Secure element
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
top
A secure element (SE) is a secure operating system (OS) in a tamper-resistant processor chip or secure component. It can protect assets (root of trust, sensitive data, keys, certificates, applications) against high-level software and hardware attacks. Applications that process this sensitive data on an SE are isolated and so operate within a controlled environment not affected by software (including possible malware) found elsewhere on the OS.cite-ref-1[1]cite-ref-2[2]
SEs exist in various form factors, as devices such as smart cards, UICCs, or smart microSD cards,cite-ref-5[5] or embedded, or integrated, as parts of larger devices.cite-ref-6[6]cite-ref-7[7] SEs are an evolution of the chips in earlier smart cards, which have been adapted to suit the needs of numerous use cases, such as smartphones, tablets, set-top boxes, wearables, connected cars, and other internet of things (IoT) devices. The technology is widely used by technology firms such as Oracle,cite-ref-oracle-8-0[8] Applecite-ref-9[9] and Samsung.cite-ref-10[10]
SEs provide secure isolation, storage and processing for applications (called applets) they host while being isolated from the external world (e.g. rich OS and application processor when embedded in a smartphone) and from other applications running on the SE. Java Card and MULTOS are the most deployed standardized multi-application operating systems currently used to develop applications running on SEs.cite-ref-oracle-8-1[8]
Since 1999, GlobalPlatform has been the body responsible for standardizing secure element technologies to support a dynamic model of application management in a multi-actor model. GlobalPlatform also runs Functional and Security Certification programmes for secure elements, and hosts a list of Functional Certified and Security Certified products. GlobalPlatform technology is also embedded in other standards such as ETSI SCP (now SET) since release 7.cite-ref-11[11] A Common Criteria Secure Element Protection Profile has been released targeting EAL4+ level with ALC_DVS.2 and AVA_VAN.5 extension to standardize the security features of a secure element across markets.cite-ref-12[12]
References
cite-note-11. ↑ citerefbertrandBertrand, Cambou. "Enhancing Secure Elements - Technology and Architecture" (PDF). Northern Arizona University.
cite-note-33. ↑ "Security IC Platform Protection Profile with Augmentation Packages" (PDF). Common Criteria.
cite-note-44. ↑ "Worldwide Market of Secure Elements Confirms its Resiliency in 2021". Eurosmart.
cite-note-66. ↑ citerefmehta2022Mehta, Tushar (April 4, 2022). "What is Integrated SIM (iSIM)? How is it better than eSIM?". Digital Trends.
cite-note-77. ↑ citerefpage2021Page, Carly (October 5, 2021). "Yubico's new hardware key features a fingerprint reader for passwordless logins". TechCrunch.
cite-note-1212. ↑ "GlobalPlatform Technology Secure Element Protection Profile Version 1.0" (PDF). Common Criteria.