TSM Directory for Mobile Payment Security Domain Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile payment systems, identifying the appropriate Trusted Service Manager (TSM) for secure transactions becomes increasingly difficult as more secure services are implemented, leading to challenges in managing secure elements and security domains across various devices and networks.
Innovation Solution
A method is provided to determine the TSM provider by identifying the secure element and application identifiers, which are then used to query a repository of TSM providers, allowing secure service providers to discover the identity of the TSM server through a centralized or distributed directory system, utilizing system buses or near-field communication links for secure message exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple secure services are implemented in mobile devices, then the security capabilities and service versatility are improved, but the difficulty of identifying and managing the appropriate Trusted Service Manager increases
Solution Approach 1:
The patent introduces a repository as an intermediary component that stores and manages mappings between security domain identifiers and Trusted Service Manager identifiers. This repository acts as a mediator between the mobile device and multiple TSMs, eliminating the need for the device to directly identify and manage multiple TSMs. The repository receives queries containing security domain identifiers and returns the corresponding TSM identifiers, thereby simplifying the TSM identification process while supporting multiple secure services.
2Ease of operation
If a centralized repository of TSM providers is implemented, then the ease of identifying the appropriate TSM is improved, but the system architecture complexity increases
Solution Approach 1:
The patent extracts the TSM identification functionality from the mobile device and places it in a separate, dedicated repository. This extraction allows the repository to handle the complexity of managing multiple TSM identifiers and their mappings to security domains, while the mobile device only needs to query the repository with security domain identifiers. This separation of concerns simplifies the device operation while concentrating the architectural complexity in a specialized component designed for this purpose.
3Adaptability or versatility
If secure elements are provisioned with multiple security domains, then the functional capabilities are improved, but the difficulty of managing and identifying the correct TSM for each domain increases
Solution Approach 1:
The repository serves as an intermediary that manages the many-to-many relationships between security domains and TSMs. When a secure element needs to be provisioned with multiple security domains, the system queries the repository with each security domain identifier, and the repository returns the corresponding TSM identifier. This intermediary approach eliminates the need for complex manual matching or hardcoding of TSM-domain relationships, thereby supporting multiple security domains while simplifying the identification process.
Data Source
AI summary
Systems and methods enable members of a secure transaction network to readily identify the appropriate trusted service manager (TSM) to support a particular transaction. A global directory of TSM providers is provided that a secure service provider can use for determining which TSM provider is the authorized manager of a security domain for the particular transaction. In aspect the directory of TSM providers may be stored within a mobile device secure element. In another aspect, the directory of TSM providers may be stored in a central TSM repository. In a further aspect, the directory of TSM providers may be distributed among a number of secondary TSM repositories. The appropriate TSM may be identified based upon a secure element identifier and an application identifier provided by a secure element as part of the transaction. Communication of the identifiers from mobile devices may be via cellular or near field communication links.


