Secure Element Credential Pre-loading for NFC Personalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for personalizing secure elements in NFC-enabled mobile devices are complex and costly due to the involvement of multiple steps and actors, particularly in securing and linking credentials to specific users for financial applications and transactions.
Innovation Solution
A method where secure credentials are pre-loaded into secure elements before embedding them into mobile devices, allowing for a link to be created between the credentials and the user only upon service subscription, reducing the need for in-the-field provisioning and eliminating the TSM's participation in data exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If secure credentials are pre-loaded into secure elements before embedding into mobile devices, then the personalization process is simplified and costs are reduced, but the security risk increases if credentials are compromised during pre-provisioning
Solution Approach 1:
The patent applies preliminary action by pre-loading secure credentials into secure elements during manufacturing before the devices are deployed to users. This allows the personalization process to be simplified and performed automatically without requiring manual intervention or complex provisioning processes in the field. The credentials are pre-configured and ready for use, reducing the complexity of device personalization while maintaining security through controlled manufacturing environments.
2Reliability
If multiple actors including TSM are involved in the personalization process, then credential security is maintained through distributed trust, but the process becomes more complex and costly
Solution Approach 1:
The patent extracts the TSM (Trusted Service Manager) from the personalization process, eliminating the need for this intermediate actor. By directly pre-loading credentials into secure elements during manufacturing, the patent removes the complex multi-party coordination involving TSM, thereby simplifying the personalization process while maintaining security through the secure manufacturing environment and direct credential injection into the device.
3Reliability
If secure credentials are tied to a specific user during provisioning, then user-specific security is ensured, but the provisioning process requires extensive in-the-field operations increasing cost and complexity
Solution Approach 1:
The patent applies preliminary action by pre-configuring secure credentials with user identification data during the manufacturing process rather than performing user-specific provisioning in the field. This allows devices to be pre-personalized with the necessary security credentials before reaching the user, significantly improving provisioning efficiency while ensuring user-specific security is maintained through the pre-configured credentials that are automatically activated when the device is associated with a user account.
Data Source
AI summary
According to an aspect of the invention, a method for personalizing a secure element for a mobile device is conceived, wherein an application is stored in the secure element and wherein the application is pre-provisioned by loading secure credentials into the application without tying said secure credentials to a specific user of the secure element.


