Secure Element Service Installation via Token-Based Proxy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile payment systems are inefficient due to a sequential process for provisioning services in secure elements, lacking feedback on installation success and relying on unstable protocols, which increases security concerns and user inconvenience.

Innovation Solution

A method and system that integrates the order and installation processes for secure-element-related services using a token-based authorization model, where a proxy application manages the installation within a communication device, leveraging a mobile IP connection for improved stability and control, allowing for user-centric app-based provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a sequential process is used for provisioning services in a secure element, then the installation can be completed, but the process lacks feedback on installation success and relies on unstable protocols

Engineering Contradiction:
Improveinstallation stabilityVSAvoidinstallation feedback
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the system receives and processes installation status information from the secure element. The server entity sends a query to retrieve installation status, and based on the received status (success or failure), the system can take appropriate actions. This resolves the contradiction by providing the missing feedback loop in the sequential provisioning process, enabling reliable detection of installation outcomes while maintaining the sequential installation approach.

Inventive Principle:
Principle #23Feedback

2Reliability

If multiple server entities communicate sequentially during account provisioning, then authorization can be verified, but the process becomes inefficient with unnecessary communication steps

Engineering Contradiction:
Improveauthorization verificationVSAvoidprovisioning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the authorization verification process into a single streamlined flow. The server entity that receives the initial service request also handles the authorization verification by querying the secure element for installation status. This consolidation eliminates unnecessary communication steps between multiple server entities while maintaining reliable authorization verification, directly addressing the efficiency problem in the conventional sequential process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure element performs self-verification by storing and providing installation status information when queried. Instead of requiring multiple server entities to communicate and verify authorization through complex interactions, the secure element autonomously maintains and provides its installation status, enabling the server to independently verify authorization and service provisioning state, thereby improving overall process efficiency.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If conventional provisioning protocols are used, then service installation can be performed, but security concerns increase due to lack of control and feedback

Engineering Contradiction:
Improveservice provisioning capabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent implements comprehensive feedback mechanisms at multiple stages: the server entity queries the secure element for installation status, receives confirmation of successful installation, and can verify the authenticity of the provisioned service. This feedback loop enables real-time monitoring and control of the provisioning process, allowing the system to detect and respond to security issues immediately rather than relying on post-provisioning verification, thereby reducing security risks while maintaining ease of service provisioning.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3104635B1Method for an improved installation of a secure-element-related service application in a secure element being located in a communication device, system and telecommunications network for an improved installation of a secure-element-related service application in a secure element being located in a communication device, program comprising a computer readable program code, and computer program product
Publication Date: 2020.02.12 DEUTSCHE TELEKOM AG
  • EP3104635B1 patent drawingFigure 1~2

AI summary

The invention relates to a method for an improved installation of a secure-element-related service application in a secure element being located in a communication device, wherein the secure-element-related service application, installed within the secure element, allows a first server entity of a service provider, together with a UE-related application installed on the communication device, to provide a service to the subscriber of the telecommunications network, wherein a secure element issuer corresponds to the secure element, wherein the method comprises the following steps: -- in a first step, an initial request is transmitted by the UE-related service application of the communication device towards the first server entity to request installation of the secure-element-related service application in the secure element, the initial request being transmitted by means of a request message, -- in a second step, subsequent to the first step, the request to install the secure-element-related service application is transmitted, by the first server entity, to the second server entity, the second server entity generating the token information related to the request to install the secure-element-related service application in the secure element of the communication device, and the second server entity transmitting the token information to the first server entity related to the request to install the secure-element-related service application in the secure element, -- in a third step, subsequent to the second step, a token information is transmitted, by the first server entity to the UE-related service application of the communication device, -- in a fourth step, subsequent to the third step, an access and/or installation request, related to the secure-element-related service application, is transmitted, together with the token information, by the UE-related service application of the communication device to a proxy application of the secure element issuer, the proxy application being able to access the secure element and/or to install secure-element-related applications on the secure element, wherein the proxy application is able to interact with the secure element of the communication device and is installed in the communication device as a link between, on the one hand, a second server entity of the secure element issuer, and, on the other hand, the secure element of the communication device, the second server entity being a server entity related to the secure element issuer, -- in a fifth step, subsequent to the fourth step, a communication link is established between the proxy application and the second server entity such that the token information, together with a SEID information (Secure Element Identifier information) of the communication device is transmitted to the second server entity in order to be validated by the second server entity.