329B1 patent drawingFigure 1
  • EP2380329B1 patent drawingFigure 2

AI summary

The invention is a method of managing data in an electronic token. The method comprising the following steps : - storing a first data into the electronic token and into a secured site, identifying a secret data intended to be initialized in the electronic token, - identifying instructions and a subset of the first data wherein the subset allows rebuilding the secret data by applying the instructions, identifying a reference allowing to identify said subset, - sending the reference to the electronic token, - in the electronic token, rebuilding the secret data from the first data and the reference by applying the instructions.