Virtual Secure Element for IoT Cost Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices often face challenges in configuring hardware secure elements due to cost sensitivity, necessitating a cost-effective solution for secure data processing.

Innovation Solution

A method utilizing software modules on terminals and servers to simulate a secure element, enabling encryption, decryption, and security calculations, thereby reducing the need for hardware secure elements and lowering device costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware secure element is configured in an IoT device, then data security is improved, but device cost increases

Engineering Contradiction:
Improvedata securityVSAvoiddevice cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a virtual secure element that replicates the security functions of a hardware secure element through software implementation. The virtual secure element module simulates cryptographic operations, key management, and security processing that would normally require dedicated hardware, thereby providing equivalent security functionality without the hardware cost overhead

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/hardware-based secure element with a software-based virtual secure element. Instead of relying on physical hardware security modules, the system uses software modules running on general-purpose processors to perform all security-critical functions including encryption, decryption, and cryptographic calculations

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of manufacture

If a virtual secure element is used instead of hardware, then device cost is reduced, but security reliability may be compromised

Engineering Contradiction:
Improvedevice costVSAvoidsecurity reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a communication interface module that acts as an intermediary between the virtual secure element and external systems. This module manages secure data transmission, implements authentication protocols, and ensures that cryptographic operations are performed securely even in the virtual environment, thereby maintaining security reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent divides the security system into distinct functional modules: a virtual secure element module for cryptographic operations, a communication interface module for secure data exchange, and integration interfaces for connecting with existing system components. This modular architecture allows each component to be optimized for its specific function while maintaining overall security

Inventive Principle:
Principle #1Segmentation

3Device complexity

If software modules are used to simulate secure element functions, then device complexity is reduced, but processing speed may decrease

Engineering Contradiction:
Improvedevice complexityVSAvoidprocessing speed
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The patent implements a universal virtual secure element that can perform multiple cryptographic functions including encryption, decryption, key generation, and authentication through software. This multi-functional approach eliminates the need for separate hardware modules for different security operations, reducing overall device complexity while providing comprehensive security capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3879783B1Data security processing method and terminal thereof
Publication Date: 2023.05.17 ADVANCED NEW TECHNOLOGIES CO LTD
  • EP3879783B1 patent drawingFigure 1~2
  • EP3879783B1 patent drawingFigure 3~4
  • EP3879783B1 patent drawingFigure 5

AI summary

Provided in this application is a method for securely processing data, including: acquiring, by a first security unit, security data from a second security unit of a security server; and performing, by a secure element (SE) application of the first security unit, security processing on a trusted application (TA) of a trusted execution environment (TEE) using the security data. The method for securely processing data, and a terminal and a server thereof provided in this application are simple to implements and when combined with device network capabilities, may provide safety guaranteeing capabilities that conform to the SE while overcoming drawbacks of difficult integration and high costs of the hardware SE, thereby reducing costs of an IoT device.