Virtual Secure Element Segmentation for Mobile Payment Accounts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile payment systems face challenges in supporting multiple payment accounts on a single mobile device due to hardware limitations and compatibility issues with secure elements, leading to complexity in provisioning and usage of NFC payments.
Innovation Solution
The implementation of multiple virtual secure elements (SEs) within a single hardware SE in a mobile device, managed by a trusted service manager, allows for dynamic selection and secure storage of multiple payment accounts, enabling seamless NFC transactions across various payment systems without requiring significant changes to existing infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If a single physical secure element is used in a mobile device, then hardware security is maintained, but only one payment account can be stored
Solution Approach 1:
The patent segments a single physical secure element into multiple virtual secure elements (vSEs), each capable of storing separate payment accounts. This is achieved by creating isolated software environments within the hardware SE, where each vSE appears as a distinct secure container to applications while physically residing in the same hardware component. This resolves the contradiction by increasing account capacity without adding multiple physical chips.
Solution Approach 2:
The patent makes a single physical secure element universal by enabling it to serve multiple payment account functions simultaneously. The hardware SE is designed to host multiple vSEs that can differentially support various payment networks (Visa, MasterCard, American Express, etc.), making one physical component perform the work of multiple specialized elements.
2Quantity of substance
If multiple physical secure elements are used to support multiple payment accounts, then account capacity increases, but hardware compatibility issues arise
Solution Approach 1:
The patent introduces a virtual secure element manager as an intermediary layer between the physical SE and payment applications. This manager handles the complexity of multiple payment network protocols and account management, translating diverse payment requirements into unified hardware operations. This resolves compatibility issues by isolating protocol diversity from the physical hardware layer.
3Quantity of substance
If multiple physical secure elements are provisioned, then multiple payment accounts can be stored, but provisioning complexity increases
Solution Approach 1:
The patent implements preliminary provisioning of multiple virtual secure elements during device manufacturing or initial setup. The vSE manager pre-configures multiple vSEs with appropriate security contexts and payment network certifications before the user needs them. This eliminates the need for complex runtime provisioning of each additional payment account, as the infrastructure is already in place.
4Adaptability or versatility
If a single hardware secure element is used, then device simplicity is maintained, but support for multiple payment networks is limited
Solution Approach 1:
The patent adds a software virtualization dimension to the traditional hardware-only secure element model. By creating multiple virtual instances within the single physical SE, the system achieves multi-network support without physical expansion. This dimensional shift from hardware multiplication to software instantiation resolves the contradiction between versatility and simplicity.
Data Source
AI summary
Methods and systems are disclosed for providing a plurality of virtual secure elements (virtual SEs) to mobile devices with secure elements (SEs). A method generates and forwards a certificate authority security domain (CASD) key for a plurality of virtual SEs to an SE supplier that created the CASD. The method receives a card serial number (CSN) and a card production life cycle (CPLC) key from the SE supplier and forwards these to a mobile device maker. An updated CSN and CPLC data is received from the device maker with an International Mobile Equipment Identity (IMEI) and an issuer security domain key (ISD key) is added to the CSN and CPLC data by a master secure element issuer trusted service manager (master SEI TSM). An application is provisioned to the device that retrieves the CSN, CPLC data, and the IMEI, which are used for to verify and activate the virtual SE.


