Virtual Secure Element Segmentation for Mobile Payment Accounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile payment systems face challenges in supporting multiple payment accounts on a single mobile device due to hardware limitations and compatibility issues with secure elements, leading to complexity in provisioning and usage of NFC payments.

Innovation Solution

The implementation of multiple virtual secure elements (SEs) within a single hardware SE in a mobile device, managed by a trusted service manager, allows for dynamic selection and secure storage of multiple payment accounts, enabling seamless NFC transactions across various payment systems without requiring significant changes to existing infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If a single physical secure element is used in a mobile device, then hardware security is maintained, but only one payment account can be stored

Engineering Contradiction:
Improvenumber of payment accountsVSAvoidsecure element architecture
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments a single physical secure element into multiple virtual secure elements (vSEs), each capable of storing separate payment accounts. This is achieved by creating isolated software environments within the hardware SE, where each vSE appears as a distinct secure container to applications while physically residing in the same hardware component. This resolves the contradiction by increasing account capacity without adding multiple physical chips.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes a single physical secure element universal by enabling it to serve multiple payment account functions simultaneously. The hardware SE is designed to host multiple vSEs that can differentially support various payment networks (Visa, MasterCard, American Express, etc.), making one physical component perform the work of multiple specialized elements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Quantity of substance

If multiple physical secure elements are used to support multiple payment accounts, then account capacity increases, but hardware compatibility issues arise

Engineering Contradiction:
Improvenumber of payment accountsVSAvoidpayment system compatibility
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The patent introduces a virtual secure element manager as an intermediary layer between the physical SE and payment applications. This manager handles the complexity of multiple payment network protocols and account management, translating diverse payment requirements into unified hardware operations. This resolves compatibility issues by isolating protocol diversity from the physical hardware layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If multiple physical secure elements are provisioned, then multiple payment accounts can be stored, but provisioning complexity increases

Engineering Contradiction:
Improvenumber of payment accountsVSAvoidprovisioning process
Core Design Contradiction:
Quantity of substanceVSEase of manufacture

Solution Approach 1:

The patent implements preliminary provisioning of multiple virtual secure elements during device manufacturing or initial setup. The vSE manager pre-configures multiple vSEs with appropriate security contexts and payment network certifications before the user needs them. This eliminates the need for complex runtime provisioning of each additional payment account, as the infrastructure is already in place.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If a single hardware secure element is used, then device simplicity is maintained, but support for multiple payment networks is limited

Engineering Contradiction:
Improvepayment network supportVSAvoidsecure element management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent adds a software virtualization dimension to the traditional hardware-only secure element model. By creating multiple virtual instances within the single physical SE, the system achieves multi-network support without physical expansion. This dimensional shift from hardware multiplication to software instantiation resolves the contradiction between versatility and simplicity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9953310B2Systems and method for providing multiple virtual secure elements in a single physical secure element of a mobile device
Publication Date: 2018.04.24 MASTERCARD INT INC
  • US9953310B2 patent drawing
  • US9953310B2 patent drawing
  • US9953310B2 patent drawing

AI summary

Methods and systems are disclosed for providing a plurality of virtual secure elements (virtual SEs) to mobile devices with secure elements (SEs). A method generates and forwards a certificate authority security domain (CASD) key for a plurality of virtual SEs to an SE supplier that created the CASD. The method receives a card serial number (CSN) and a card production life cycle (CPLC) key from the SE supplier and forwards these to a mobile device maker. An updated CSN and CPLC data is received from the device maker with an International Mobile Equipment Identity (IMEI) and an issuer security domain key (ISD key) is added to the CSN and CPLC data by a master secure element issuer trusted service manager (master SEI TSM). An application is provisioned to the device that retrieves the CSN, CPLC data, and the IMEI, which are used for to verify and activate the virtual SE.