Trusted Service Manager Identifying Secure Elements via CPLC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face challenges in identifying and authenticating devices equipped with secure elements, especially when these elements are moved between devices or lack common identifiers like MSISDN or IMEI/MEID, and require secure element unlocking for personalized services.
Innovation Solution
The implementation of a trusted service manager system that receives card production life cycle (CPLC) information to identify secure elements and associate secure element identification information with messages, enabling secure element authentication and unlocking through derived keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional device identifiers (MSISDN, IMEI/MEID) are used to identify mobile devices, then identification is straightforward for devices with these identifiers, but identification fails for devices without these identifiers (e.g., tablets) and becomes unreliable when secure elements are moved between devices
Solution Approach 1:
The patent introduces CPLC information as an intermediary identifier that bridges the gap between device identification and secure element identification. Instead of relying on device-specific identifiers, the system uses CPLC data embedded in the secure element itself, allowing consistent identification regardless of device type or secure element location
Solution Approach 2:
The patent creates a copy of the secure element's identity information (CPLC data) that can be transmitted independently of the physical secure element. This allows the service provider to identify and authenticate the secure element based on its copied identity characteristics rather than requiring direct access to device identifiers
2Adaptability or versatility
If different manufacturers use different security techniques and encryption methods to lock secure elements, then each manufacturer can implement their own security standards, but the service provider cannot uniformly unlock and personalize secure elements from different manufacturers
Solution Approach 1:
The patent implements a universal unlocking mechanism where the service provider uses a single master key to unlock secure elements from different manufacturers. The CPLC information contains manufacturer-specific data that enables the service provider to adapt the universal unlocking process to work with various encryption techniques while maintaining a consistent interface
Solution Approach 2:
The patent changes the parameters of the unlocking process by using CPLC information to dynamically adjust the unlocking approach based on the secure element's manufacturer and encryption method. This allows the system to handle different security techniques through parameter variation rather than requiring separate unlocking procedures for each manufacturer
3Adaptability or versatility
If secure elements are removed from devices and inserted into different devices, then secure elements can be reused and flexible deployment is enabled, but identification and authentication of the secure element becomes difficult
Solution Approach 1:
The patent performs preliminary action by embedding CPLC identification information into the secure element before it is removed from the device. This pre-loaded identification data remains with the secure element throughout its lifecycle, ensuring continuous identifiability regardless of device changes
Solution Approach 2:
The patent creates a portable copy of the secure element's identity (CPLC data) that travels with the secure element when it is moved between devices. This copied identity information allows the service provider to track and authenticate the secure element independently of its physical location or host device
Data Source
AI summary
Embodiments of the disclosure provide systems and methods for identifying devices by a trusted service manager. According to one example embodiments of the disclosure, a method for identifying communications is provided. The method can include receiving, by a service provider from a device, a message comprising card production life cycle (CPLC) information associated with a secure element incorporated into the device; and evaluating, by the service provider, the received CPLC information in order to identify the secure element.


