Secure Element Policy Management via Single OTA Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional remote secure element policy management in multi-partner scenarios is costly and time-consuming due to the need for multiple over-the-air (OTA) operations, which burdens users and service providers with resource-intensive and complex processes.

Innovation Solution

Implementing a system that uses public key infrastructure (PKI) and a third-party trusted service manager to establish confidential OTA keys, allowing for the creation of security domains and profile downloads with a single OTA transfer, thereby reducing the number of required OTA sessions and simplifying remote management operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple over-the-air (OTA) operations are used for remote secure element management, then security and provisioning can be achieved, but user wait time and operational cost increase significantly

Engineering Contradiction:
Improvesecure element provisioningVSAvoiduser wait time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-establishes a trusted relationship between the service provider TSM and the secure element during manufacturing or initial provisioning. This preliminary action stores authentication credentials and authorization tokens in the secure element beforehand, enabling subsequent remote management operations to proceed without requiring multiple interactive OTA sessions. The pre-configured trust anchor allows the SE to automatically validate service provider credentials, eliminating time-consuming back-and-forth authentication exchanges.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple over-the-air (OTA) operations are performed for security domain creation, then proper authentication and authorization can be ensured, but bandwidth consumption and operational costs increase

Engineering Contradiction:
Improveauthentication and authorizationVSAvoidbandwidth use
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent combines multiple authentication and authorization steps into a single streamlined OTA operation. By merging the verification of service provider credentials, validation of security domain creation requests, and authorization of provisioning actions into one consolidated transaction, the system maintains robust security checks while dramatically reducing the total bandwidth consumed. The merged operation leverages pre-stored trust relationships to perform what would traditionally require separate authentication handshakes, certificate validations, and authorization confirmations in a single efficient exchange.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If conventional remote management procedures are used with multiple OTA sessions, then secure element policies can be managed, but device complexity and operational complexity increase

Engineering Contradiction:
Improveremote management capabilityVSAvoidoperational complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The secure element is equipped with self-service capabilities that enable it to autonomously validate service provider credentials and execute provisioning operations without requiring complex multi-step coordination. The SE contains embedded logic to automatically verify authentication tokens, validate security domain creation requests, and manage its own access control policies based on pre-configured authorization rules. This self-service approach simplifies the overall system architecture by eliminating the need for complex external coordination protocols while maintaining full remote management versatility.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9832025B2Remote secure element policy management
Publication Date: 2017.11.28 VERIZON PATENT & LICENSING INC
  • US9832025B2 patent drawing
  • US9832025B2 patent drawing
  • US9832025B2 patent drawing

AI summary

A policy server that is associated with a secure element owner receives a request, from a service provider, to provision access, by an application, to the secure element. The policy server creates, in response to the request, a policy ticket, for the service provider, that defines privileges for the service provider to create a security domain or a new profile within the secure element. The policy server provides, to a service provider trusted service manager (TSM), the policy ticket and a signed certificate, the signed certificate corresponding to a root certificate that is inserted into a Controlling Authority Security Domain (CASD) portion of the secure element prior to receiving the request. When the CASD receives the policy ticket and signed certificate from the service provider TSM, the CASD validates based on the root certificate and provisions access to the secure element based on information in the policy ticket.