Web Server Bypass for Secure Element Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices face challenges in securely storing and transmitting sensitive information, such as credit card details, due to the risk of theft or fraud during online transactions, as existing security measures are not sufficient to prevent unauthorized access.
Innovation Solution
A mobile access terminal is equipped with a secure element, a web server residing in a secure storage area, a near field communications system, an over-the-air proxy, and a trusted security zone, which provides exclusive access to the web browser, ensuring that sensitive information is stored and transmitted securely by restricting access to only the web browser and blocking outside IP addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive information is stored in a secure element with restricted access, then security against unauthorized access is improved, but accessibility for legitimate transactions may be limited
Solution Approach 1:
The patent introduces a web server as an intermediary component that resides within the secure element and acts as a controlled mediator between the secure stored data and external web browsers. This web server receives requests from web browsers, retrieves necessary information from the secure element, and transmits it back through secure channels. This intermediary approach maintains the security boundaries of the secure element while enabling legitimate access for transactions, thus resolving the contradiction between security and accessibility.
2Reliability
If a web server is embedded within the secure element, then secure transmission of sensitive data is improved, but device complexity increases
Solution Approach 1:
The patent merges the web server functionality directly into the secure element, combining what would traditionally be separate components (secure storage and web serving capabilities) into a single integrated unit. This consolidation ensures that the web server operates within the security boundaries of the secure element, eliminating the need for separate secure communication infrastructure and reducing overall system complexity while maintaining secure transmission capabilities.
3Reliability
If exclusive access to the web server is provided to the web browser, then security against unauthorized access is improved, but functionality for other applications is reduced
Solution Approach 1:
The patent applies local quality by providing exclusive access rights specifically to the web browser component while maintaining security. The web server within the secure element is configured to recognize and authenticate web browser requests through specific protocols and communication channels, granting access only to legitimate browser-based transactions. This localized access control ensures that other applications or unauthorized entities cannot access the secure data, while the web browser maintains full functionality for secure transactions.
Data Source
AI summary
A mobile access terminal providing access to data in a secure element of the mobile access terminal is provided. The mobile access terminal comprises the secure element; a web browser; a near field communications system; an over-the-air proxy; an application programming interface layer; and a web server residing on a secure storage area of the mobile access terminal, wherein the web browser is provided with exclusive access to the web server.


