Trusted Service Manager Script Generation via Public-Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Third-party entities face technical complexity and cost barriers in generating scripts executable by secure hardware components for mobile payment systems, particularly for stored value payment applets, and are hesitant to outsource due to concerns about sharing sensitive financial transaction data.

Innovation Solution

A secure trusted service manager provider system configures mobile payment system servers to generate and deploy scripts on behalf of third-party entities, using public-key encryption to ensure privacy and security, allowing third-party entities to manage stored value payment applets on secure hardware components without directly accessing sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party entities generate and deploy scripts directly on secure hardware components, then they can manage stored value payment applets with full control, but they face technical complexity and cost barriers

Engineering Contradiction:
ImproveAbility to manage stored value payment appletsVSAvoidScript generation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The mobile payment system server acts as an intermediary between third-party entities and secure hardware components. The server generates scripts on behalf of third-party entities and deploys them to secure hardware components, eliminating the need for third parties to directly handle complex script generation while maintaining their ability to manage payment applets through simplified interfaces

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If third-party entities outsource script generation to mobile payment system servers, then technical complexity is reduced, but they must share sensitive financial transaction data

Engineering Contradiction:
ImproveScript generation complexityVSAvoidData privacy risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system implements localized data handling where sensitive financial transaction data is processed and encrypted within the secure hardware component environment. The mobile payment system server generates scripts using locally available data without requiring third parties to share sensitive information externally, maintaining data privacy while reducing technical complexity for third parties

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If third-party entities handle their own script generation and deployment, then they maintain data privacy, but they incur high technical and financial overhead

Engineering Contradiction:
ImproveData privacy protectionVSAvoidTechnical overhead
Core Design Contradiction:
Object-affected harmful factorsVSEase of manufacture

Solution Approach 1:

The mobile payment system server provides self-service capabilities where third-party entities can request script generation and deployment through simplified interfaces. The server automatically handles script generation, encryption, and deployment to secure hardware components without requiring third parties to invest in complex technical infrastructure, reducing overhead while maintaining data privacy through localized processing

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12063513B2Secure trusted service manager provider
Publication Date: 2024.08.13 APPLE INC
  • US12063513B2 patent drawing
  • US12063513B2 patent drawing
  • US12063513B2 patent drawing

AI summary

A secure trusted service manager provider may include at least one processor configured to provide, to an electronic device, a first script to provision an applet instance corresponding to a third party server, the script including a public key corresponding to the third party server. The at least one processor may be configured to receive, from the electronic device, an encrypted symmetric key and provide the encrypted symmetric key to the third party server, the symmetric key being encrypted with the public key. The at least one processor may be configured to receive, from the third party server, an encrypted data element corresponding to a transaction to be performed by the applet instance, the encrypted data element being encrypted with the symmetric key, generate a second script that includes the encrypted data element and provide, to the electronic device, the second script that includes the encrypted data element.