Central TSM for Secure Element Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service providers face challenges in managing secure elements across various mobile devices and networks due to limitations in traditional Trusted Service Managers (TSMs), which lack the capability to process communications between a large variety of service providers, mobile network operators, devices, and security domains, leading to complex and laborious processes for installing and provisioning applications.
Innovation Solution
A central TSM system is introduced that manages instructions on behalf of service provider security domains, allowing for standardized requests to be processed efficiently, reducing the need for multiple intermediaries and minimizing processing time and errors by using a central security domain to interface with secure elements across different mobile networks and devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional TSMs are used to manage secure elements, then service providers can provision applications to mobile devices, but the process becomes complex and laborious due to the need to retrieve and verify extensive information from multiple sources
Solution Approach 1:
A central TSM is introduced as an intermediary system that consolidates information from multiple sources (secure elements, MNOs, service providers) into a single repository. This central TSM acts as a mediator between service providers and the distributed secure elements, eliminating the need for service providers to directly retrieve and verify information from multiple disparate sources, thereby simplifying the provisioning process while maintaining security and accuracy
Solution Approach 2:
The central TSM is designed as a universal system that can handle provisioning requests for multiple service providers, mobile network operators, and various types of secure elements through a standardized interface. This multi-functional approach allows a single system to serve diverse provisioning needs without requiring separate specialized systems for each provider or device type
2Reliability
If service providers retrieve information from multiple sources to securely install payment applets, then security is maintained, but extensive processing time and labor are required
Solution Approach 1:
The central TSM pre- consolidates and verifies all necessary information (secure element identifiers, MNO information, security domain information, credentials) into a centralized repository before provisioning requests are made. This preliminary organization of data means that when a service provider needs to provision an application, the required information is already prepared and available in a verified state, eliminating the need for real-time retrieval and verification from multiple sources during the actual provisioning process
3Adaptability or versatility
If traditional TSMs are used without centralized management, then service providers have direct control over their provisioning processes, but they face overwhelming complexity in adapting to numerous secure element form factors and configurations
Solution Approach 1:
The central TSM implements a universal provisioning framework that supports multiple secure element form factors (UICC, embedded secure elements, NFC enablers) and various security domain configurations through standardized interfaces and protocols. This allows service providers to work with a single unified system rather than needing to adapt their processes to each different secure element type, while the system maintains the necessary adaptability to handle diverse configurations
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems, methods, and computer program products are provided for performing content management operations. At least one memory stores data, and a central security domain manages instructions on behalf of one or more service provider security domains. The instructions are received, over a network, from a trusted service manager. The instructions are processed in at least one of the one or more determined service provider security domains, using the data stored in the at least one memory. The data includes one or more generic applications, each of which can be instantiated for one or more service providers.