Trusted Service Manager Server for Secure NFC Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication systems lack a centralized and secure method to manage and verify authorized application sources for accessing and writing data to mobile device memories, particularly in near-field communication (NFC) transactions, which can lead to security breaches and unauthorized data access.

Innovation Solution

A trusted service manager (TSM) server is introduced to register and verify application sources using service identifiers, ensuring only authorized applications can access and write data to mobile device secure elements, thereby controlling access and preventing unauthorized modifications or installations through a centralized verification database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized verification system is implemented to manage authorized application sources, then security and reliability of NFC transactions are improved, but device complexity and system infrastructure requirements increase

Engineering Contradiction:
Improvesecurity of NFC transactionsVSAvoidsystem infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Trusted Service Manager (TSM) server as an intermediary between application sources and mobile devices. The TSM server acts as a centralized verification authority that registers application sources, verifies their authorization credentials, and manages secure elements. This intermediary resolves the contradiction by providing centralized security management without requiring complex verification logic to be distributed across each mobile device, thus improving reliability while controlling device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the TSM server continuously verifies application sources before allowing data writing operations. The server maintains registration records and authorization states, providing feedback to both application sources and mobile devices about verification status. This feedback loop ensures that only authorized applications can access secure elements, enhancing security while maintaining a manageable system through centralized control and state tracking.

Inventive Principle:
Principle #23Feedback

2Reliability

If application sources are strictly verified before data access, then unauthorized access is prevented, but transaction speed and operational efficiency may be reduced

Engineering Contradiction:
Improveprevention of unauthorized accessVSAvoidtransaction speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The TSM server performs verification actions in advance by pre-registering application sources and storing their authorization credentials in a database. Before actual data writing operations, the server checks whether the application source is already registered and authorized. This preliminary registration and pre-verification approach reduces the time required during actual transactions, as the system only needs to verify against stored credentials rather than performing full authentication each time, thus maintaining security while improving transaction speed.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If centralized verification database is used to manage authorized applications, then control and security are enhanced, but system cost and infrastructure requirements increase

Engineering Contradiction:
Improvecontrol over authorized applicationsVSAvoidinfrastructure requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The TSM server is designed as a universal platform that can serve multiple mobile devices and manage multiple application sources through a single centralized database. The server performs multiple functions including registration, verification, credential management, and authorization control. This multi-functional design reduces the need for separate verification systems for each device or application, consolidating infrastructure requirements while maintaining enhanced control and security across the entire NFC ecosystem.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9077769B2Communications system providing enhanced trusted service manager (TSM) verification features and related methods
Publication Date: 2015.07.07 BLACKBERRY LTD
  • US9077769B2 patent drawing
  • US9077769B2 patent drawing
  • US9077769B2 patent drawing

AI summary

A trusted service manager (TSM) server may include at least one communications device capable of communicating with at least one application server, a verification database server, and at least one mobile communications device. The TSM server may further include a processor coupled with the at least one communications device and capable of registering the at least one application server with the verification database server, receiving a request from the at least one application server to access the memory of the mobile communications device, cooperating with the verification database server to verify the at least one application server based upon the access request and based upon registering of the at least one application server, and writing application data from the at least one application server to the memory of the at least one mobile communications device based upon verifying the at least one application server.