Secure Element Script Deployment via Direct Service Provider Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile payment systems, modifying stored value payment applets on secure elements of electronic devices is inefficient due to the need for multiple exchanges between secure elements and service provider servers, often requiring proxying through mobile payment system servers, which can increase latency and is not feasible for global deployment across multiple data centers.
Innovation Solution
A mobile payment system server acts as a global gateway, allowing authorized service provider servers to communicate directly with secure elements for transactions, reducing the need for proxying through mobile payment system servers and enabling direct script deployment, thus minimizing latency and facilitating global deployment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If service provider servers communicate through mobile payment system servers to modify payment applets on secure elements, then security and centralized control are improved, but transaction latency and system complexity increase
Solution Approach 1:
The mobile payment system server acts as an intermediary that establishes initial security credentials and authorizes service provider servers to communicate directly with secure elements. This mediator approach maintains centralized security control while enabling direct subsequent communications to reduce latency.
Solution Approach 2:
The communication process is segmented into two phases: initial secure credential establishment through the mobile payment system server, followed by direct script deployment communications between service provider servers and secure elements. This segmentation maintains security while reducing operational latency.
2Reliability
If multiple exchanges are required between secure elements and service provider servers for modifying payment applets, then security verification is improved, but productivity and efficiency deteriorate
Solution Approach 1:
Security credentials and authorization tokens are established in advance through preliminary communication between the mobile payment system server, service provider servers, and secure elements. This preliminary action enables subsequent modifications to proceed with fewer exchanges, improving efficiency while maintaining security verification.
3Device complexity
If proxying through mobile payment system servers is required for script deployment, then centralized control is improved, but device complexity and deployment flexibility worsen
Solution Approach 1:
The system dynamically switches from centralized proxying to direct communication based on authorization status. Once a service provider server is authorized by the mobile payment system server, it can directly deploy scripts to secure elements without further proxying, enabling flexible global deployment while maintaining initial centralized control.
Data Source
AI summary
A device facilitating script deployment through service provider servers includes at least one processor configured to receive, from a service provider, a request to perform a transaction directly with a device secure element on which a credential is provisioned, where the request includes a credential identifier corresponding to the credential. The at least one processor is further configured to identify, based at least in part on the credential identifier, the device secure element. The at least one processor is further configured to verify that the service provider is authorized to interact directly with the device secure element. The at least one processor is further configured to instruct, responsive to the verifying, the device secure element to communicate directly with a service provider server to perform the transaction. The at least one processor is further configured to receive, from the device secure element, a result associated with the transaction.


