Trusted Application Trust Verification for Secure Element Efficiency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current card application management in secure elements is inefficient due to limited computing resources, leading to low execution efficiency and potential security risks when delegating operations to other environments.
Innovation Solution
Establishing a trust relationship between a trusted application entity and a security domain within a secure element, allowing the trusted application to verify and execute card content management instructions, thereby offloading computational tasks and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If verification operations are performed within the secure element SE, then security is maintained, but execution efficiency deteriorates due to limited computing resources
Solution Approach 1:
The patent extracts the verification operation from the secure element SE and relocates it to an external entity. Specifically, the verification unit in the external entity verifies the card content management instruction by using the first key to decrypt the authorization code and compare it with the verification result, thereby performing verification operations outside the resource-constrained SE environment while maintaining security through cryptographic protocols
Solution Approach 2:
The patent introduces an external entity as an intermediary between the server and the secure element SE. This external entity includes a verification unit that acts as a mediator to verify card content management instructions by decrypting authorization codes and comparing them with verification results, thereby offloading computational burden from the SE while maintaining security through controlled information exchange
2Productivity
If verification operations are transferred to an external entity, then execution efficiency improves, but security deteriorates due to potential exposure of sensitive operations
Solution Approach 1:
The patent applies preliminary action by having the external entity verify the card content management instruction before executing it within the secure element. The verification unit decrypts the authorization code using the first key and compares it with the verification result in advance, ensuring that only verified instructions are processed by the SE, thus maintaining security while improving efficiency
Solution Approach 2:
The patent changes the location parameter of the verification operation from inside the secure element to an external entity. By relocating the verification unit to the external entity and having it perform verification operations outside the SE boundary, the system improves execution efficiency while maintaining security through controlled parameter exchange and verification protocols
Data Source
AI summary
A method includes sending, by a trusted application (TA) entity, a certificate of the TA entity and a private key signature of the TA entity to a target security domain (SD). The certificate and the private key signature enable the target SD to perform trust verification via a server, obtaining, by the TA entity, a first key of the target SD when the trust verification of the TA entity succeeds, and establishing, by the TA entity, a trust relationship with the target SD.


