Trusted Service Manager Encrypts Sector Keys for Mobile Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service Providers face challenges in securely transmitting applications to mobile phones with key-protected memory sectors, as existing methods risk unauthorized access and security breaches when using SMS for over-the-air services, especially with the Trusted Service Manager controlling memory device allocation and keys.
Innovation Solution
A method where the Trusted Service Manager receives an application and unique identifier from the Service Provider, assigns and encrypts destination sectors and keys, and transmits a setup-message via a secure channel to the mobile phone, ensuring secure memory device setup and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If SMS is used for over-the-air transmission of applications to mobile phones, then existing network infrastructure can be utilized and service coverage is expanded, but security is compromised and unauthorized access to memory sectors becomes possible
Solution Approach 1:
The patent introduces a Trusted Service Manager (TSM) as an intermediary between the Service Provider and the mobile phone. The TSM securely manages the transmission of sector keys and application data through encrypted channels, preventing unauthorized access while utilizing existing SMS infrastructure. This mediator ensures that sensitive information is protected during over-the-air transmission.
Solution Approach 2:
The system performs preliminary security setup by pre-configuring the mobile phone with security parameters and establishing encrypted communication channels before actual application transmission. The TSM pre-authenticates devices and prepares secure transmission paths, ensuring that when applications are transmitted via SMS, the security framework is already in place to protect the data.
2Productivity
If Service Providers directly transmit applications to mobile phones, then transmission speed is improved and service delivery is faster, but security control is weakened and sensitive information may be exposed
Solution Approach 1:
The Trusted Service Manager acts as a secure intermediary that handles the sensitive transmission of sector keys and application data. While Service Providers can quickly initiate transmission requests, the TSM manages the actual secure delivery through encrypted channels, maintaining both transmission efficiency and security control.
Solution Approach 2:
The transmission process is segmented into distinct phases: Service Provider initiates the request, TSM secures the transmission path and encrypts sensitive data, and the mobile phone receives and processes the encrypted payload. This segmentation allows fast initiation by the Service Provider while security-critical operations are handled separately by the TSM.
3Ease of operation
If sector keys are transmitted through unencrypted channels for memory device setup, then ease of operation is improved and setup is simpler, but security is compromised and hackers can access sensitive information
Solution Approach 1:
The Trusted Service Manager serves as a secure intermediary that automatically handles the encryption and secure transmission of sector keys during memory device setup. This maintains ease of operation as the process remains automated and simple to initiate, while the TSM's encryption capabilities prevent unauthorized access to the transmitted keys.
Solution Approach 2:
The system changes the security parameter of the transmission channel from unencrypted to encrypted. The TSM applies encryption transformations to the sector keys and sensitive data before transmission, maintaining the automated setup process while fundamentally changing the security characteristics of the communication channel to prevent hacker access.
Data Source
Figure 1~3
Figure 4~5
AI summary
A Trusted Service Manager (TSM) receives via a first communication channel from a Service Provider (SP) a request (REQ(MIA)) that contains an application (MIA) together with a unique identifier of a mobile phone (MOB), particularly its telephone number. The mobile phone (MOB) is equipped with a memory device (MIF) that comprises multiple memory sectors being protected by sector keys. Preferably the memory device (MIF) is a MIFARE device. The TSM extracts the application (MIA) and the unique identifier from the received request, assigns destination sector(s) and associated sector key(s) of the memory device (MIF), compiles the application (MIA), the sector key(s) and the sector number(s) of the destination sector(s) into a setup-message (SU(MIA)), encrypts the setup- message and transmits it to either the mobile phone via a second communication channel or the Service Provider via the first communication channel (CN). If the setup-message (SU(MIA)) is transmitted to the Service Provider, the Service Provider sends it over the second communication channel to the mobile phone.