Security Element Application Installation Inversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for installing applications in security elements of portable terminal devices are inflexible and prone to failures due to the complexity of determining the correct Trusted Service Manager (TSM) and proprietary communication protocols, leading to difficulties in securely managing security-relevant data.

Innovation Solution

A method where the security element itself can initiate and direct installation orders to installation devices using multiple communication protocols, allowing it to act as a client in the installation process, and interact with multiple installation devices to ensure secure and flexible application installation, even across different security elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional installation devices (TSM) are used to manage security elements, then application installation can be cryptographically secured, but the system becomes rigid and installation orders frequently fail due to difficulty in determining the correct TSM and proprietary communication protocols

Engineering Contradiction:
Improveinstallation success rateVSAvoidsystem rigidity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional installation initiation model by allowing the security element to autonomously initiate installation orders to installation devices, rather than requiring external entities to determine and contact the appropriate TSM. This inversion resolves the contradiction by making the system more flexible (security element can choose any installation device) while maintaining security through cryptographic verification of the installation order authenticity.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The security element is empowered to autonomously generate and send installation orders to installation devices without requiring external management coordination. The security element independently determines which installation device to contact and initiates the installation process itself, eliminating the need for complex TSM determination logic while maintaining cryptographic security through built-in authentication mechanisms.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If multiple installation devices (TSM) are deployed to provide installation services, then service coverage is increased, but it becomes increasingly difficult for application providers to determine the correct TSM to contact

Engineering Contradiction:
Improveservice coverageVSAvoidTSM determination difficulty
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The security element autonomously determines which installation device to contact and initiates the installation order itself, eliminating the need for application providers to determine the correct TSM. The security element can independently select from multiple installation devices based on its own criteria, maintaining service coverage while simplifying the overall system operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security element acts as an intermediary between the application provider and installation devices. Instead of the application provider directly contacting installation devices (which requires TSM determination), the security element receives the application and autonomously contacts appropriate installation devices, simplifying the interaction model while maintaining multiple service options.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security elements use proprietary communication protocols for communication with installation devices, then security is enhanced, but installation orders increasingly fail due to protocol incompatibility

Engineering Contradiction:
Improvecommunication securityVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security element autonomously selects and contacts installation devices that are compatible with its communication protocol, eliminating protocol incompatibility issues. By initiating the installation order itself, the security element can choose from installation devices that support its proprietary protocol, maintaining both security and compatibility without requiring external coordination.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system becomes dynamic in allowing multiple communication protocols to coexist. Different security elements can use different proprietary protocols and autonomously select installation devices that match their protocol requirements, enabling protocol diversity while maintaining overall system compatibility through decentralized protocol selection.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2923264B1Method and system for application installation in a security element
Publication Date: 2022.03.23 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP2923264B1 patent drawingFigure 1~2
  • EP2923264B1 patent drawingFigure 3

AI summary

A method for installing an application (30) in a security element (20; 20'") of a portable terminal (10) comprises the following steps: the installation device receives (S3; T1) an installation order for installing a prescribed application (30) on a prescribed security element (20; 20'"). This order is handled by the installation device (S4; T2, T3, T4, T5). According to the invention, the installation device (100; 100') receives the installation order from the prescribed security element (20; 20"') itself or from a further security element (20'; 20"), which is different from the prescribed security element (20; 20"').