Partially delegated over-the-air provisioning of a secure element
First Claim
1. A system for provisioning a secure element on a mobile device, comprising:
- a first trusted service manager associated with a credit card;
a second trusted service manager associated with a wireless service provider; and
a mobile device having a secure element to hold the credit card and an over-the-air client to communicate wirelessly with the first trusted service manager and the second trusted service manager,wherein the second trusted service manager receives a provisioning service request from the first trusted service manager, validates that the provisioning service request originates from the first trusted service manager and that the first trusted service manager is authorized to conduct provisioning on the mobile device based on an exchange of shared secrets or security tokens, receives a request from the over-the-air client over a secure connection established between the secure element and the second trusted service manager, transmits a command over the secure connection to the over-the-air client in response to the request, the command relating to at least a portion of the service identified in the provisioning request, receives a command result over the secure connection from the over-the-air client, and closes the secure connection.
5 Assignments
0 Petitions
Accused Products
Abstract
A system for provisioning a secure element on a mobile device is provided. The system comprises a first trusted service manager associated with a credit card, a second trusted service manager associated with a wireless service provider, and a mobile device. The mobile device has a secure element to hold the credit card and an over-the-air client to communicate wirelessly with the first trusted service manager and the second trusted service manager. When the second trusted service manager receives a message from the first trusted service manager to provision a personalization information for the credit card to the mobile device, the second trusted service manager transmits to the over-the-air client a message to initiate transfer of the personalization information for the credit card.
-
Citations
18 Claims
-
1. A system for provisioning a secure element on a mobile device, comprising:
-
a first trusted service manager associated with a credit card; a second trusted service manager associated with a wireless service provider; and a mobile device having a secure element to hold the credit card and an over-the-air client to communicate wirelessly with the first trusted service manager and the second trusted service manager, wherein the second trusted service manager receives a provisioning service request from the first trusted service manager, validates that the provisioning service request originates from the first trusted service manager and that the first trusted service manager is authorized to conduct provisioning on the mobile device based on an exchange of shared secrets or security tokens, receives a request from the over-the-air client over a secure connection established between the secure element and the second trusted service manager, transmits a command over the secure connection to the over-the-air client in response to the request, the command relating to at least a portion of the service identified in the provisioning request, receives a command result over the secure connection from the over-the-air client, and closes the secure connection. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A method of provisioning a secure element on a mobile device, comprising:
-
receiving, by a second trusted service manager associated with a wireless service provider, a provisioning service request from a first trusted service manager associated with a credit card; validating, by the second trusted service manager, that the provisioning service request originates from the first trusted service manager and that the first trusted service manager is authorized to conduct provisioning on the mobile device based on an exchange of shared secrets or security tokens; establishing a secure connection between the second trusted service manager and the secure element of the mobile device, wherein at least a portion of the secure connection is provided by a wireless link; receiving, by the second trusted service manager, a request over the secure connection from an over-the-air client of the mobile device; in response to the request, transmitting, by the second trusted service manager, a command over the secure connection to the over-the-air client, the command relating to at least a portion of the services identified in the provisioning service request; receiving, by the second trusted service manager, a command result over the secure connection from the over-the-air client; and closing the secure connection with the secure element of the mobile device. - View Dependent Claims (8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A method of provisioning a secure element on a mobile device performed by the mobile device, comprising:
-
in response to receiving a provisioning service request from a first trusted service manager associated with a credit card, establishing, by an over-the-air client of the mobile device, a secure connection between a second trusted service manager associated with a wireless service provider and the secure element of the mobile device, wherein the provisioning service request comprises one of locking the credit card and suspending the credit card, and wherein at least a portion of the secure connection is provided by a wireless link; requesting, by the over-the-air client, a command from the second trusted service manager; receiving, by the over-the-air client, the command from the second trusted service manager over the secure connection, the command relating to at least a portion of the services identified in the provisioning service request; transmitting, by the over-the-air client, a command result over the secure connection to the second trusted service manager; and closing the secure connection with the secure element of the mobile device. - View Dependent Claims (17, 18)
-
Specification