UICC Secure Element for Mobile Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data loss prevention approaches for mobile devices are inefficient and resource-intensive, failing to effectively secure personally identifiable data from unauthorized access while preserving processor and memory capacity, especially on battery-powered devices optimized for energy efficiency.

Innovation Solution

The use of cryptographic services from a universal integrated circuit card (UICC) connected to the mobile device to protect personally identifiable data stored in a Personal Data Store (PDS) through secure access control and encryption, ensuring that only authorized applications can access the data by using a shared secret key and biometric authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional data loss prevention approaches are used to secure personally identifiable data, then data security is improved, but processor capacity and memory capacity are significantly reduced, and energy consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessor capacity and memory capacity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic operations from the main processor and relocates them to a dedicated secure element (UICC or SE). This separation allows the secure element to handle encryption, decryption, and key management functions independently, thereby preserving processor and memory capacity for other applications while maintaining strong data security through specialized hardware acceleration.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure element (UICC or SE) as an intermediary component between the main processor and the personally identifiable data stored in the personal data store. This intermediary handles all cryptographic operations and access control, enabling secure data protection without requiring the main processor to perform resource-intensive encryption tasks, thus avoiding capacity reduction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional data loss prevention approaches are used to secure personally identifiable data, then data security is improved, but energy consumption increases significantly on battery-powered devices

Engineering Contradiction:
Improvedata securityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts energy-intensive cryptographic operations from the main processor and relocates them to a dedicated secure element with its own processing unit. This secure element performs encryption, decryption, and key management locally without requiring continuous power consumption from the main device battery, thereby maintaining data security while preserving energy efficiency for other device functions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure element operates as a self-contained unit with its own processing capabilities and memory. It can perform cryptographic operations independently using its internal resources, reducing the energy burden on the main device battery. The secure element manages its own key storage, encryption/decryption processes, and access control without requiring continuous energy support from the host device.

Inventive Principle:
Principle #25Self-service

3Reliability

If strong encryption keys are used to protect personally identifiable data, then data security is improved, but the complexity of access control and key management increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess control and key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts key management functions including generation, storage, and distribution of encryption keys from the main device software system and relocates them to the secure element. The secure element generates and stores cryptographic keys in its protected memory, managing access control through hardware-enforced mechanisms. This extraction simplifies the main device's software complexity while maintaining strong security through dedicated hardware key management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure element serves as an intermediary that centralizes all key management and access control operations. It provides a simplified interface for authorized applications to access encrypted data without exposing the complexity of key management to the main device software. The secure element handles authentication, key derivation, and encryption operations, reducing the complexity burden on the host device while maintaining robust security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11405782B2Methods and systems for securing and utilizing a personal data store on a mobile device
Publication Date: 2022.08.02 MASTERCARD INT INC
  • US11405782B2 patent drawing
  • US11405782B2 patent drawing
  • US11405782B2 patent drawing

AI summary

Methods and apparatus for securing access to an encrypted personal data store on a mobile device. In some embodiments, a universal integrated circuit card (UICC) processor receives, from a mobile device processor of a mobile device having an encrypted Personal Data Store (PDS), a PDS access request associated with a mobile application, then determines that access control rules are stored in at least one access control rules database and transmits to the mobile device processor, the access control rules governing access to the data in the encrypted PDS. The process also includes the UICC processor receiving a request for a symmetric shared secret and transmitting the symmetric shared secret to the mobile device processor for use in accessing the PID of the user stored in the encrypted PDS in accordance with the access control rules.