Delegated Secure Element Provisioning via Trusted Service Manager Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile terminal provisioning systems face challenges in securely and efficiently managing the provisioning of financial information, such as credit cards, over-the-air, due to limitations in secure communication protocols and liability management.
Innovation Solution
A system comprising a first trusted service manager associated with a credit card, a second trusted service manager associated with a wireless service provider, and a mobile device with a secure element, where the second trusted service manager initiates the transfer of personalization information for the credit card through an over-the-air client, establishing a secure wireless connection for provisioning actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the second trusted service manager (wireless service provider) directly provisions credit card information to the mobile device, then provisioning efficiency is improved, but security and liability management deteriorate
Solution Approach 1:
The first trusted service manager acts as an intermediary between the second trusted service manager and the mobile device. The second TSM sends provisioning requests to the first TSM, which then executes the actual provisioning actions on the mobile device. This intermediary structure allows the wireless service provider to maintain control and efficiency while delegating sensitive financial provisioning to a specialized trusted service manager that assumes liability responsibility.
2Reliability
If multiple trusted service managers are involved in the provisioning process, then security and liability management are improved, but system complexity increases
Solution Approach 1:
The provisioning system is segmented into distinct functional roles: the second trusted service manager handles wireless service provisioning and device control, while the first trusted service manager handles financial card provisioning and security. This segmentation allows each component to specialize in its domain, improving overall security and liability management while maintaining manageable system complexity through clear role separation.
3Ease of operation
If over-the-air provisioning is used for credit cards, then ease of operation is improved, but secure communication requirements increase system complexity
Solution Approach 1:
The mobile device includes an over-the-air client that automatically handles secure communication protocols and provisioning processes. The client manages secure connections, authentication, and data transfer without requiring user intervention for complex security configurations. This self-service approach maintains ease of operation for users while the system automatically handles the cryptographic and protocol complexity in the background.
Data Source
AI summary
A system for provisioning a secure element on a mobile device is provided. The system comprises a first trusted service manager associated with a credit card, a second trusted service manager associated with a wireless service provider, and a mobile device. The mobile device has a secure element to hold the credit card and an over-the-air client to communicate wirelessly with the first trusted service manager and the second trusted service manager. When the second trusted service manager receives a message from the first trusted service manager to provision a personalization information for the credit card to the mobile device, the second trusted service manager transmits to the over-the-air client a message to initiate transfer of the personalization information for the credit card.


