Key Escrow Service for Secure Element TSM Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current NFC systems have a tight coupling between the secure element and the Trusted Service Manager (TSM), limiting users to a single TSM chosen by the device manufacturer, which restricts access to services from multiple payment providers.
Innovation Solution
Implementing a key escrow service that manages cryptographic keys for secure elements, allowing users to select from multiple secure service providers through a service provider selector module, and enabling secure key transmission to the chosen provider, while revoking keys from previous providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single TSM is tightly coupled with the secure element, then security is maintained through dedicated key management, but user choice and service diversity are limited
Solution Approach 1:
The system segments the key management function by separating the secure element (which stores keys) from the TSM (which manages services). The secure element contains a key escrow service that can independently manage key access, allowing multiple TSMs to be authorized without compromising security. This segmentation enables users to choose different TSMs while maintaining dedicated key protection.
Solution Approach 2:
The key escrow service acts as an intermediary between the secure element and multiple TSMs. It controls key access by authenticating TSMs and granting permission to access the secure element. This intermediary mechanism allows flexible TSM selection while maintaining security through centralized key access control.
2Ease of manufacture
If device manufacturer selects the TSM, then initial provisioning is simplified, but end user autonomy and service selection freedom are reduced
Solution Approach 1:
The system performs preliminary action by pre-configuring the secure element with a key escrow service and multiple authorized TSM identifiers during manufacturing. This initial setup simplifies production while enabling users to autonomously select their preferred TSM later through the key escrow service, which already has the necessary authorization information stored.
3Reliability
If cryptographic keys are shared with only one TSM, then secure communication channel is established, but access to multiple service providers is blocked
Solution Approach 1:
The key escrow service provides universal access control by maintaining a list of authorized TSMs and their corresponding cryptographic keys. Instead of binding the secure element to a single TSM, the key escrow service can authenticate multiple TSMs and establish secure communication channels with each, enabling access to multiple service providers while maintaining cryptographic security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods are described herein for enabling users to select from available secure service providers (each having a Trusted Service Manager ("TSM")) for provisioning applications and services on a secure element installed on a device of the user. A proposed method for providing secure services to a computing network device (110) comprising a secure element (111) in this regard comprises: maintaining, by a computer (150), at least one cryptographic key (120) for the secure element (111), the at least one cryptographic key (120) operable to provide secure access to the secure element (111) via a secure communication channel; receiving from the network device (110), by the computer (150), a selection of a secure service provider (160A, 160B) from available secure service providers (160A, 160B) each having a trusted service manager, TSM (170A, 170B); and transmitting, by the computer (150), the at least one cryptographic key to the selected TSM (160, 170) of the selected service provider (160A, 160B) in response to receiving the request to select the service provider (160A, 160B).