Web Server Bypass for Secure Element Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices face challenges in securely storing and transmitting sensitive information, such as credit card details, due to the risk of theft or fraud during online transactions, as existing security measures are not sufficient to prevent unauthorized access.

Innovation Solution

A mobile access terminal is equipped with a secure element, a web server residing in a secure storage area, a near field communications system, an over-the-air proxy, and a trusted security zone, which provides exclusive access to the web browser, ensuring that sensitive information is stored and transmitted securely by restricting access to only the web browser and blocking outside IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensitive information is stored in a secure element with restricted access, then security against unauthorized access is improved, but accessibility for legitimate transactions may be limited

Engineering Contradiction:
ImprovesecurityVSAvoidaccessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a web server as an intermediary component that resides within the secure element and acts as a controlled mediator between the secure stored data and external web browsers. This web server receives requests from web browsers, retrieves necessary information from the secure element, and transmits it back through secure channels. This intermediary approach maintains the security boundaries of the secure element while enabling legitimate access for transactions, thus resolving the contradiction between security and accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a web server is embedded within the secure element, then secure transmission of sensitive data is improved, but device complexity increases

Engineering Contradiction:
Improvesecure transmissionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the web server functionality directly into the secure element, combining what would traditionally be separate components (secure storage and web serving capabilities) into a single integrated unit. This consolidation ensures that the web server operates within the security boundaries of the secure element, eliminating the need for separate secure communication infrastructure and reducing overall system complexity while maintaining secure transmission capabilities.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If exclusive access to the web server is provided to the web browser, then security against unauthorized access is improved, but functionality for other applications is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidfunctionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by providing exclusive access rights specifically to the web browser component while maintaining security. The web server within the secure element is configured to recognize and authenticate web browser requests through specific protocols and communication channels, granting access only to legitimate browser-based transactions. This localized access control ensures that other applications or unauthorized entities cannot access the secure data, while the web browser maintains full functionality for secure transactions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9906958B2Web server bypass of backend process on near field communications and secure element chips
Publication Date: 2018.02.27 T MOBILE INNOVATIONS LLC
  • US9906958B2 patent drawing
  • US9906958B2 patent drawing
  • US9906958B2 patent drawing

AI summary

A mobile access terminal providing access to data in a secure element of the mobile access terminal is provided. The mobile access terminal comprises the secure element; a web browser; a near field communications system; an over-the-air proxy; an application programming interface layer; and a web server residing on a secure storage area of the mobile access terminal, wherein the web browser is provided with exclusive access to the web server.