Secure Element Partitioning for Roaming NFC Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users of Near-Field Communication (NFC) mobile devices cannot access local services while roaming due to the lack of security access by the local Mobile Network Operator (MNO) and Trusted Service Manager (TSM) to the Secure Element (SE) on the device.
Innovation Solution
Creating separate encrypted partitions on the SIM's Secure Element, with one Trusted Service Manager generating and delegating encryption keys to another TSM for access, allowing secure installation and management of local applications during roaming.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the Secure Element (SE) on the NFC mobile device is protected by cryptographic keys shared only between the user's home MNO and the TSM, then security is maintained, but users cannot access local NFC-enabled services while roaming in other countries
Solution Approach 1:
The Secure Element (SE) is divided into multiple partitions: a home partition protected by home MNO cryptographic keys, and guest partitions that can be accessed by visiting MNOs. This segmentation allows different access control policies for different service scenarios while maintaining overall security.
Solution Approach 2:
A Trusted Service Manager (TSM) acts as an intermediary between the home MNO, visiting MNOs, and the Secure Element. The TSM manages cryptographic keys and controls access to guest partitions, enabling secure roaming services without compromising the security model.
2Adaptability or versatility
If cryptographic keys are shared between multiple MNOs and TSMs to enable roaming access, then service accessibility improves, but security risks increase
Solution Approach 1:
Different cryptographic key pairs are assigned to different partitions within the Secure Element. The home partition uses home MNO keys, while guest partitions use separate key pairs that can be selectively delegated to visiting MNOs, minimizing the security exposure of the home MNO's master keys.
Solution Approach 2:
Guest partitions and their associated cryptographic keys are pre-configured in the Secure Element before roaming occurs. When a user roams to a visiting MNO, the TSM can quickly delegate access to the appropriate pre-configured guest partition without needing to establish new security relationships on the fly.
3Adaptability or versatility
If guest partitions are added to the Secure Element for roaming access, then local service accessibility improves, but device complexity increases
Solution Approach 1:
The Trusted Service Manager (TSM) automatically manages the complexity of guest partition configuration, key generation, and access control. The system self-configures security relationships when roaming agreements are established, eliminating the need for manual intervention and reducing the perceived complexity for end users.
Data Source
AI summary
A method of accessing local applications when roaming on a NFC mobile device may include creating a first partition and a second partition on a secure element (SE) of a subscriber identification module (SIM) of a near field communication (NFC) enabled device. The home TSM separates the first partition and the second partition by public key encryption. The home TSM generates cryptographic keys in response to a request by a roaming TSM for access to the second partition of the SIM. Following the exchange of security keys, the home TSM delegates to the roaming TSM access to the second partition of the SIM.


