Secure Element Decoupling via Key Escrow Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current NFC systems have a tight coupling between the secure element and the Trusted Service Manager (TSM), limiting users to only one TSM and thus restricting access to services from multiple secure service providers, as the TSM is typically chosen by the device manufacturer based on their business relationships.

Innovation Solution

Implementing a key escrow service that manages cryptographic keys for users and secure service providers, allowing users to select from multiple TSMs through a service provider selector module, and enabling secure key transmission and revocation to facilitate access to chosen service providers, thereby decoupling the secure element from a single TSM.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single TSM is tightly coupled to the secure element, then security is maintained through dedicated key management, but user choice and service provider diversity are limited

Engineering Contradiction:
ImprovesecurityVSAvoiduser choice
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the key management function by separating the cryptographic key from the single TSM. The key is divided into multiple shares distributed to different TSMs, allowing the secure element to interact with multiple service providers while maintaining security through threshold cryptography principles.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element is designed with universal compatibility to work with multiple TSMs rather than being dedicated to a single provider. This multi-functionality is achieved through the key sharing mechanism that enables any authorized TSM to access and provision the secure element, thereby providing users with choice among different service providers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If the device manufacturer selects a single TSM based on business relationships, then initial provisioning is simplified, but users are restricted from accessing services from other providers

Engineering Contradiction:
Improveinitial provisioningVSAvoidservice provider access
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by pre-distributing key shares to multiple potential TSMs during manufacturing, rather than designating a single TSM. This preliminary distribution of cryptographic credentials enables users to later select from multiple authorized service providers without requiring complex re-provisioning procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary key sharing mechanism that mediates between the secure element and multiple TSMs. This intermediary layer of key management allows the secure element to maintain security while enabling access from multiple service providers, resolving the conflict between simplified initial provisioning and ongoing service provider flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If cryptographic keys are shared with multiple TSMs, then user choice and service diversity are enabled, but security management complexity increases

Engineering Contradiction:
Improveservice provider selectionVSAvoidkey management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the complexity of key management from the secure element and the user device by implementing a centralized key distribution and management system. The complex cryptographic operations and key sharing logic are removed from the embedded secure element and handled by external key management infrastructure, thereby reducing device complexity while enabling multi-TSM access.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3171289B1Enabling users to select between secure service providers using a central trusted service manager
Publication Date: 2018.08.08 GOOGLE LLC
  • EP3171289B1 patent drawingFigure 1
  • EP3171289B1 patent drawingFigure 2
  • EP3171289B1 patent drawingFigure 3

AI summary

Systems and methods are described herein for enabling users to select from available secure service providers (each having a Trusted Service Manager ("TSM")) for provisioning applications and services on a secure element installed on a device of the user. The device includes a service provider selector ("SPS") module that provides a user interface for selecting the secure service provider. In one embodiment, the SPS communicates with a key escrow service that maintains cryptographic keys for the secure element and distributes the keys to the user selected secure service provider. The key escrow service also revokes the keys from deselected secure service providers. In another embodiment, the SPS communicates with a central TSM that provisions applications and service on behalf of the user selected secure service provider. The central TSM serves as a proxy between the secure service providers and the secure element.