EP3200425B1

Enabling users to select between secure service providers using a key escrow service

Abstract

This record has no abstract on file.

EP3200425B1, drawing sheet 1
Sheet 1 of 4

Term

5.9 yearsleft in the term

Expires 10 August 2032.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

11 claims: 2 independent, 9 dependent

  1. 1
    A computer-implemented method for providing secure services to a network device (110) comprising a secure element (111) in a system (100) comprising the network device (110), a computer (150) maintaining at least one cryptographic key (120) for the secure element (111), and secure service providers (160A, 160B) each having a trusted service manager, TSM (170A, 170B), the method comprising:maintaining, by the computer (150), said at least one cryptographic key (120) for the secure element (111), the at least one cryptographic key (120) operable to provide secure access to the secure element (111) via a secure communication channel;receiving from the network device (110), by the computer (150), a request to select a secure service provider (160A, 160B), among said secure server providers (160A, 160B), from available secure service providers (160A, 160B) each having said trusted service manager, TSM (170A, 170B), wherein the secure element (111) includes information related to a previous TSM (170A, 170B) that is different from the TSM (170A, 170B) of the selected service provider (160A, 160B), and wherein if the previous TSM (170A, 170B) possesses the at least one cryptographic key (120), the method further comprises revoking the at least one cryptographic key (120) from the previous TSM (170A, 170B) in response to receiving the request to select the secure service provider (160A, 160B);and transmitting, by the computer (150), the at least one cryptographic key to the TSM (160, 170) of the selected service provider (160A, 160B) in response to receiving the request to select the service provider (160A, (160B).
  2. 8
    A system for providing secure services to a network device (110) comprising a secure element (111), the system comprising:secure service providers (160A, 160B), the network device (110), a first network communication module configured to receive, from the network device (110), a request to select a secure service provider (160A, 160B), among said secure server providers (160A, 160B), from available secure service providers (160A, 160B) each having a trusted service manager, TSM (170A, 170B);a key escrow service (150) configured to maintain at least one cryptographic key (120) for the secure element (111), the at least one cryptographic key (120) operable to provide secure access to the secure element (111) via a secure communication channel wherein the secure element (111) includes information related to a previous TSM (170A, 170B) that is different from the TSM of the selected service provider (160A, 160B), and wherein if the previous TSM (170A, 170B) possesses the at least one cryptographic key (120), the key escrow service (150) is configured to revoke the at least one cryptographic key (120) from the previous TSM (170A, 170B) in response to receiving the request to select the service provider (160A, 160B);and a second network communication module configured to transmit the at least one cryptographic key to the TSM (170A, 170B) of the selected service provider (160A, 160B) in response to receiving the request to select the service provider (160A, 160B) , wherein the key escrow service (150) is communicably coupled to the first network communication module and to the second network communication module.