Virtual Host Filtering for Secure Element Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure device platforms with virtual primary platforms face challenges in managing access and isolating operating system requirements across different secure elements, leading to complexity in certifications and security protocols, particularly in devices like NFC embedded Secure Elements and eUICC, which require separate certifications and testing.

Innovation Solution

The introduction of a filtering mechanism within the tamper-resistant element host domain that includes a plurality of virtual hosts associated with input/output interfaces, allowing only specific virtual hosts to interact with internal hosts embedded in specific applications, utilizing a whitelist based on firmware family identifiers to manage access and isolate interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single operating system is used to manage multiple secure elements with different requirements, then device complexity is reduced, but certification and security management becomes too complex to handle diverse requirements

Engineering Contradiction:
Improveoperating system management complexityVSAvoidcertification and security management capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent divides the host domain into multiple virtual host instances, each dedicated to specific secure elements or functions. This segmentation allows different secure elements to operate with their own customized operating systems and certification requirements without affecting others, thus resolving the contradiction between simplified device management and diverse certification needs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual hosts as intermediary components between external interfaces and internal secure elements. These virtual hosts act as mediators that manage communication and access control, enabling the system to handle multiple certification standards and security requirements through a unified architectural layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple virtual hosts are added to manage different secure elements, then adaptability to different requirements improves, but access management complexity increases

Engineering Contradiction:
Improvesecure element requirement isolationVSAvoidaccess management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts access management functions into dedicated virtual host instances that are separately managed. Each virtual host handles access control for its specific secure element independently, which simplifies the overall access management complexity by dividing it into manageable, isolated units rather than handling all access control centrally.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If virtual hosts are used to isolate services, then security and certification compliance improves, but impact on handset components increases

Engineering Contradiction:
Improvesecurity isolationVSAvoidhandset component interaction
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs virtual hosts to serve multiple functions: they provide service isolation for security, manage access control for different secure elements, and maintain compatibility with various handset components. This multi-functionality reduces the need for separate dedicated components for each function, thereby minimizing the overall impact on handset components while maintaining strong security isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3789902B1Secure device operating with a secure tamper-resistant platform, corresponding system and computer program product
Publication Date: 2023.07.19 STMICROELECTRONICS SRL
  • EP3789902B1 patent drawingFigure 1
  • EP3789902B1 patent drawingFigure 2
  • EP3789902B1 patent drawingFigure 3

AI summary

A secure device (10) operating with a secure tamper-resistant platform including a tamper-resistant hardware platform (11) and a virtual primary platform (12, 1P) operating with a low level operating system performing an abstraction of resources of the hardware platform (11), and a secondary platform (2P) with a high level operating system providing a further abstraction of resources to applications (14) in which respective internal hosts (23) are embedded, said secure device (10) including an internal host domain (23) including said internal hosts (23), said secure device (10) including a plurality of physical and/or logical input/output interfaces (25) through which externals hosts (311, 341) can access said internal hosts (23), said virtual primary platform (12, 1P) being configured to set interactions between said externals hosts (311, 341) and said internal hosts (23), wherein said internal host domain (23) includes a further set of virtual hosts (24) each configured to operate as a proxy between an input/output interface (25) and an application (14), each input/output interface (25) being configured to address only one among the virtual hosts (24).