Trusted Application SE Applet Installation via TEE

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for installing a secure element (SE) applet on a user terminal are time-consuming due to complex interaction chains involving multiple servers, which prolong the installation process.

Innovation Solution

A method where a trusted application (TA) on the user terminal parses and sends the required signaling to the SE to install the applet directly, eliminating the need for external server involvement and establishing a secure channel for installation, thereby shortening the interaction chain and reducing installation time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the user terminal downloads and installs the SE applet using the application TSM server and OEM TSM server with secure channel forwarding, then the SE applet can be installed securely, but the interaction chain becomes complex and installation time increases

Engineering Contradiction:
Improveinstallation securityVSAvoidinstallation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the SE applet installation function from the complex multi-server interaction chain and relocates it directly to the user terminal's TEE environment. The TA in the TEE directly downloads and installs the SE applet on the SE without requiring application TSM server or OEM TSM server involvement, thereby eliminating the complex interaction chain while maintaining security through the trusted execution environment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces the TEE as an intermediary trusted execution environment that mediates between the user terminal and the SE. The TA within the TEE acts as a trusted intermediary that can directly communicate with and install applets on the SE, replacing the need for multiple external TSM servers while maintaining the security requirements through the isolated and protected TEE environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple servers (application TSM server and OEM TSM server) are involved in the SE applet installation process, then security requirements are met, but the interaction chain complexity increases

Engineering Contradiction:
Improvesecurity requirement complianceVSAvoidinteraction chain complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functions of the application TSM server and OEM TSM server into a single integrated function performed by the TA in the TEE. Instead of having separate servers handle different aspects of SE applet installation, the trusted application within the trusted execution environment consolidates these responsibilities, directly downloading and installing applets on the SE without requiring external server coordination.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent enables the user terminal's TEE to self-service the SE applet installation process. The TA within the TEE autonomously downloads the SE applet from the server and directly installs it on the SE without requiring external TSM servers to coordinate or forward commands. This self-service approach within the trusted execution environment maintains security while eliminating the complex multi-server interaction chain.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10977021B2SE applet processing method, terminal, and server
Publication Date: 2021.04.13 HUAWEI TECH CO LTD
  • US10977021B2 patent drawing
  • US10977021B2 patent drawing
  • US10977021B2 patent drawing

AI summary

A secure element (SE) applet installation method, applied to a user terminal with a trusted execution environment (TEE) and an SE, and the TEE is provided with a trusted application (TA). The SE applet installation method includes obtaining, by the TA, an SE applet command package after the user terminal receives an installation request instructing the TA to obtain the SE applet command package, parsing, by the TA, the SE applet command package to obtain target signaling included in the SE applet command package, where the target signaling being used to install a target SE applet, and sending, by the TA, the target signaling to the SE to install the target SE applet according to the target signaling.