Trusted Application Trust Verification for Secure Element Efficiency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current card application management in secure elements is inefficient due to limited computing resources, leading to low execution efficiency and potential security risks when delegating operations to other environments.

Innovation Solution

Establishing a trust relationship between a trusted application entity and a security domain within a secure element, allowing the trusted application to verify and execute card content management instructions, thereby offloading computational tasks and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If verification operations are performed within the secure element SE, then security is maintained, but execution efficiency deteriorates due to limited computing resources

Engineering Contradiction:
ImprovesecurityVSAvoidexecution efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the verification operation from the secure element SE and relocates it to an external entity. Specifically, the verification unit in the external entity verifies the card content management instruction by using the first key to decrypt the authorization code and compare it with the verification result, thereby performing verification operations outside the resource-constrained SE environment while maintaining security through cryptographic protocols

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an external entity as an intermediary between the server and the secure element SE. This external entity includes a verification unit that acts as a mediator to verify card content management instructions by decrypting authorization codes and comparing them with verification results, thereby offloading computational burden from the SE while maintaining security through controlled information exchange

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If verification operations are transferred to an external entity, then execution efficiency improves, but security deteriorates due to potential exposure of sensitive operations

Engineering Contradiction:
Improveexecution efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by having the external entity verify the card content management instruction before executing it within the secure element. The verification unit decrypts the authorization code using the first key and compares it with the verification result in advance, ensuring that only verified instructions are processed by the SE, thus maintaining security while improving efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the location parameter of the verification operation from inside the secure element to an external entity. By relocating the verification unit to the external entity and having it perform verification operations outside the SE boundary, the system improves execution efficiency while maintaining security through controlled parameter exchange and verification protocols

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11552807B2Data processing method and apparatus
Publication Date: 2023.01.10 HUAWEI TECH CO LTD
  • US11552807B2 patent drawing
  • US11552807B2 patent drawing
  • US11552807B2 patent drawing

AI summary

A method includes sending, by a trusted application (TA) entity, a certificate of the TA entity and a private key signature of the TA entity to a target security domain (SD). The certificate and the private key signature enable the target SD to perform trust verification via a server, obtaining, by the TA entity, a first key of the target SD when the trust verification of the TA entity succeeds, and establishing, by the TA entity, a trust relationship with the target SD.