Secure Element Decoupling via Key Escrow Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current NFC systems have a tight coupling between the secure element and the Trusted Service Manager (TSM), limiting users to only one TSM and thus restricting access to services from multiple secure service providers, as the TSM is typically chosen by the device manufacturer based on their business relationships.
Innovation Solution
Implementing a key escrow service that manages cryptographic keys for users and secure service providers, allowing users to select from multiple TSMs through a service provider selector module, and enabling secure key transmission and revocation to facilitate access to chosen service providers, thereby decoupling the secure element from a single TSM.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single TSM is tightly coupled to the secure element, then security is maintained through dedicated key management, but user choice and service provider diversity are limited
Solution Approach 1:
The patent segments the key management function by separating the cryptographic key from the single TSM. The key is divided into multiple shares distributed to different TSMs, allowing the secure element to interact with multiple service providers while maintaining security through threshold cryptography principles.
Solution Approach 2:
The secure element is designed with universal compatibility to work with multiple TSMs rather than being dedicated to a single provider. This multi-functionality is achieved through the key sharing mechanism that enables any authorized TSM to access and provision the secure element, thereby providing users with choice among different service providers.
2Ease of manufacture
If the device manufacturer selects a single TSM based on business relationships, then initial provisioning is simplified, but users are restricted from accessing services from other providers
Solution Approach 1:
The system performs preliminary action by pre-distributing key shares to multiple potential TSMs during manufacturing, rather than designating a single TSM. This preliminary distribution of cryptographic credentials enables users to later select from multiple authorized service providers without requiring complex re-provisioning procedures.
Solution Approach 2:
The patent introduces an intermediary key sharing mechanism that mediates between the secure element and multiple TSMs. This intermediary layer of key management allows the secure element to maintain security while enabling access from multiple service providers, resolving the conflict between simplified initial provisioning and ongoing service provider flexibility.
3Adaptability or versatility
If cryptographic keys are shared with multiple TSMs, then user choice and service diversity are enabled, but security management complexity increases
Solution Approach 1:
The patent extracts the complexity of key management from the secure element and the user device by implementing a centralized key distribution and management system. The complex cryptographic operations and key sharing logic are removed from the embedded secure element and handled by external key management infrastructure, thereby reducing device complexity while enabling multi-TSM access.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods are described herein for enabling users to select from available secure service providers (each having a Trusted Service Manager ("TSM")) for provisioning applications and services on a secure element installed on a device of the user. The device includes a service provider selector ("SPS") module that provides a user interface for selecting the secure service provider. In one embodiment, the SPS communicates with a key escrow service that maintains cryptographic keys for the secure element and distributes the keys to the user selected secure service provider. The key escrow service also revokes the keys from deselected secure service providers. In another embodiment, the SPS communicates with a central TSM that provisions applications and service on behalf of the user selected secure service provider. The central TSM serves as a proxy between the secure service providers and the secure element.