Trusted Service Manager Encrypts Sector Keys for Mobile Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service Providers face challenges in securely transmitting applications to mobile phones with key-protected memory sectors, as existing methods risk unauthorized access and security breaches when using SMS for over-the-air services, especially with the Trusted Service Manager controlling memory device allocation and keys.

Innovation Solution

A method where the Trusted Service Manager receives an application and unique identifier from the Service Provider, assigns and encrypts destination sectors and keys, and transmits a setup-message via a secure channel to the mobile phone, ensuring secure memory device setup and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SMS is used for over-the-air transmission of applications to mobile phones, then existing network infrastructure can be utilized and service coverage is expanded, but security is compromised and unauthorized access to memory sectors becomes possible

Engineering Contradiction:
Improveservice coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a Trusted Service Manager (TSM) as an intermediary between the Service Provider and the mobile phone. The TSM securely manages the transmission of sector keys and application data through encrypted channels, preventing unauthorized access while utilizing existing SMS infrastructure. This mediator ensures that sensitive information is protected during over-the-air transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security setup by pre-configuring the mobile phone with security parameters and establishing encrypted communication channels before actual application transmission. The TSM pre-authenticates devices and prepares secure transmission paths, ensuring that when applications are transmitted via SMS, the security framework is already in place to protect the data.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If Service Providers directly transmit applications to mobile phones, then transmission speed is improved and service delivery is faster, but security control is weakened and sensitive information may be exposed

Engineering Contradiction:
Improvetransmission speedVSAvoidinformation exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The Trusted Service Manager acts as a secure intermediary that handles the sensitive transmission of sector keys and application data. While Service Providers can quickly initiate transmission requests, the TSM manages the actual secure delivery through encrypted channels, maintaining both transmission efficiency and security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The transmission process is segmented into distinct phases: Service Provider initiates the request, TSM secures the transmission path and encrypts sensitive data, and the mobile phone receives and processes the encrypted payload. This segmentation allows fast initiation by the Service Provider while security-critical operations are handled separately by the TSM.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If sector keys are transmitted through unencrypted channels for memory device setup, then ease of operation is improved and setup is simpler, but security is compromised and hackers can access sensitive information

Engineering Contradiction:
Improvesetup simplicityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The Trusted Service Manager serves as a secure intermediary that automatically handles the encryption and secure transmission of sector keys during memory device setup. This maintains ease of operation as the process remains automated and simple to initiate, while the TSM's encryption capabilities prevent unauthorized access to the transmitted keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the security parameter of the transmission channel from unencrypted to encrypted. The TSM applies encryption transformations to the sector keys and sensitive data before transmission, maintaining the automated setup process while fundamentally changing the security characteristics of the communication channel to prevent hacker access.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2183728B1Method, system and trusted service manager for securely transmitting an application to a mobile phone
Publication Date: 2015.03.25 NXP BV
  • EP2183728B1 patent drawingFigure 1~3
  • EP2183728B1 patent drawingFigure 4~5

AI summary

A Trusted Service Manager (TSM) receives via a first communication channel from a Service Provider (SP) a request (REQ(MIA)) that contains an application (MIA) together with a unique identifier of a mobile phone (MOB), particularly its telephone number. The mobile phone (MOB) is equipped with a memory device (MIF) that comprises multiple memory sectors being protected by sector keys. Preferably the memory device (MIF) is a MIFARE device. The TSM extracts the application (MIA) and the unique identifier from the received request, assigns destination sector(s) and associated sector key(s) of the memory device (MIF), compiles the application (MIA), the sector key(s) and the sector number(s) of the destination sector(s) into a setup-message (SU(MIA)), encrypts the setup- message and transmits it to either the mobile phone via a second communication channel or the Service Provider via the first communication channel (CN). If the setup-message (SU(MIA)) is transmitted to the Service Provider, the Service Provider sends it over the second communication channel to the mobile phone.