Procedure for configuring a virtual security element

The method automates the selection of virtual security elements in mobile devices by grouping applications by area and using local position, addressing the inefficiency of manual application selection in existing systems.

DE102014000896B4Active Publication Date: 2025-10-09GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102014000896
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2014-01-23
Publication Date
2025-10-09
Estimated Expiration
2034-01-23

AI Technical Summary

Technical Problem

Existing mobile communication devices with virtual security elements require manual selection of applications from different virtual security elements, which is time-consuming and cumbersome, especially when using unknown or rarely used applications.

Method used

A method for configuring virtual security elements in mobile devices that automatically selects the appropriate element based on the device's local position, using a communication device's processor and memory to group applications by area of application and forward commands to the selected virtual security element.

Benefits of technology

Automatically selects the appropriate virtual security element based on location, eliminating the need for manual selection and ensuring seamless application usage without user intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for configuring a virtual security element of a mobile communication device, whereby a communication connection exists between the communication device and a terminal, wherein the virtual security element is stored in a physical security element of the communication device, wherein the physical security element comprises at least one processor, at least one memory and at least one data processing interface, where all applications belonging to an application area are grouped together in a group for the application area, wherein a first unit (4) located on the communication device, upon receipt of a command (2) from the terminal for selecting an application, first checks the command (2) and determines a group of an associated application area for the command (2) and then, upon successful check and determination, forwards the command to a second unit (10) located on the communication device, which forwards the command to the virtual security element within the specific group of an associated application area for the command in order to execute an application (16) stored in the virtual security element, whereby the virtual security element is selected depending on the local position of the communication device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention describes a method for configuring a virtual security element of a mobile communication device.

[0002] Mobile communication devices, e.g. a smartphone, which contain at least one physical security element, e.g. a SIM card, are known from the prior art. Physical security elements in which at least one virtual security element is stored are also known. Each virtual security element usually stores at least one application. Before a user or a terminal, e.g. a bank terminal, can access the application of a virtual security element, a suitable virtual security element must be explicitly selected. This has the disadvantage that if different applications with different functions are stored in different virtual security elements, then the user or the terminal, for example, has to make a selection each time they use the application as to which application should be selected and used. This is time-consuming and cumbersome.Furthermore, calling up unknown or relatively rarely used applications causes problems.

[0003] US 2013 / 0339166 A1 discloses card applets linked to an electronic wallet that are enabled and disabled based on user-defined rules. Based on the rules and a device status, the card emulation status and the states of the card applets are changed to enable or disable the completion of transactions. The transactions take place between a computing device and a reader, such as a point-of-sale terminal. In some embodiments, a user designates multiple card applets as fast cards that can complete a transaction via near-field communication (NFC) without user input at the time of the transaction.

[0004] US 2012 / 0265685 A1 discloses a system for automatically selecting an access credential from a plurality of access credentials on a portable communications device based on its geolocation and a user preference for use in an electronic wallet transaction. The system includes a geolocation device that detects the geolocation of the portable communications device; a location identification unit that is activated by a predetermined user input and that uses the geolocation to determine a retailer where the portable communications device is most likely located; means for storing the preferences corresponding to the access credentials; and means for automatically determining which of the plurality of access credentials should be used for the electronic wallet transaction based on the preferences.

[0005] Based on the prior art, the object of the invention is to find a solution which avoids the described disadvantage.

[0006] The object of the invention is solved by the independent claim. Advantageous embodiments are described in the dependent claims. To solve the problem, the invention discloses a method for configuring a virtual security element of a mobile communication device, whereby a communication connection exists between the communication device and a terminal, wherein the virtual security element is stored in a physical security element of the communication device, wherein the physical security element comprises at least one processor, at least one memory and at least one data processing interface, where all applications belonging to an application area are grouped together in a group for the application area, wherein a first unit located on the communication device, upon receiving a command from the terminal to select an application, first checks the command and determines a group of an associated application area for the command and then, upon successful check and determination, forwards the command to a second unit located on the communication device that forwards the command to the virtual security element within the specific group of an associated application area for the command to execute an application stored in the virtual security element, which is characterized by the fact that the virtual security element is selected depending on the local position of the communication device.

[0007] A further advantageous embodiment is that a user of the communication device additionally defines his or her own rules for selecting the virtual security element.

[0008] A further advantageous embodiment is that the communication device uses its own application to determine the local position.

[0009] A further advantageous embodiment is that all available location sources are used to determine the local position of the communication device.

[0010] A further advantageous embodiment is that a code of a mobile communication network and / or a GPS signal and / or data of a LAN communication network are / is used as the location source.

[0011] A further advantageous embodiment is that the first unit first supplements the command with the specific group of an associated application area for the command and then forwards the supplemented command to the second unit.

[0012] A further advantageous embodiment is that the first unit, after initializing the physical security element of the communication device, checks all data received from the terminal with regard to a command from the terminal.

[0013] A further advantageous embodiment is that after successful checking and determination by the first unit of the command received from the terminal with regard to a group of an associated application area, all subsequent commands received by the terminal until the next deinitialization of the physical security element are extended with the group of an associated application area and forwarded to the second unit.

[0014] A further advantageous embodiment is that the application area is determined by determining an identifier of the command.

[0015] A further advantageous embodiment is that an application identifier is used as the identifier of the command.

[0016] A further advantageous embodiment is that at least one application is stored in a virtual security element.

[0017] A further advantageous embodiment is that a user within a group determines which virtual security element is preferred.

[0018] A further advantageous embodiment is that if the first unit cannot determine a group of an associated application area for the command, a separate group is used to which all commands are assigned for which no group of an associated application area can be determined.

[0019] A further advantageous embodiment is that the first unit and / or the second unit are implemented at least partially in the physical security element of the communication device. For example, the first unit can be implemented in the communication device and the second unit in the secure element.

[0020] A further advantageous embodiment is that a contactless and / or a contact-based communication connection is used as the communication connection.

[0021] A further advantageous embodiment is that a SIM card is used as the physical security element.

[0022] A further advantageous embodiment is that a smartphone is used as the mobile communication device.

[0023] In the following, a basic embodiment of the invention is described with reference to the attached figure. Fig. 1 shows the functional environment in which the invention is used.

[0024] A terminal, e.g. a bank terminal, which is not shown here for reasons of clarity, sends a command 2 to a mobile communications device not shown, e.g. a smartphone. In the communications device, the command 2 is forwarded to a physical security element not shown here, e.g. a SIM card. The SIM card contains a first unit 4. The first unit 4 checks the command 2, e.g. using a table or an assignment structure 6, which contains an assignment of possible commands to a group of an associated application area. The command 2 can also be checked by comparing it with an application identifier (AID) stored in table 6. Possible areas of application include use as a credit card, local transport card, ID card, customer loyalty card. At least one application can exist per group.The application is preferably stored in a virtual security element. If the first unit 4 finds an assignment between the command 2 and a group from, for example, the table or the assignment structure 6, it supplements the command 2 with the found group to form an expanded command 8. The first unit 4 sends the command 8 to a second unit 10. The second unit 10 checks a table 12 to determine which preferred virtual security element should be used for the group of command 8. Typically, a user selects which virtual security element should be preferred for an application area. The second unit 10 evaluates the command 8, in particular its membership in a group, removes additions, e.g.the group, of the first unit 4, so that a command 14 generated by the second unit 10 is equal to the command 2 and forwards the command 14 to the preferred virtual security element 16 so that an application stored in the preferred virtual security element 16 executes the command 14.

[0025] The invention enables the virtual security element to be selected depending on the local position of the communication device. In addition, a user of the communication device can define their own rules for selecting the virtual security element. This means that the user does not have to select which local transport card they want to use, for example when traveling from one city to another. The selection of the local transport card or a corresponding application in a virtual security element is automatically determined based on the user's location. Alternatively, the user can determine which credit card is to be used, for example depending on their location, e.g. at home or abroad, without having to manually select the desired or suitable credit card before each use. For example, a first credit card should only be used in the user's home country and a second credit card only abroad.Another example is if the user uses a separate access card for different buildings, ideally from the same access card manufacturer, which therefore use the same commands but different keys, the local position of the communication device can be used to automatically determine which access card should be used, without the user having to worry about the selection.

[0026] The communication device uses its own application to determine the local position. This is, for example, the so-called wallet app, which also handles the selection of a suitable virtual security element. Alternatively, other and / or multiple apps can be used for this purpose.

[0027] It is advisable to use all available location sources to determine the local position of the communication device in order to determine the most accurate local position possible.

[0028] For example, a code from a mobile communications network and / or a GPS signal and / or data from a LAN communications network can be used as the location source. Furthermore, any other suitable signal can be used.

[0029] With the present invention, the application area requested by a terminal and the associated preferred virtual security element 16 are automatically called up, and the application is executed in the preferred virtual security element 16 without the user having to worry about the selection. Furthermore, the user does not have to worry about selecting or changing the virtual security element.

Claims

[1] Method for configuring a virtual security element of a mobile communication device, whereby a communication connection exists between the communication device and a terminal, wherein the virtual security element is stored in a physical security element of the communication device, wherein the physical security element comprises at least one processor, at least one memory and at least one data processing interface, where all applications belonging to an application area are grouped together in a group for the application area, wherein a first unit (4) located on the communication device, upon receipt of a command (2) from the terminal for selecting an application, first checks the command (2) and determines a group of an associated application area for the command (2) and then, upon successful check and determination, forwards the command to a second unit (10) located on the communication device, which forwards the command to the virtual security element within the specific group of an associated application area for the command in order to execute an application (16) stored in the virtual security element, whereby the virtual security element is selected depending on the local position of the communication device. [2] Method according to claim 1, characterized by that a user of the communication device additionally defines his own rules for selecting the virtual security element. [3] Method according to claim 1 or 2, characterized by that the communication device uses its own application to determine the local position. [4] Method according to one of claims 3, characterized by that all available location sources are used to determine the local position of the communication device. [5] Method according to claim 4, characterized by that a code of a mobile communication network and / or a GPS signal and / or data of a LAN communication network are / will be used as the location source.

Citation Information

Patent Citations

  • System and Method for Physical-World Based Dynamic Contactless Data Emulation in a Portable Communication Device

    US20120265685A1

  • User-configurable activation of card applets

    US20130339166A1