Local Trusted Service Manager for Secure Element Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
GlobalPlatform compliant secure elements, such as those in mobile devices, face challenges in accessing the Issuer Security Domain without a connection to a Trusted Service Manager, particularly during device production when the issuer is unknown, and managing scripts are difficult to prepare in advance.
Innovation Solution
A method where a management script is generated locally within the secure element, encrypted, and transmitted through the host unit to the secure domain for decryption and execution, allowing secure management operations without external TSM communication, using corresponding key sets for encryption and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a management script is generated and transmitted through an external TSM, then the secure element can be managed, but the system requires continuous connection to external TSM which is not always available in mobile devices
Solution Approach 1:
The patent introduces a local TSM application as an intermediary component embedded within the mobile device that mediates between the secure element and the external TSM infrastructure. This local intermediary can generate and execute management scripts autonomously when external connection is unavailable, while still being able to communicate with external TSM when needed, thus resolving the contradiction between reliability and external dependency.
Solution Approach 2:
The local TSM application performs preliminary actions by pre-generating and storing management scripts locally within the mobile device before external TSM connection is needed. This allows the system to have management capabilities ready in advance, enabling autonomous operation during periods when external TSM is inaccessible, thereby improving reliability without requiring continuous external connection.
2Productivity
If management scripts are prepared in advance for secure element management, then setup operations can be performed efficiently, but the issuer cannot know the identifiers of secure elements it will need to manage upfront
Solution Approach 1:
The local TSM application implements dynamic script generation capabilities that adapt to the specific secure element identifiers encountered during device provisioning. Rather than relying on static pre-prepared scripts for unknown elements, the system can dynamically generate appropriate management scripts based on the actual secure element identifiers discovered during operation, thus maintaining both efficiency and flexibility.
Solution Approach 2:
The local TSM application enables the mobile device to serve itself by autonomously generating and executing management scripts for secure elements without requiring external TSM intervention for every operation. This self-service capability allows the device to handle unknown secure elements independently, improving adaptability while maintaining operational efficiency through automated local processing.
3Reliability
If the manufacturer passes issuer-specific seed values to secure elements during manufacturing, then keys can be generated for access, but the manufacturer cannot know which issuer will manage the device later
Solution Approach 1:
The local TSM application provides universal functionality by implementing a standardized interface and script generation mechanism that can work with secure elements from multiple different issuers. Rather than requiring issuer-specific customizations during manufacturing, the system uses a universal local TSM that can adapt to manage secure elements from any issuer, thus maintaining secure access capability while improving multi-issuer compatibility.
Data Source
AI summary
A method for managing a secure element which is embedded into a host unit. The described method comprises (a) transmitting a request for a management script from the host unit to a program element of the secure element, (b) at the program element, generating a management script in accordance with the request and encrypting the generated management script, (c) transmitting the encrypted management script from the program element to the host unit, (d) transmitting the encrypted management script from the host unit to a secure domain of the secure element, and (e) at the secure domain, decrypting and executing the management script.


