Secure Element Backup and Restoration via Trusted Service Manager

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for mobile payment services lack a technique for safely backing up and restoring secure information stored in Secure Elements (SE) when terminals or SEs are replaced or updated, leading to inconvenience and potential data loss.

Innovation Solution

A method and system for identifying secure information, generating backup data, transmitting it securely to a Trusted Service Manager (TSM) server, and restoring it to the original or another terminal, utilizing secure channels and encryption to manage and integrate card information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure information is stored in SE for mobile payment service, then security is improved, but data loss occurs when terminal or SE is replaced

Engineering Contradiction:
ImprovesecurityVSAvoiddata loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs backup of secure information from the SE to the TSM server before terminal or SE replacement occurs. This preliminary action ensures that even if the original SE is lost or replaced, the secure information can be restored from the backup stored on the TSM server, thus preventing data loss while maintaining security through encrypted transmission and storage.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If backup data is transmitted to TSM server, then data safety is improved, but transmission security may be compromised

Engineering Contradiction:
Improvedata safetyVSAvoidtransmission security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a secure transmission environment by establishing a trusted communication channel between the SE and TSM server. This 'inert atmosphere' protects the backup data during transmission from external security threats such as eavesdropping or tampering, allowing safe data transfer while maintaining transmission security through encryption and authentication mechanisms.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Ease of repair

If secure information is backed up to external server, then data recovery is improved, but security risk increases

Engineering Contradiction:
Improvedata recoveryVSAvoidsecurity risk
Core Design Contradiction:
Ease of repairVSObject-affected harmful factors

Solution Approach 1:

The patent introduces the TSM server as a trusted intermediary between the SE and external storage. The TSM server acts as a secure mediator that receives, stores, and manages backup data with appropriate security controls. This intermediary approach enables data recovery functionality while mitigating security risks by using a dedicated trusted service manager rather than direct external storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If multiple card information are integrated in SE, then functionality is improved, but management complexity increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the management complexity of multiple card information from the SE by backing up and storing card data on the TSM server. The SE retains only essential secure elements, while the TSM server manages the complete card information portfolio. This extraction reduces management complexity at the SE level while maintaining full functionality through centralized card information management.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10037248B2Method and system for managing secure element
Publication Date: 2018.07.31 TELINK
  • US10037248B2 patent drawing
  • US10037248B2 patent drawing
  • US10037248B2 patent drawing

AI summary

A method for managing a secure element (SE) is disclosed. The method for managing the SE includes identifying secure information stored in the SE, sending a command to request to set suspension of use of a means of payment included in the secure information stored in the SE to a secure server, generating backup data using at least part of the identified secure information, transmitting the backup data from the SE to the secure server through a secure channel set between the secure server and the SE and storing the backup data, transmitting a restoration command on the secure information to the secure server, and restoring the backup data of the secure server to the SE or another SE.