Virtual Secure Element for Token Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The secure storage of sensitive information on communication devices is challenging without relying on secure elements, as it complicates the provisioning process and increases manufacturing costs, while also posing security risks if not properly protected.

Innovation Solution

The use of tokens, which are substitutes for sensitive information, are encrypted and stored on the device, with the ability to be decrypted at runtime and deleted upon inactivity, and renewed upon reboot or power cycle, reducing the risk of unauthorized use by being dynamically changed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure element is used to store sensitive information, then security is improved, but manufacturing cost and device complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a software-based copy of secure element functionality through a virtual secure element implemented in the operating system. This virtual implementation replicates the security functions of hardware secure elements without requiring additional physical components, thereby maintaining security while reducing manufacturing costs and device complexity

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/hardware-based secure element with a software-based implementation. By substituting the physical secure element hardware with a virtual secure element running on the device's existing processor and memory, the system eliminates the need for additional secure hardware components while maintaining security through software-based encryption and key management

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a secure element is used to store sensitive information, then security is improved, but provisioning complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual secure element replicates secure element functionality through software, allowing provisioning to be performed via standard software distribution channels rather than requiring complex hardware provisioning infrastructure. This enables over-the-air provisioning and simplifies the overall provisioning process while maintaining security

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual secure element is implemented as part of the operating system, allowing it to serve multiple functions including secure storage, authentication, and encryption. This multi-functionality eliminates the need for separate provisioning processes for different security functions, thereby reducing provisioning complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If tokens are stored statically in memory, then access speed is improved, but security is worsened due to higher compromise risk

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements dynamic token generation where tokens are created on-demand rather than being stored statically. When a token is needed, it is generated from encrypted seed values in volatile memory, used immediately, and then discarded. This dynamic approach maintains fast access speeds while significantly reducing security risks associated with static token storage

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses disposable tokens that are generated temporarily from encrypted seed values stored in volatile memory. Each token is used once or for a limited time and then discarded, preventing long-term exposure risks. The encrypted seed values serve as reusable templates that can generate multiple disposable tokens without being compromised

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS10904002B2Token security on a communication device
Publication Date: 2021.01.26 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US10904002B2 patent drawing
  • US10904002B2 patent drawing
  • US10904002B2 patent drawing

AI summary

Techniques for enhancing the security of storing sensitive information or a token on a communication device may include sending a request for the sensitive information or token. The communication device may receive a session key encrypted with a hash value derived from user authentication data that authenticates the user of the communication device, and the sensitive information or token encrypted with the session key. The session key encrypted with the hash value, and the sensitive information or token encrypted with the session key can be stored in a memory of the communication device.