EP3200425A1

Enabling users to select between secure service providers using a key escrow service

Abstract

Systems and methods are described herein for enabling users to select from available secure service providers (each having a Trusted Service Manager ("TSM")) for provisioning applications and services on a secure element installed on a device of the user. A proposed method for providing secure services to a computing network device (110) comprising a secure element (111) in this regard comprises: maintaining, by a computer (150), at least one cryptographic key (120) for the secure element (111), the at least one cryptographic key (120) operable to provide secure access to the secure element (111) via a secure communication channel; receiving from the network device (110), by the computer (150), a selection of a secure service provider (160A, 160B) from available secure service providers (160A, 160B) each having a trusted service manager, TSM (170A, 170B); and transmitting, by the computer (150), the at least one cryptographic key to the selected TSM (160, 170) of the selected service provider (160A, 160B) in response to receiving the request to select the service provider (160A, 160B).

EP3200425A1, drawing sheet 1
Sheet 1 of 5

Term

5.9 yearsto projected expiry

Projected expiry 10 August 2032, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

15 claims: 2 independent, 13 dependent

  1. 1
    A computer-implemented method for providing secure services to a network device (110) comprising a secure element (111), the method comprising:maintaining, by a computer (150), at least one cryptographic key (120) for the secure element (111), the at least one cryptographic key (120) operable to provide secure access to the secure element (111) via a secure communication channel;receiving from the network device (110), by the computer (150), a selection of a secure service provider (160A, 160B) from available secure service providers (160A, 160B) each having a trusted service manager, TSM (170A, 170B);and transmitting, by the computer (150), the at least one cryptographic key to the TSM (160, 170) of the selected service provider (160A, 160B) in response to receiving the request to select the service provider (160A, 160B).
  2. 10
    A system for providing secure services to a network device (110) comprising a secure element (111), the system comprising:a first network communication module configured to receive a selection of a secure service provider (160A, 160B) from available secure service providers (160A, 160B) each having a trusted service manager, TSM (170A, 170B);a key escrow service (150) configured to maintain at least one cryptographic key (120) for the secure element (111), the at least one cryptographic key (120) operable to provide secure access to the secure element (111) via a secure communication channel;and a second network communication module configured to transmit the at least one cryptographic key to the TSM (170A, 170B) of the selected service provider (160A, 160B) in response to receiving the request to select the service provider (160A, 160B), wherein the key escrow service (150) is communicably coupled to the first network communication module and to the second network communication module.