Delegated Secure Element Provisioning via Trusted Service Manager Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile terminal provisioning systems face challenges in securely and efficiently managing the provisioning of financial information, such as credit cards, over-the-air, due to limitations in secure communication protocols and liability management.

Innovation Solution

A system comprising a first trusted service manager associated with a credit card, a second trusted service manager associated with a wireless service provider, and a mobile device with a secure element, where the second trusted service manager initiates the transfer of personalization information for the credit card through an over-the-air client, establishing a secure wireless connection for provisioning actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the second trusted service manager (wireless service provider) directly provisions credit card information to the mobile device, then provisioning efficiency is improved, but security and liability management deteriorate

Engineering Contradiction:
Improveprovisioning efficiencyVSAvoidsecurity and liability management
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The first trusted service manager acts as an intermediary between the second trusted service manager and the mobile device. The second TSM sends provisioning requests to the first TSM, which then executes the actual provisioning actions on the mobile device. This intermediary structure allows the wireless service provider to maintain control and efficiency while delegating sensitive financial provisioning to a specialized trusted service manager that assumes liability responsibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple trusted service managers are involved in the provisioning process, then security and liability management are improved, but system complexity increases

Engineering Contradiction:
Improvesecurity and liability managementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The provisioning system is segmented into distinct functional roles: the second trusted service manager handles wireless service provisioning and device control, while the first trusted service manager handles financial card provisioning and security. This segmentation allows each component to specialize in its domain, improving overall security and liability management while maintaining manageable system complexity through clear role separation.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If over-the-air provisioning is used for credit cards, then ease of operation is improved, but secure communication requirements increase system complexity

Engineering Contradiction:
Improveease of operationVSAvoidsecure communication requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The mobile device includes an over-the-air client that automatically handles secure communication protocols and provisioning processes. The client manages secure connections, authentication, and data transfer without requiring user intervention for complex security configurations. This self-service approach maintains ease of operation for users while the system automatically handles the cryptographic and protocol complexity in the background.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8060449B1Partially delegated over-the-air provisioning of a secure element
Publication Date: 2011.11.15 T MOBILE INNOVATIONS LLC
  • US8060449B1 patent drawing
  • US8060449B1 patent drawing
  • US8060449B1 patent drawing

AI summary

A system for provisioning a secure element on a mobile device is provided. The system comprises a first trusted service manager associated with a credit card, a second trusted service manager associated with a wireless service provider, and a mobile device. The mobile device has a secure element to hold the credit card and an over-the-air client to communicate wirelessly with the first trusted service manager and the second trusted service manager. When the second trusted service manager receives a message from the first trusted service manager to provision a personalization information for the credit card to the mobile device, the second trusted service manager transmits to the over-the-air client a message to initiate transfer of the personalization information for the credit card.