Virtual Terminal Authorization for Secure Element Cryptographic Operations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data transfer systems require dedicated hardware devices separate from multipurpose devices, compromising data security and privacy, and lack effective authorization controls for secure element operations.

Innovation Solution

A virtual terminal hosted by a secure element on a multipurpose device, integrated into mobile devices, uses an authorizer application to authorize cryptographic operations, ensuring data security through token-based validation and encryption, eliminating the need for separate hardware and enhancing authorization controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated hardware devices are used for data transfer, then data security is improved, but device complexity and portability are worsened

Engineering Contradiction:
Improvedata securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the secure element that hosts the virtual terminal directly into the multipurpose user device, combining previously separate hardware components into a unified integrated system. This integration maintains security functionality while eliminating the need for separate dedicated hardware devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure element within the multipurpose device is designed to host multiple virtual terminals for different data transfer purposes, making a single device component serve multiple security functions. This multi-functionality replaces the need for separate dedicated hardware for each data transfer operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If authorization controls are added to secure element operations, then data security is improved, but operational complexity is worsened

Engineering Contradiction:
Improvedata securityVSAvoidauthorization control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorizer application serves as an intermediary component that manages authorization controls between the virtual terminal and cryptographic applet. It receives authorization requests, validates them against stored criteria, and returns authorization decisions, thereby simplifying the overall authorization process while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authorization system implements feedback mechanisms where the authorizer application continuously monitors operation status and adjusts authorization decisions based on compliance with authorization criteria. This feedback loop ensures security while automating the control process to reduce operational complexity.

Inventive Principle:
Principle #23Feedback

3Reliability

If token-based authorization is implemented, then unauthorized access is reduced, but processing time is worsened

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthorization processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing authorization criteria and storing them in the authorizer application before actual data transfer operations occur. This advance preparation enables faster real-time authorization decisions without compromising security, as the framework is already in place.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260010613A1Authorizer for operations of a virtual terminal
Publication Date: 2026.01.08 APPLE INC
  • US20260010613A1 patent drawing
  • US20260010613A1 patent drawing
  • US20260010613A1 patent drawing

AI summary

Techniques for using an authorizer in a virtual terminal on a multipurpose device to authorize operations of a cryptographic applet in a secure element associated with the multipurpose device are described herein. These techniques include receiving an authorization token and setting authorization criteria for the operation of the cryptographic applet based on the authorization token.