Key Escrow Service for Secure Element TSM Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current NFC systems have a tight coupling between the secure element and the Trusted Service Manager (TSM), limiting users to a single TSM chosen by the device manufacturer, which restricts access to services from multiple payment providers.

Innovation Solution

Implementing a key escrow service that manages cryptographic keys for secure elements, allowing users to select from multiple secure service providers through a service provider selector module, and enabling secure key transmission to the chosen provider, while revoking keys from previous providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single TSM is tightly coupled with the secure element, then security is maintained through dedicated key management, but user choice and service diversity are limited

Engineering Contradiction:
ImprovesecurityVSAvoiduser choice
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the key management function by separating the secure element (which stores keys) from the TSM (which manages services). The secure element contains a key escrow service that can independently manage key access, allowing multiple TSMs to be authorized without compromising security. This segmentation enables users to choose different TSMs while maintaining dedicated key protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key escrow service acts as an intermediary between the secure element and multiple TSMs. It controls key access by authenticating TSMs and granting permission to access the secure element. This intermediary mechanism allows flexible TSM selection while maintaining security through centralized key access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If device manufacturer selects the TSM, then initial provisioning is simplified, but end user autonomy and service selection freedom are reduced

Engineering Contradiction:
Improveinitial provisioningVSAvoiduser autonomy
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The system performs preliminary action by pre-configuring the secure element with a key escrow service and multiple authorized TSM identifiers during manufacturing. This initial setup simplifies production while enabling users to autonomously select their preferred TSM later through the key escrow service, which already has the necessary authorization information stored.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cryptographic keys are shared with only one TSM, then secure communication channel is established, but access to multiple service providers is blocked

Engineering Contradiction:
Improvesecure communicationVSAvoidservice provider access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key escrow service provides universal access control by maintaining a list of authorized TSMs and their corresponding cryptographic keys. Instead of binding the secure element to a single TSM, the key escrow service can authenticate multiple TSMs and establish secure communication channels with each, enabling access to multiple service providers while maintaining cryptographic security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3200425B1Enabling users to select between secure service providers using a key escrow service
Publication Date: 2025.01.08 GOOGLE LLC
  • EP3200425B1 patent drawingFigure 1
  • EP3200425B1 patent drawingFigure 2
  • EP3200425B1 patent drawingFigure 3

AI summary

Systems and methods are described herein for enabling users to select from available secure service providers (each having a Trusted Service Manager ("TSM")) for provisioning applications and services on a secure element installed on a device of the user. A proposed method for providing secure services to a computing network device (110) comprising a secure element (111) in this regard comprises: maintaining, by a computer (150), at least one cryptographic key (120) for the secure element (111), the at least one cryptographic key (120) operable to provide secure access to the secure element (111) via a secure communication channel; receiving from the network device (110), by the computer (150), a selection of a secure service provider (160A, 160B) from available secure service providers (160A, 160B) each having a trusted service manager, TSM (170A, 170B); and transmitting, by the computer (150), the at least one cryptographic key to the selected TSM (160, 170) of the selected service provider (160A, 160B) in response to receiving the request to select the service provider (160A, 160B).