Trusted Service Manager Script Generation via Public-Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Third-party entities face technical complexity and cost barriers in generating scripts executable by secure hardware components for mobile payment systems, particularly for stored value payment applets, and are hesitant to outsource due to concerns about sharing sensitive financial transaction data.
Innovation Solution
A secure trusted service manager provider system configures mobile payment system servers to generate and deploy scripts on behalf of third-party entities, using public-key encryption to ensure privacy and security, allowing third-party entities to manage stored value payment applets on secure hardware components without directly accessing sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If third-party entities generate and deploy scripts directly on secure hardware components, then they can manage stored value payment applets with full control, but they face technical complexity and cost barriers
Solution Approach 1:
The mobile payment system server acts as an intermediary between third-party entities and secure hardware components. The server generates scripts on behalf of third-party entities and deploys them to secure hardware components, eliminating the need for third parties to directly handle complex script generation while maintaining their ability to manage payment applets through simplified interfaces
2Device complexity
If third-party entities outsource script generation to mobile payment system servers, then technical complexity is reduced, but they must share sensitive financial transaction data
Solution Approach 1:
The system implements localized data handling where sensitive financial transaction data is processed and encrypted within the secure hardware component environment. The mobile payment system server generates scripts using locally available data without requiring third parties to share sensitive information externally, maintaining data privacy while reducing technical complexity for third parties
3Object-affected harmful factors
If third-party entities handle their own script generation and deployment, then they maintain data privacy, but they incur high technical and financial overhead
Solution Approach 1:
The mobile payment system server provides self-service capabilities where third-party entities can request script generation and deployment through simplified interfaces. The server automatically handles script generation, encryption, and deployment to secure hardware components without requiring third parties to invest in complex technical infrastructure, reducing overhead while maintaining data privacy through localized processing
Data Source
AI summary
A secure trusted service manager provider may include at least one processor configured to provide, to an electronic device, a first script to provision an applet instance corresponding to a third party server, the script including a public key corresponding to the third party server. The at least one processor may be configured to receive, from the electronic device, an encrypted symmetric key and provide the encrypted symmetric key to the third party server, the symmetric key being encrypted with the public key. The at least one processor may be configured to receive, from the third party server, an encrypted data element corresponding to a transaction to be performed by the applet instance, the encrypted data element being encrypted with the symmetric key, generate a second script that includes the encrypted data element and provide, to the electronic device, the second script that includes the encrypted data element.


