Secure Element Service Installation via Token-Based Proxy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile payment systems are inefficient due to a sequential process for provisioning services in secure elements, lacking feedback on installation success and relying on unstable protocols, which increases security concerns and user inconvenience.
Innovation Solution
A method and system that integrates the order and installation processes for secure-element-related services using a token-based authorization model, where a proxy application manages the installation within a communication device, leveraging a mobile IP connection for improved stability and control, allowing for user-centric app-based provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a sequential process is used for provisioning services in a secure element, then the installation can be completed, but the process lacks feedback on installation success and relies on unstable protocols
Solution Approach 1:
The patent implements a feedback mechanism where the system receives and processes installation status information from the secure element. The server entity sends a query to retrieve installation status, and based on the received status (success or failure), the system can take appropriate actions. This resolves the contradiction by providing the missing feedback loop in the sequential provisioning process, enabling reliable detection of installation outcomes while maintaining the sequential installation approach.
2Reliability
If multiple server entities communicate sequentially during account provisioning, then authorization can be verified, but the process becomes inefficient with unnecessary communication steps
Solution Approach 1:
The patent merges the authorization verification process into a single streamlined flow. The server entity that receives the initial service request also handles the authorization verification by querying the secure element for installation status. This consolidation eliminates unnecessary communication steps between multiple server entities while maintaining reliable authorization verification, directly addressing the efficiency problem in the conventional sequential process.
Solution Approach 2:
The secure element performs self-verification by storing and providing installation status information when queried. Instead of requiring multiple server entities to communicate and verify authorization through complex interactions, the secure element autonomously maintains and provides its installation status, enabling the server to independently verify authorization and service provisioning state, thereby improving overall process efficiency.
3Ease of manufacture
If conventional provisioning protocols are used, then service installation can be performed, but security concerns increase due to lack of control and feedback
Solution Approach 1:
The patent implements comprehensive feedback mechanisms at multiple stages: the server entity queries the secure element for installation status, receives confirmation of successful installation, and can verify the authenticity of the provisioned service. This feedback loop enables real-time monitoring and control of the provisioning process, allowing the system to detect and respond to security issues immediately rather than relying on post-provisioning verification, thereby reducing security risks while maintaining ease of service provisioning.
Data Source
Figure 1~2
AI summary
The invention relates to a method for an improved installation of a secure-element-related service application in a secure element being located in a communication device, wherein the secure-element-related service application, installed within the secure element, allows a first server entity of a service provider, together with a UE-related application installed on the communication device, to provide a service to the subscriber of the telecommunications network, wherein a secure element issuer corresponds to the secure element, wherein the method comprises the following steps: -- in a first step, an initial request is transmitted by the UE-related service application of the communication device towards the first server entity to request installation of the secure-element-related service application in the secure element, the initial request being transmitted by means of a request message, -- in a second step, subsequent to the first step, the request to install the secure-element-related service application is transmitted, by the first server entity, to the second server entity, the second server entity generating the token information related to the request to install the secure-element-related service application in the secure element of the communication device, and the second server entity transmitting the token information to the first server entity related to the request to install the secure-element-related service application in the secure element, -- in a third step, subsequent to the second step, a token information is transmitted, by the first server entity to the UE-related service application of the communication device, -- in a fourth step, subsequent to the third step, an access and/or installation request, related to the secure-element-related service application, is transmitted, together with the token information, by the UE-related service application of the communication device to a proxy application of the secure element issuer, the proxy application being able to access the secure element and/or to install secure-element-related applications on the secure element, wherein the proxy application is able to interact with the secure element of the communication device and is installed in the communication device as a link between, on the one hand, a second server entity of the secure element issuer, and, on the other hand, the secure element of the communication device, the second server entity being a server entity related to the secure element issuer, -- in a fifth step, subsequent to the fourth step, a communication link is established between the proxy application and the second server entity such that the token information, together with a SEID information (Secure Element Identifier information) of the communication device is transmitted to the second server entity in order to be validated by the second server entity.