Local Trusted Service Manager for Contactless Smart Card Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current contactless smart cards face limitations in memory partitioning, security, and key management due to statically partitioned namespaces, leading to memory collisions, reduced security, and restricted access control, which hinders the ability to support multiple applications and secure data protection.

Innovation Solution

Implementing a trusted service manager (TSM) within the secure element of contactless smart cards using asymmetric cryptography to dynamically manage namespaces, allowing for secure data storage and access control through private and public keys, enabling multiple applications and secure data management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If statically partitioned namespaces are used in contactless smart cards, then memory allocation is simplified, but memory collisions occur and available memory space is reduced

Engineering Contradiction:
Improvememory allocation complexityVSAvoidavailable memory space
Core Design Contradiction:
Device complexityVSQuantity of substance

Solution Approach 1:

The patent implements dynamic memory allocation by replacing static namespace partitioning with a file system that allows flexible creation, deletion, and resizing of data containers. The TSM manages memory dynamically based on application requirements, eliminating fixed partition boundaries and enabling efficient memory utilization without collisions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the memory space into virtual file systems and data containers managed by the TSM, rather than using rigid static partitions. This segmentation approach allows multiple applications to coexist with isolated data spaces while enabling dynamic allocation and efficient memory utilization through the TSM's file management capabilities.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If limited security protocols are enforced on cards without processor capabilities, then ease of operation is improved, but security options are reduced

Engineering Contradiction:
Improvecard operation simplicityVSAvoidsecurity options
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a Trusted Service Manager (TSM) as an intermediary component that bridges the gap between simple contactless card operation and enhanced security requirements. The TSM provides cryptographic key management, authentication, and secure data handling capabilities without requiring the card itself to have complex processing capabilities, thus maintaining ease of operation while significantly improving security options.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces mechanical/physical security limitations (processor capabilities) with cryptographic/software-based security mechanisms. By implementing a virtual file system and cryptographic protocols at the software level, the system achieves advanced security without requiring additional hardware processing power, thus maintaining simplicity while enhancing security options.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Quantity of substance

If all memory is actively used in small capacity cards, then memory utilization is maximized, but flexibility for development is reduced

Engineering Contradiction:
Improvememory utilizationVSAvoiddevelopment flexibility
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic memory management through a file system that allows memory to be allocated and deallocated based on runtime requirements. Applications can create, modify, and delete data containers as needed, enabling flexible development while maintaining high memory utilization. The TSM manages the file system to ensure efficient space usage without fixed allocations.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If multiple applications share memory space, then device versatility is improved, but memory collisions and access conflicts increase

Engineering Contradiction:
Improvemulti-application supportVSAvoidmemory access reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the shared memory space into isolated file systems and data containers managed by the TSM. Each application operates within its own virtual space, preventing direct memory collisions while enabling multiple applications to coexist. The TSM's file system provides namespace isolation and manages access control, ensuring reliable memory access across multiple applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The TSM acts as an intermediary layer between multiple applications and the underlying memory space. It manages file systems, handles allocation requests, and resolves access conflicts through centralized control. This intermediary approach enables multiple applications to share memory efficiently while maintaining access reliability through coordinated management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8793508B2Local trusted services manager for a contactless smart card
Publication Date: 2014.07.29 GOOGLE LLC
  • US8793508B2 patent drawing
  • US8793508B2 patent drawing
  • US8793508B2 patent drawing

AI summary

Systems, methods, computer programs, and devices are disclosed herein for deploying a local trusted service manager within a secure element of a contactless smart card device. The secure element is a component of a contactless smart card incorporated into a contactless smart card device. An asymmetric cryptography algorithm is used to generate public-private key pairs. The private keys are stored in the secure element and are accessible by a trusted service manager (TSM) software application or a control software application in the secure element. A non-TSM computer with access to the public key encrypts and then transmits encrypted application data or software applications to the secure element, where the TSM software application decrypts and installs the software application to the secure element for transaction purposes.