UICC Secure Element for Mobile Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data loss prevention approaches for mobile devices are inefficient and resource-intensive, failing to effectively secure personally identifiable data from unauthorized access while preserving processor and memory capacity, especially on battery-powered devices optimized for energy efficiency.
Innovation Solution
The use of cryptographic services from a universal integrated circuit card (UICC) connected to the mobile device to protect personally identifiable data stored in a Personal Data Store (PDS) through secure access control and encryption, ensuring that only authorized applications can access the data by using a shared secret key and biometric authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional data loss prevention approaches are used to secure personally identifiable data, then data security is improved, but processor capacity and memory capacity are significantly reduced, and energy consumption increases
Solution Approach 1:
The patent extracts the cryptographic operations from the main processor and relocates them to a dedicated secure element (UICC or SE). This separation allows the secure element to handle encryption, decryption, and key management functions independently, thereby preserving processor and memory capacity for other applications while maintaining strong data security through specialized hardware acceleration.
Solution Approach 2:
The patent introduces a secure element (UICC or SE) as an intermediary component between the main processor and the personally identifiable data stored in the personal data store. This intermediary handles all cryptographic operations and access control, enabling secure data protection without requiring the main processor to perform resource-intensive encryption tasks, thus avoiding capacity reduction.
2Reliability
If conventional data loss prevention approaches are used to secure personally identifiable data, then data security is improved, but energy consumption increases significantly on battery-powered devices
Solution Approach 1:
The patent extracts energy-intensive cryptographic operations from the main processor and relocates them to a dedicated secure element with its own processing unit. This secure element performs encryption, decryption, and key management locally without requiring continuous power consumption from the main device battery, thereby maintaining data security while preserving energy efficiency for other device functions.
Solution Approach 2:
The secure element operates as a self-contained unit with its own processing capabilities and memory. It can perform cryptographic operations independently using its internal resources, reducing the energy burden on the main device battery. The secure element manages its own key storage, encryption/decryption processes, and access control without requiring continuous energy support from the host device.
3Reliability
If strong encryption keys are used to protect personally identifiable data, then data security is improved, but the complexity of access control and key management increases
Solution Approach 1:
The patent extracts key management functions including generation, storage, and distribution of encryption keys from the main device software system and relocates them to the secure element. The secure element generates and stores cryptographic keys in its protected memory, managing access control through hardware-enforced mechanisms. This extraction simplifies the main device's software complexity while maintaining strong security through dedicated hardware key management.
Solution Approach 2:
The secure element serves as an intermediary that centralizes all key management and access control operations. It provides a simplified interface for authorized applications to access encrypted data without exposing the complexity of key management to the main device software. The secure element handles authentication, key derivation, and encryption operations, reducing the complexity burden on the host device while maintaining robust security.
Data Source
AI summary
Methods and apparatus for securing access to an encrypted personal data store on a mobile device. In some embodiments, a universal integrated circuit card (UICC) processor receives, from a mobile device processor of a mobile device having an encrypted Personal Data Store (PDS), a PDS access request associated with a mobile application, then determines that access control rules are stored in at least one access control rules database and transmits to the mobile device processor, the access control rules governing access to the data in the encrypted PDS. The process also includes the UICC processor receiving a request for a symmetric shared secret and transmitting the symmetric shared secret to the mobile device processor for use in accessing the PID of the user stored in the encrypted PDS in accordance with the access control rules.


