Terminal Transmission Server for Secure Runtime Environment Content
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing infrastructure for managing content in secure runtime environments of mobile devices is inefficient and requires significant organizational and financial effort, as it lacks direct compatibility with the communication standards needed for secure runtime environments, leading to security and operational challenges for mobile network operators.
Innovation Solution
A mobile station with a secure runtime environment and a management server that utilizes a terminal transmission server within the security element to forward content messages from a management server to the secure runtime environment, allowing the existing security element management server infrastructure to manage both the security element and the secure runtime environment efficiently and securely, without the need for an external server infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate secure server infrastructure is implemented to manage content in the secure runtime environment, then security and compatibility are improved, but organizational complexity and financial cost increase significantly
Solution Approach 1:
The patent merges the management of security elements and secure runtime environment into a single server infrastructure. The management server uses a unified message routing mechanism that can handle both ETSI-standard messages for security elements and Global Platform-compliant messages for secure runtime environments, eliminating the need for separate server infrastructures and reducing organizational complexity while maintaining security standards.
Solution Approach 2:
The management server is designed with multi-functionality to handle different types of content management requests. It can process security element messages according to ETSI standards and terminal messages for secure runtime environments according to Global Platform standards, making a single server infrastructure capable of performing multiple security management functions.
2Adaptability or versatility
If a separate secure server infrastructure is implemented to manage content in the secure runtime environment, then compatibility with security standards is improved, but financial cost increases significantly
Solution Approach 1:
The management server is designed with multi-functionality to handle different types of content management requests. It can process security element messages according to ETSI standards and terminal messages for secure runtime environments according to Global Platform standards, making a single server infrastructure capable of performing multiple security management functions.
Solution Approach 2:
The system enables self-service through automated message routing and processing. The management server automatically routes incoming messages to the appropriate destination (security element or secure runtime environment) based on message type, eliminating the need for manual intervention and reducing operational costs while maintaining compatibility with multiple security standards.
3Ease of operation
If traditional content management infrastructure is used for secure runtime environment, then operational simplicity is maintained, but security requirements are not met
Solution Approach 1:
The management server acts as an intermediary between the traditional content management infrastructure and the secure runtime environment. It receives content from traditional infrastructure, processes and secures the messages according to Global Platform standards, and delivers them to the secure runtime environment, thereby maintaining operational simplicity while ensuring security requirements are met.
4Device complexity
If message routing is handled externally rather than internally within the security element, then infrastructure complexity is reduced, but security control is weakened
Solution Approach 1:
The management server acts as an intermediary between the traditional content management infrastructure and the secure runtime environment. It receives content from traditional infrastructure, processes and secures the messages according to Global Platform standards, and delivers them to the secure runtime environment, thereby maintaining operational simplicity while ensuring security requirements are met.
Data Source
Figure 1~2
Figure 3
AI summary
The invention relates to a mobile station comprising a mobile terminal (ME) with a secure runtime environment (TEE) and comprising a removable or securely implemented security element (SE). The security element (SE) is equipped with a terminal transmission server (TEE-TSM) which is designed to transmit terminal messages to the secure runtime environment (TEE), said messages being receivable by the secure runtime environment (TEE). The terminal messages are transmitted to the security element (SE) by means of a trusted service manager (SE-TSM) which is provided for the security element (SE), whereby greater efficiency with constant security is ensured.