Trusted Processor Random Authorization for Secure Element Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable electronic devices with NFC circuitry face security risks when malicious software prevents secure data from being erased, allowing unauthorized users to perform financial transactions with stolen or lost devices.

Innovation Solution

Incorporating a trusted processor that generates and injects a random authorization number into a secure element, disabling payment functions if the number changes, and monitoring for risky events to ensure only authorized users can perform transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the processor sends deletion commands to erase secure data from the secure element, then the secure data can be removed before device transfer, but malicious software can prevent the deletion command from being sent, leaving secure data vulnerable

Engineering Contradiction:
Improvesecurity of secure dataVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides security functions into two separate components: a secure element that stores secure data and a trusted processor that generates and manages authorization numbers. This segmentation ensures that even if the processor is compromised, the secure element remains protected through its own authorization verification mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authorization number acts as an intermediary between the trusted processor and the secure element. This intermediary mechanism allows the system to verify authorized operations without directly exposing the secure data or relying solely on processor commands, thereby preventing malware from bypassing security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system continuously monitors for risky events and generates new authorization numbers, then security is enhanced against unauthorized access, but device complexity and processing overhead increase

Engineering Contradiction:
Improveprotection against unauthorized transactionsVSAvoidmonitoring and authorization management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted processor proactively generates new authorization numbers in anticipation of potential security risks, such as device theft or loss. By pre-establishing fresh authorization credentials before unauthorized access can occur, the system neutralizes security threats before they can exploit existing authorization numbers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the trusted processor continuously monitors for risky events and responds by generating new authorization numbers. This closed-loop control ensures that security measures are dynamically adjusted based on detected threats, maintaining protection while managing system complexity through automated responses.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10546293B2Apparatuses and methods for using a random authorization number to provide enhanced security for a secure element
Publication Date: 2020.01.28 APPLE INC
  • US10546293B2 patent drawing
  • US10546293B2 patent drawing
  • US10546293B2 patent drawing

AI summary

A system for provisioning credentials onto an electronic device is provided. The system may include a payment network subsystem, a service provider subsystem, and one or more user devices that can be used to perform mobile transactions at a merchant terminal. The user device may communicate with the service provider subsystem in order to obtained commerce credentials from the payment network subsystem. The user device may include a secure element and a corresponding trusted processor. The trusted processor may generate a random authorization number and inject that number into the secure element. Mobile payments should only be completed if the random authorization number on the secure element matches the random authorization number at the trusted processor. The trusted processor may be configured to efface the previous random authorization number and generate a new random authorization number when detecting a potential change in ownership at the user device.