Electronic Token Secret Data Rebuild Method
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for initializing secret data in electronic tokens, such as SIM cards, often occur at low security levels and do not meet high security requirements, especially in machine-to-machine (M2M) domains where secure data initialization is critical and may involve switching between mobile network operators (MNOs).
Innovation Solution
A method where no part of the secret value is sent outside a high security level site; instead, a recipe and reference to stored data are sent to the token, allowing it to rebuild the secret value securely, adhering to high security standards like GSM Security Accreditation Scheme (SAS) requirements, and enabling secure switching between MNOs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If secret data is sent to electronic token at low security level site, then initialization can be performed flexibly and late in lifecycle, but security level is insufficient
Solution Approach 1:
The secret data is segmented into two parts: a first part stored securely in the electronic token during manufacturing, and a second part generated later by combining the first part with additional data. This segmentation allows the token to be initialized late in the lifecycle (improving adaptability) while the critical secret component remains protected in high-security manufacturing (maintaining security level).
Solution Approach 2:
The first part of the secret data is prepared and stored in the electronic token during high-security manufacturing, before the token is deployed. This preliminary action ensures that the critical secret material is established under secure conditions, while allowing flexible initialization of the complete secret data later when combined with additional information.
2Ease of manufacture
If SIM card is welded to wireless module at early stage, then integration is achieved, but secret data remains uninitialized and security is compromised
Solution Approach 1:
The electronic token is prepared with the first part of the secret data during high-security manufacturing, but the complete secret data is not finalized until later when additional data is provided. This allows the token to be physically integrated early (improving ease of manufacture) while the security-critical secret data is completed under controlled conditions later (maintaining security level).
Solution Approach 2:
The secret data in the electronic token is dynamic rather than static - it evolves from containing only the first part to containing the complete secret data when combined with additional information. This dynamic approach allows early physical integration while delaying the finalization of secret data until security conditions are appropriate.
3Reliability
If secret value is encrypted and sent through secured channel, then some security is improved, but security level is still not satisfactory
Solution Approach 1:
The critical secret component (first part of secret data) is extracted and stored in the electronic token during high-security manufacturing, separate from the additional data that will be provided later. This extraction eliminates the need for complex encrypted transmission mechanisms, as the critical secret material never leaves the secure manufacturing environment.
Solution Approach 2:
The electronic token itself performs the security function by securely storing the first part of the secret data and later combining it with additional data to generate the complete secret value. This self-service approach eliminates the need for external secured transmission channels and complex encryption mechanisms.
Data Source
Figure 1
Figure 2
AI summary
The invention is a method of managing data in an electronic token. The method comprising the following steps : - storing a first data into the electronic token and into a secured site, identifying a secret data intended to be initialized in the electronic token, - identifying instructions and a subset of the first data wherein the subset allows rebuilding the secret data by applying the instructions, identifying a reference allowing to identify said subset, - sending the reference to the electronic token, - in the electronic token, rebuilding the secret data from the first data and the reference by applying the instructions.