Virtual Host Filtering for Secure Element Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure device platforms with virtual primary platforms face challenges in managing access and isolating operating system requirements across different secure elements, leading to complexity in certifications and security protocols, particularly in devices like NFC embedded Secure Elements and eUICC, which require separate certifications and testing.
Innovation Solution
The introduction of a filtering mechanism within the tamper-resistant element host domain that includes a plurality of virtual hosts associated with input/output interfaces, allowing only specific virtual hosts to interact with internal hosts embedded in specific applications, utilizing a whitelist based on firmware family identifiers to manage access and isolate interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single operating system is used to manage multiple secure elements with different requirements, then device complexity is reduced, but certification and security management becomes too complex to handle diverse requirements
Solution Approach 1:
The patent divides the host domain into multiple virtual host instances, each dedicated to specific secure elements or functions. This segmentation allows different secure elements to operate with their own customized operating systems and certification requirements without affecting others, thus resolving the contradiction between simplified device management and diverse certification needs.
Solution Approach 2:
The patent introduces virtual hosts as intermediary components between external interfaces and internal secure elements. These virtual hosts act as mediators that manage communication and access control, enabling the system to handle multiple certification standards and security requirements through a unified architectural layer.
2Adaptability or versatility
If multiple virtual hosts are added to manage different secure elements, then adaptability to different requirements improves, but access management complexity increases
Solution Approach 1:
The patent extracts access management functions into dedicated virtual host instances that are separately managed. Each virtual host handles access control for its specific secure element independently, which simplifies the overall access management complexity by dividing it into manageable, isolated units rather than handling all access control centrally.
3Reliability
If virtual hosts are used to isolate services, then security and certification compliance improves, but impact on handset components increases
Solution Approach 1:
The patent designs virtual hosts to serve multiple functions: they provide service isolation for security, manage access control for different secure elements, and maintain compatibility with various handset components. This multi-functionality reduces the need for separate dedicated components for each function, thereby minimizing the overall impact on handset components while maintaining strong security isolation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A secure device (10) operating with a secure tamper-resistant platform including a tamper-resistant hardware platform (11) and a virtual primary platform (12, 1P) operating with a low level operating system performing an abstraction of resources of the hardware platform (11), and a secondary platform (2P) with a high level operating system providing a further abstraction of resources to applications (14) in which respective internal hosts (23) are embedded, said secure device (10) including an internal host domain (23) including said internal hosts (23), said secure device (10) including a plurality of physical and/or logical input/output interfaces (25) through which externals hosts (311, 341) can access said internal hosts (23), said virtual primary platform (12, 1P) being configured to set interactions between said externals hosts (311, 341) and said internal hosts (23), wherein said internal host domain (23) includes a further set of virtual hosts (24) each configured to operate as a proxy between an input/output interface (25) and an application (14), each input/output interface (25) being configured to address only one among the virtual hosts (24).