Virtual Terminal Authorizer for Secure Element Operations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data transfer systems require dedicated hardware devices separate from multipurpose devices, compromising data security and privacy, and lack effective authorization controls for secure element operations.
Innovation Solution
A virtual terminal hosted by a secure element on a multipurpose device, integrated with an authorizer application, enables authorization controls and encryption, eliminating the need for separate hardware and ensuring secure data transfers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated hardware devices are used for data transfer, then data security is improved, but device complexity and portability are worsened
Solution Approach 1:
The patent merges the secure element that previously required dedicated hardware into a virtual terminal implementation within multipurpose devices. The secure element is virtualized and integrated into the device's existing hardware platform, allowing secure data transfer operations without requiring separate dedicated hardware devices. This combining approach maintains security functionality while eliminating the need for additional standalone hardware.
Solution Approach 2:
The virtual terminal enables the secure element to function within multipurpose devices that already exist in users' possession. Instead of requiring dedicated single-function hardware devices, the secure element is implemented as a virtual component that can operate within general-purpose smartphones, tablets, or computers. This multi-functionality approach allows the same device to serve both general computing purposes and secure data transfer purposes.
2Reliability
If authorization controls are added to secure element operations, then data security is improved, but operational complexity is worsened
Solution Approach 1:
The virtual terminal implementation includes an authorizer application that automatically manages authorization for secure element operations. The system performs self-service authorization by having the authorizer application interact with the virtual terminal to obtain necessary permissions and credentials. This automated self-service approach reduces the need for manual authorization management and complex external control mechanisms, thereby maintaining security while reducing operational complexity.
3Reliability
If separate hardware devices are used, then security isolation is improved, but ease of operation is worsened
Solution Approach 1:
The patent combines the secure element functionality with the user's existing multipurpose device, eliminating the need to operate separate dedicated hardware devices. Users can perform secure data transfer operations directly from their smartphones, tablets, or computers without needing to physically handle or switch between multiple devices. This merging maintains security isolation through virtualization while dramatically improving ease of operation by using familiar devices.
4Adaptability or versatility
If virtual terminal is implemented, then device versatility is improved, but security risk is worsened
Solution Approach 1:
The virtual terminal implementation introduces an authorizer application as an intermediary layer between the virtual terminal and the secure element operations. This intermediary performs security checks, validates credentials, and manages authorization tokens before allowing operations to proceed. The authorizer acts as a mediator that enables versatile device compatibility while maintaining security by filtering and controlling access requests, thereby reducing the risk of unauthorized access despite the virtualized environment.
Data Source
AI summary
Techniques for using an authorizer in a virtual terminal on a multipurpose device to authorize operations of a cryptographic applet in a secure element associated with the multipurpose device are described herein. These techniques include receiving an authorization token and setting authorization criteria for the operation of the cryptographic applet based on the authorization token.


