Secure Element Credential Pre-loading for NFC Personalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for personalizing secure elements in NFC-enabled mobile devices are complex and costly due to the involvement of multiple steps and actors, particularly in securing and linking credentials to specific users for financial applications and transactions.

Innovation Solution

A method where secure credentials are pre-loaded into secure elements before embedding them into mobile devices, allowing for a link to be created between the credentials and the user only upon service subscription, reducing the need for in-the-field provisioning and eliminating the TSM's participation in data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If secure credentials are pre-loaded into secure elements before embedding into mobile devices, then the personalization process is simplified and costs are reduced, but the security risk increases if credentials are compromised during pre-provisioning

Engineering Contradiction:
Improvepersonalization process complexityVSAvoidcredential security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-loading secure credentials into secure elements during manufacturing before the devices are deployed to users. This allows the personalization process to be simplified and performed automatically without requiring manual intervention or complex provisioning processes in the field. The credentials are pre-configured and ready for use, reducing the complexity of device personalization while maintaining security through controlled manufacturing environments.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple actors including TSM are involved in the personalization process, then credential security is maintained through distributed trust, but the process becomes more complex and costly

Engineering Contradiction:
Improvecredential securityVSAvoidpersonalization process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the TSM (Trusted Service Manager) from the personalization process, eliminating the need for this intermediate actor. By directly pre-loading credentials into secure elements during manufacturing, the patent removes the complex multi-party coordination involving TSM, thereby simplifying the personalization process while maintaining security through the secure manufacturing environment and direct credential injection into the device.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If secure credentials are tied to a specific user during provisioning, then user-specific security is ensured, but the provisioning process requires extensive in-the-field operations increasing cost and complexity

Engineering Contradiction:
Improveuser-specific securityVSAvoidprovisioning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-configuring secure credentials with user identification data during the manufacturing process rather than performing user-specific provisioning in the field. This allows devices to be pre-personalized with the necessary security credentials before reaching the user, significantly improving provisioning efficiency while ensuring user-specific security is maintained through the pre-configured credentials that are automatically activated when the device is associated with a user account.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9749303B2Method for personalizing a secure element, method for enabling a service, secure element and computer program product
Publication Date: 2017.08.29 NXP BV
  • US9749303B2 patent drawing
  • US9749303B2 patent drawing
  • US9749303B2 patent drawing

AI summary

According to an aspect of the invention, a method for personalizing a secure element for a mobile device is conceived, wherein an application is stored in the secure element and wherein the application is pre-provisioned by loading secure credentials into the application without tying said secure credentials to a specific user of the secure element.