Transferring the control of a secure element
Abstract
Transferring control of the secure element between TSMs includes a zone master key established between TSMs that facilitates encryption of temporary keys. TSM creates this zone master key before initiating the transfer of control. When the transfer of control is initiated, the first TSM establishes a communication channel and removes its key from the secure element. The first TSM creates a temporary key that is encrypted using the zone master key established between the first TSM and the second TSM. The encrypted temporary key is communicated to the second TSM along with the device identifier. The second TSM uses the zone master key to decrypt the temporary key and the device identifier to identify the user device. The new TSM establishes a communication channel and removes the temporary key from the secure element. The new TSM then enters the key into the secure element and saves it.

Term
Projected expiry 25 February 2033.
- Priority and filed
- Granted
- Today
- Projected expiry
29 claims: 9 independent, 20 dependent
- 1セキュアエレメントの制御を転送するためのコンピュータにより実行される方法であって、 コンピュータにより、第1のトラステッドサービスマネージャ(trusted service manager(「TSM」))と第2のTSMとの間に、前記第1のTSMから前記第2のTSMへのセキュアエレメントの制御の転送を促進するマスターキーを作成することと、 前記コンピュータにより、前記第1のTSMから前記第2のTSMにセキュアエレメントの制御を転送する要求を受信することと、 前記コンピュータにより、前記セキュアエレメント上に常駐する前記第1のTSMにより既知のアクセスキーを使用して設立される、前記セキュアエレメントとのセキュア通信チャネルを開始することと、 前記コンピュータにより、前記アクセスキーを前記セキュアエレメントから削除する命令を通信することと、 前記コンピュータにより、一時キーを作成することと、 前記コンピュータにより、前記一時キーを前記セキュアエレメントに通信することと、 前記コンピュータにより、前記第1のTSMと前記第2のTSMとの間に設立された前記マスターキーを使用して、前記一時キーを暗号化することと、 前記コンピュータにより、前記第2のTSMが前記セキュアエレメントにアクセスするように、前記暗号化された一時キーを前記第2のTSMに通信することと、を含む、方法。
- 2前記コンピュータは、前記第1のTSMを動作させる、第1のセキュアサービス提供者である、請求項1に記載のコンピュータにより実行される方法。
- 3前記マスターキーを作成することが、 前記コンピュータにより、前記マスターキーの第1の部分を生成することと、 前記コンピュータにより、前記マスターキーの前記第1の部分を、前記第1のTSM上に常駐するハードウェアセキュリティモジュールに入力することと、 前記コンピュータにより、前記マスターキーの第2の部分を生成することと、 前記コンピュータにより、前記マスターキーの前記第2の部分を、前記第1のTSM上に常駐するハードウェアセキュリティモジュールに入力することと、 前記コンピュータにより、前記第1のTSM上に常駐する前記ハードウェアセキュリティモジュール内の前記第1および第2のマスターキー部分を組み立てることと、 前記コンピュータにより、前記マスターキー部分を破壊することと、を含む、請求項1に記載のコンピュータにより実行される方法。
- 4前記コンピュータにより、前記セキュアエレメントとの前記セキュア通信チャネルを終了することをさらに含む、請求項1に記載のコンピュータにより実行される方法。
- 5前記コンピュータにより、ユーザデバイス識別子を前記第2のTSMに通信することをさらに含み、前記ユーザデバイス識別子が、前記セキュアエレメントを識別するように、前記第2のTSMにより使用されてよい、請求項1に記載のコンピュータにより実行される方法。
- 6前記第2のTSMが前記セキュアエレメントにアクセスするように、前記暗号化された一時キーを前記第2のTSMに通信することが、前記暗号化された一時キーをメディエータTSMに通信することを含む、請求項1に記載のコンピュータにより実行される方法。
- 7前記第2のTSMが前記メディエータTSMである、請求項1に記載のコンピュータにより実行される方法。
- 8前記第2のTSMにより、前記第1のTSMと前記第2のTSMとの間に設立された前記マスターキーを使用して、前記一時キーを解読することと、 前記第2のTSMにより、前記第2のTSMにより解読された前記一時キーを使用して設立される、前記セキュアエレメントとのセキュア通信チャネルを開始することと、 前記第2のTSMにより、前記一時キーを前記セキュアエレメントから削除することと、 前記メディエータTSMにより、第2の一時キーを作成することと、 前記第2のTSMにより、前記第2の一時キーを前記セキュアエレメントに通信することと、 前記メディエータTSMにより、前記第2のTSMと第3のTSMとの間に設立される第2のマスターキーを使用して、前記第2の一時キーを暗号化することと、 前記メディエータTSMにより、前記第3のTSMが前記セキュアエレメントにアクセスするように、前記暗号化された第2の一時キーを前記第3のTSMに通信することと、をさらに含む、請求項7に記載のコンピュータにより実行される方法。
- 9セキュアエレメントの制御を転送するためのコンピュータにより実行される方法であって、 コンピュータにより、第1のトラステッドサービスマネージャ(「TSM」)とメディエータTSMとの間に、前記第1のTSMから前記メディエータTSMへのセキュアエレメントの制御の転送を促進する、第1のマスターキーを作成することと、 コンピュータにより、前記メディエータTSMと第2のTSMとの間に、前記メディエータTSMから前記第2のTSMへの前記セキュアエレメントの制御の転送を促進する、第2のマスターキーを作成することと、 前記コンピュータにより、前記第1のTSMから前記メディエータTSMに前記セキュアエレメントの制御を転送するように、前記第1のTSMと前記メディエータTSMとの間に設立された前記第1のマスターキーにより暗号化され、かつ前記セキュアエレメント上に保存されている第1の一時キーを前記第1のTSMから受信することと、 前記コンピュータにより、前記第1のTSMと前記メディエータTSMとの間に設立された前記第1のマスターキーを使用して、前記第1の一時キーを解読することと、 前記コンピュータにより、前記メディエータTSMにより解読された前記第1の一時キーを使用して設立される、前記セキュアエレメントとのセキュア通信チャネルを開始することと、 前記コンピュータにより、前記第1の一時キーを前記セキュアエレメントから削除する命令を通信することと、 前記コンピュータにより、第2の一時キーを作成することと、 前記コンピュータにより、前記第2の一時キーを前記セキュアエレメントに通信することと、 前記コンピュータにより、前記メディエータTSMと前記第2のTSMとの間に設立された前記第2のマスターキーを使用して、前記第2の一時キーを暗号化することと、 前記コンピュータにより、前記第2のTSMが前記セキュアエレメントにアクセスするように、前記暗号化された第2の一時キーを前記第2のTSMに通信することと、を含む、方法。
- 10前記コンピュータが、前記メディエータTSMを動作させる、モバイルオペレーティングネットワークである、請求項9に記載のコンピュータにより実行される方法。
- 11前記第1および第2のマスターキーのうちの1つを作成することが、 前記コンピュータにより、前記マスターキーの第1の部分を生成することと、 前記コンピュータにより、前記マスターキーの前記第1の部分をハードウェアセキュリティモジュールに入力することと、 前記コンピュータにより、前記マスターキーの第2の部分を生成することと、 前記コンピュータにより、前記マスターキーの前記第2の部分を前記ハードウェアセキュリティモジュールに入力することと、 前記コンピュータにより、前記ハードウェアセキュリティモジュール内の前記マスターキー部分を組み立てることと、 前記コンピュータにより、前記マスターキー部分を破壊することと、を含む、請求項9に記載のコンピュータにより実行される方法。
- 12前記コンピュータにより、前記セキュアエレメントとの前記セキュア通信チャネルを終了することをさらに含む、請求項9に記載のコンピュータにより実行される方法。
- 13前記コンピュータにより、ユーザデバイス識別子を前記第2のTSMに通信することをさらに含み、前記ユーザデバイス識別子が、前記セキュアエレメントを識別するように、前記第2のTSMにより使用されてよい、請求項9に記載のコンピュータにより実行される方法。
- 14コンピュータプログラムであって、 セキュアエレメントの制御を転送するためのコンピュータ可読プログラムコードを中に具現化させた持続性コンピュータ可読媒体を備え、前記コンピュータ可読媒体が、前記第1のTSMからメディエータTSMにセキュアエレメントの制御を転送するように、 第1の一時キーを第1のトラステッドサービスマネージャ(「TSM」)から受信するためのコンピュータ可読プログラムコードと、 前記セキュアエレメント上に常駐する前記第1の一時キーを使用して設立される、前記セキュアエレメントとのセキュア通信チャネルを開始するためのコンピュータ可読プログラムコードと、 前記セキュアエレメント上に入力および保存される、第2の一時キーを作成するためのコンピュータ可読プログラムコードと、 前記第2の一時キーを前記第2のTSMに通信するためのコンピュータ可読プログラムコードと、を備える、コンピュータプログラム。
- 15前記第1のTSMと前記メディエータTSMとの間に、前記第1のTSMから前記メディエータTSMへの前記セキュアエレメントの制御の転送を促進する、第1のマスターキーを作成するためのコンピュータ可読プログラムコードと、 前記メディエータTSMと前記第2のTSMとの間に、前記メディエータTSMから前記第2のTSMへの前記セキュアエレメントの制御の転送を促進する、第2のマスターキーを作成するためのコンピュータ可読プログラムコードと、をさらに備える、請求項14に記載のコンピュータプログラム。
- 16前記第1の一時キーが、前記第1のTSMと前記メディエータTSMとの間に設立された前記マスターキーにより暗号化される、請求項15に記載のコンピュータプログラム。
- 17前記第1のTSMと前記メディエータTSMとの間に設立された前記第1のマスターキーを使用して、前記第1の一時キーを解読するためのコンピュータ可読プログラムコードをさらに備える、請求項15に記載のコンピュータプログラム。
- 18前記第2の一時キーを前記第2のTSMに通信する前に、前記第2のTSMと前記メディエータTSMとの間に設立された前記マスターキーを使用して、前記第2の一時キーを暗号化するためのコンピュータ可読プログラムコードをさらに備える、請求項15に記載のコンピュータプログラム。
- 19前記第1および第2のマスターキーのうちの1つを作成するための前記コンピュータ可読プログラムコードが、 前記マスターキーの第1の部分を生成するためのコンピュータ可読プログラムコードと、 前記マスターキーの前記第1の部分をハードウェアセキュリティモジュールに入力するためのコンピュータ可読プログラムコードと、 前記マスターキーの第2の部分を生成するためのコンピュータ可読プログラムコードと、 前記マスターキーの前記第2の部分を前記ハードウェアセキュリティモジュールに入力するためのコンピュータ可読プログラムコードと、 前記ハードウェアセキュリティモジュール内の前記マスターキー部分を組み立てるためのコンピュータ可読プログラムコードと、 前記マスターキー部分を破壊するためのコンピュータ可読プログラムコードと、を備える、請求項15に記載のコンピュータプログラム。
- 20前記第1の一時キーを前記セキュアエレメントから削除するためのコンピュータ可読プログラムコードをさらに備える、請求項14に記載のコンピュータプログラム。
- 21前記アクセスキーを前記セキュアエレメントから削除するための前記コンピュータ可読プログラムコードが、前記アクセスキーを前記セキュアエレメントから削除する命令を前記セキュアエレメントに通信するためのコンピュータ可読プログラムコードを備える、請求項20に記載のコンピュータプログラム。
- 22前記セキュアエレメントとの前記セキュア通信チャネルを終了するためのコンピュータ可読プログラムコードをさらに備える、請求項14に記載のコンピュータプログラム。
- 23ユーザデバイス識別子を前記第2のTSMに通信するためのコンピュータ可読プログラムコードをさらに備え、前記ユーザデバイス識別子が、前記セキュアエレメントを識別するために前記第2のTSMにより使用されてよい、請求項14に記載のコンピュータプログラム。
- 24セキュアエレメントの制御を転送するためのシステムであって、前記システムが、記憶媒体と、 前記記憶媒体に保存されるコンピュータ実行可能命令を実行するように構成されるプロセッサと、を備え、前記コンピュータ実行可能命令が、 前記第1のTSMからメディエータTSMにセキュアエレメントの制御を転送するように、第1の一時キーを第1のTSMから受信するための命令と、 前記第1のTSMと前記メディエータTSMとの間に設立された前記第1のマスターキーを使用して、前記第1の一時キーを解読するための命令と、 前記セキュアエレメントとのセキュア通信チャネルを開始するための命令であって、前記セキュア通信チャネルが、前記メディエータTSMにより解読された前記第1の一時キーを使用して設立される、命令と、 前記第1の一時キーを前記セキュアエレメントから削除する命令を通信するための命令と、 第2の一時キーを作成するための命令と、 前記第2の一時キーを前記セキュアエレメントに通信するための命令と、 前記第2のTSMが前記セキュアエレメントにアクセスするように、前記第2の一時キーを前記第2のTSMに通信するための命令と、を備える、システム。
- 25前記コンピュータ実行可能命令が、 前記第1のTSMと前記メディエータTSMとの間に第1のマスターキーを作成するための命令であって、前記マスターキーが、前記第1のTSMから前記メディエータTSMへの前記セキュアエレメントの制御の転送を促進する、命令と、 前記メディエータTSMと前記第2のTSMとの間に第2のマスターキーを作成するための命令であって、前記マスターキーが、前記メディエータTSMから前記第2のTSMへの前記セキュアエレメントの制御の転送を促進する、命令と、をさらに備える、請求項24に記載のシステム。
- 26前記コンピュータ実行可能命令が、前記第2の一時キーを前記第2のTSMに通信する前に、前記メディエータTSMと前記第2のTSMとの間に設立された前記第2のマスターキーにより前記第2の一時キーを暗号化するための命令をさらに備える、請求項24に記載のシステム。
- 27前記第1および第2のマスターキーのうちの1つを作成するための前記コンピュータ実行可能命令が、 前記マスターキーの第1の部分を生成するための命令と、 前記マスターキーの前記第1の部分をハードウェアセキュリティモジュールに入力するための命令と、 前記マスターキーの第2の部分を生成するための命令と、 前記マスターキーの前記第2の部分を前記ハードウェアセキュリティモジュールに入力するための命令と、前記ハードウェアセキュリティモジュール内の前記マスターキー部分を組み立てるための命令と、 前記マスターキー部分を破壊するためのコンピュータ可読プログラムコードと、を備える、請求項24に記載のシステム。
- 28前記コンピュータ実行可能命令が、前記セキュアエレメントとの前記セキュア通信チャネルを終了するための命令をさらに備える、請求項24に記載のシステム。
- 29前記コンピュータ実行可能命令が、ユーザデバイス識別子を前記第2のTSMに通信するための命令をさらに備え、前記ユーザデバイス識別子が、前記セキュアエレメントを識別するように、前記第2のTSMにより使用されてよい、請求項24に記載のシステム。
Independent claims29
85 paragraphs, as filed
This disclosure generally relates to mobile communication devices, more specifically from the Trusted Service Manager "TSM", which users can use to complete secure commerce, communications, and other tasks. Regarding methods and systems that allow selection.
Related Applications This application is filed on June 14, 2012 in the United States, which claims priority over US Provisional Patent Application No. 61 / 604,503, entitled "Portable Secure Element," filed on February 28, 2012. Claim priority over Application No. 13 / 523,637, title "Portable Secure Element". The entire contents of the priority application mentioned above are fully incorporated herein by reference.
The current Near Field Communication (NFC) ecosystem is mounted on communication devices to provide a secure operating environment for financial commerce, transit ticketing, identification and authentication, physical security access, and other features. It relies on hardware components commonly referred to as "secure elements". Secure elements generally include an tamper-proof microprocessor, memory, and its own operating environment with the operating system. Among other things, Trusted Service Manager (TSM) installs, sets up, and customizes secure elements. The secure element has one or more access keys that are typically attached at the time of manufacture. The corresponding key is where the TSM can establish a cryptographically secure channel for the secure element for installation, setup, and customization of the secure element, while the device with the secure element is in the possession of the end user. As it is, it is shared by TSM. In this way, the secure element can remain secure even if the host CPU in the device fails.
<p> One flaw with current NFC systems is the existence of a tight connection between the secure element and the TSM. In the current deployment, only one TSM accesses the key of a particular secure element. Therefore, the end user can choose to set up secure element features provided by only one TSM. This TSM is typically selected by the device manufacturer. For example, a smartphone manufacturer may choose a smartphone TSM under the guidance of a mobile network operator (MNO) such as Sprint or Verizon who purchases the smartphone rather than the end user. Therefore, the TSM features available to the end user may not be within the end user's interests. As an example, the MNO is MasterCard or Bank of You may have a business relationship with only one payment provider, such as America. The TSM may allow the secure element to be set up with payment instructions from only one payment provider. Therefore, the end user cannot access the service from other payment providers such as VISA.</p>
<p> In one exemplary embodiment, the method and system for transferring control of a secure element between TSMs comprises a zone master key established between the TSMs that facilitates temporary key encryption during the transfer process. TSM agrees and establishes a zone master key before initiating the transfer of control. When the transfer of control is initiated, the first TSM establishes a communication channel with the secure element and deletes its key. The first TSM creates a temporary key. The temporary key is encrypted using the zone master key established between the first TSM and the second TSM, and the encrypted temporary key is communicated to the second TSM along with the device identifier. The second TSM uses the zone master key to decrypt the temporary key and the device identifier to identify the user device. The new TSM establishes a secure communication channel with the secure element and removes the temporary key. The new TSM then enters and stores the key in the secure element. In one exemplary embodiment, the first TSM may transfer control of the secure element to the mediator TSM, then transfer control of the secure element to the second TSM.</p><p> These and other aspects, objectives, features, and advantages of the exemplary embodiments will take into account the following detailed description of the exemplary embodiments illustrated, including optimal embodiments of carrying out the invention as presented herein. Then it will be apparent to those skilled in the art.</p>
<figref num="1">FIG. 5 is a block diagram showing an operating environment of a system for transferring control of a secure element using a zone master key according to an exemplary embodiment.</figref><figref num="2">FIG. 5 is a block diagram showing an operating environment of a system for transferring control of a secure element through a device according to an exemplary embodiment.</figref><figref num="3">FIG. 5 is a block flow diagram illustrating a method for transferring control of a secure element using a zone master key according to an exemplary embodiment.</figref><figref num="4">FIG. 6 is a block flow diagram showing a method for creating a zone master key according to an exemplary embodiment.</figref><figref num="5">FIG. 5 is a block flow diagram showing a method for transferring control of a secure element from TSM A to TSM B according to an exemplary embodiment.</figref><figref num="6">FIG. 5 is a block flow diagram showing a method for transferring control of a secure element through a device according to an exemplary embodiment.</figref><figref num="7">FIG. 5 is a block flow diagram illustrating a method for transferring control of a secure element from TSM A to mobile network operator TSM according to an exemplary embodiment.</figref><figref num="8">FIG. 5 is a block flow diagram illustrating a method for transferring control of a secure element from a mobile network operator TSM to TSM B according to an exemplary embodiment.</figref>
Overview An exemplary embodiment provides a method and system that allows a user to transfer control of a secure element from one TSM to another using a zone master key established between TSMs. TSM establishes an agreement on the transfer of control and creates a zone master key before initiating the transfer of control. The zone master key facilitates encryption of the temporary key used to transfer control from one TSM to another. In an exemplary embodiment, the zone master key is a shared symmetric key. Temporary key exchange can occur by encrypting the temporary key with a pre-shared symmetric key. In an alternative exemplary embodiment, the temporary key exchange may occur by utilizing the PKI infrastructure, where the temporary key is the source TSM with a public key exposed by the target TSM (eg, TSM B). It can be encrypted by (eg, TSM A). In an exemplary embodiment, secure element control is performed directly from TSM A using a temporary key encrypted with a zone master key established between TSM A and TSM B. May be transferred to B. In an alternative exemplary embodiment, control of the secure element is transferred from TSM A to an intermediary such as a mobile network operator (MNO) before being transferred to TSM B using one or more temporary keys. You can. The first temporary key may be encrypted with the zone master key established between the TSM A and MNO TSM, and the second temporary key may be the zone master established between the MNO TSM and TSM B. It may be encrypted by the key. In an alternative exemplary embodiment, a single temporary key may be used to transfer control from the TSM A to the MNO TSM and then to the TSM B.
When the transfer of control is initiated, TSM A receives and agrees to an instruction to transfer control to a second TSM, eg, TSM B or mediator TSM (eg, MNO TSM). TSM A establishes a communication channel with the secure element and deletes its key. TSM A creates a temporary key and stores it in a secure element. TSM A encrypts the temporary key with a zone master key established between TSM A and a second TSM. The encrypted temporary key is communicated to the second TSM along with the device identifier. The second TSM uses the zone master key to decrypt the temporary key and the device identifier to identify the user device.
The second TSM uses a temporary key to establish a communication channel with the secure element. When the communication channel is established, the second TSM removes the temporary key from the secure element. The second TSM then enters and stores the key in the secure element, thereby gaining control of the secure element. In an exemplary embodiment, the second TSM is the mediator TSM, then control is transferred to TSM B using the same method. In an exemplary embodiment, the mediator TSM is an MNO TSM. In an alternative exemplary embodiment, the mediator TSM is a third party entity such as Google. In yet another alternative exemplary embodiment, Mediator TSM is an operating system such as Android or an operating system provider.
The functionality of the exemplary embodiments will be described in more detail below and will be read in conjunction with the drawings showing the program flow. System architecture
Illustrative embodiments are described in detail herein with reference to the drawings in which similar numbers indicate similar (but not necessarily the same) elements throughout the drawings.
FIG. 1 is a block diagram showing an operating environment 100 for a system for transferring control of secure element 126 using a zone master key according to an exemplary embodiment. As shown in FIG. 1, the exemplary operating environment 100 includes a user device system 120 and two or more secure service provider systems 140 configured to communicate with each other over one or more networks 130. Be prepared.
Network 130 comprises telecommunications means through which network devices (devices 120 and 140) can exchange data. For example, network 130 includes a storage area network (SAN), a personal area network (PAN), a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN"". ), Wireless Local Area Network (WLAN), Virtual Private Network (VPN), Intranet, Internet, Bluetooth®, NFC, or Signals, Data, and / or Messages (Generally referred to as Data) Can be implemented as any other suitable architecture or system that facilitates communication, or may be part of them. In an alternative exemplary embodiment, the secure communication channel 130 can include a cellular network.
In an exemplary embodiment, the user device system 120 is via an electronic, magnetic, or radio frequency electromagnetic field between the device 120 and another device, eg, a smart card (not shown) or a reader (not shown). Can refer to smart devices that can communicate with each other. In an exemplary embodiment, the user device 120 has processing power such as storage capacity / memory and one or more applications 122 capable of performing specific functions. In an exemplary embodiment, the non-contact device 120 includes an operating system (not shown) and a user interface 121. The exemplary contactless device 120 includes smartphones, mobile phones, personal digital assistants (PDAs), mobile computing devices (eg, netbooks, tablets, and iPads), laptops, and other devices. It also has processing functionality and user interface functionality in the case of.
The non-contact device 120 also comprises a secure element 126 that may reside within a removable smart chip or secure digital (SD) card or may be embedded within a fixed chip on the device 120. In one exemplary embodiment, the subscriber identification module (SIM) card may be capable of hosting a secure element 126, eg, an NFC SIM card. The secure element 126 resides on the device 120 and is stored within the secure element while a software application (not shown) accessible to the device user securely interacts with certain features within the secure element 126. Allows you to protect your information. The secure element 126 may include an application (not shown) that runs on it to perform the functions described herein.
The secure element 126 includes components typical of smart cards such as cryptographic processors and random generators. In an exemplary embodiment, the secure element 126 is a Smart MX type NFC within a highly secure system on a chip controlled by a smart card operating system such as the JAVA® Card Open Platform (JCOP) operating system. It is equipped with a controller 124. In another exemplary embodiment, the secure element 126 is configured to include a non-EMV non-contact smart card as an optional implementation.
The secure element 126 communicates with the controller 124 and the application 122 within the user device 120. In an exemplary embodiment, the secure element 126 may store encrypted user information so that only trusted applications can access the stored information. Controller 124 interacts with a secure key 127 encrypted application for decryption and mounting within secure element 126.
In an exemplary embodiment, controller 124 is an NFC controller. The NFC controller sends and receives data, identifies the reader or smart card, performs authentication and encryption functions, and according to NFC specific procedures, the user device 120 listens to the transfer from the reader / smart card, or the user device 120 May be able to instruct how to configure various power saving modes. In an alternative exemplary embodiment, the controller 124 is a Bluetooth® link controller or Wi-Fi controller capable of performing similar functions.
Application 122 is a program, function, routine, applet, or similar entity that resides on user device 120 and performs its operations there. For example, application 122 is one of offline payment applications, digital wallet applications, coupon applications, loyalty card applications, other value-added applications, user interface applications, or other suitable applications running on the contactless device 120. It may be one or more. In addition, Secure Element 126 uses secure contactless software applications such as offline payments or other payment applications, Secure Forms of Application 122, authentication applications, payment provisioning applications, or other secure functionality of Secure Element. Suitable applications may be included.
The user device 120 communicates with the reader / smart card via the antenna 128. In an exemplary embodiment, when the user device application 122 is launched and prioritized, the controller 124 is notified of the user device 120's readiness for commerce. The controller 124 outputs the radio signal through the antenna 128 or listens to the radio signal from the reader / smart card.
Secure Service Provider 140 acts as a mediator that helps service providers securely distribute and manage applications and services, such as NFC contactless application services. Illustrative secure service providers 140 are Gemalto and First Includes Data. The trusted service manager (TSM) 145 of the secure service provider 140 typically hosts the application and mounts and sets up the application on top of the secure element 126 of the user device. Each TSM145 can receive, store, and utilize key 149 of secure element 126 residing on user device 120. In an exemplary embodiment, one or more keys 149 are stored within a hardware security module (HSM). Having the key 149 allows the TSM145 to access the secure element 126 via a secure encrypted communication channel to mount, set up, and customize the application within the secure element 126. In an exemplary embodiment, the key 149 allows the secure element 126 to be accessed and controlled only by the TSM 147 having the current access key 149. For example, if control of secure element 126 is transferred from TSM A147A to TSM B147B, only TSM B147 will be TSM. The B key 149B can be used to access and control secure element 126. TSM A key 149A does not allow TSM A145A access to and control of secure element 126.
In one exemplary embodiment, the secure service provider 140 bypasses the controller 124 residing on the user device 120 when communicating with the secure element 126. For example, in one UICC / SIM secure element, the secure service provider 140 communicates with the secure element 126 via a wireless CPU (not shown) mounted on the user device 120. Thus, in one exemplary embodiment, the involvement of controller 124 during the setup of the application on secure element 126 may be optional. In one exemplary embodiment, the host CPU (not shown) and the wireless CPU (not shown) interact with each other to coordinate access control to the secure element 126.
FIG. 2 is a block diagram showing an operating environment of a system for transferring control of a secure element through a device according to an alternative exemplary embodiment. The exemplary operating environment 200 includes two or more secure service providers that include many of the same components as system 100 and are configured to communicate with the user device system 120 over one or more networks 140. Includes system 140. The exemplary operating environment 200 also includes a mobile network operator (MNO) system 210.
In an exemplary embodiment, the MNO system 210 is a third party system that acts as a mediator while transferring control from one TSM145 to another. An exemplary MNO210 comprises a TSM215 and one or more keys 219. The TSM215 and key 219 function in a manner similar to the TSM145 and key 149 residing on the secure service provider 140 described above. In an exemplary embodiment, the user device 120 accesses network 130 via the MNO 210. Illustrative MNO210 includes Verizon, Sprint, and AT & T. The MNO210 provides network 130 access to user device 120 via a mobile network (not shown) such as a 3G or 4G mobile communication network. In an alternative exemplary embodiment, the user device 120 can connect to an internet provider, NFC, or Bluetooth® to access network 130 via other mechanisms such as Wi-Fi. ..
As described herein, the MNO TSM215 is a mediator TSM. In an exemplary embodiment, the mediator TSM is the MNO TSM215. In an alternative exemplary embodiment, Mediator TSM is a third party entity such as Google or an operating system / operating system provider such as Android. In this exemplary embodiment, the MNO system 210 can communicate with the user device using any network 130, and the mediator TSM215 can communicate with the user device 120 over Wi-Fi.
The components shown in FIGS. 1-2 are further detailed below with reference to the methods shown herein. System process
FIG. 3 is a block flow diagram illustrating a method for transferring control of secure element 126 using a zone master key according to an exemplary embodiment. Method 300 is described with reference to the components shown in FIG.
In block 305, TSM A145A and TSM B145B create a zone master key to facilitate the transfer of control. The method of creating a zone master key is described in more detail below with reference to the method described in FIG.
FIG. 4 is a block flow diagram showing a method for creating a zone master key according to an exemplary embodiment, as referenced in block 305 of FIG. Method 305 is described with reference to the components shown in FIG.
At block 410, TSM A145A and TSM B145B agree to create a key exchange zone. In an exemplary embodiment, consent between the TSM A145A and the TSM B145B occurs offline before initiating the transfer of control of the secure element 126 residing on the user device 120. For example, TSM A145A and TSM B145B may create an agreement to allow transfer of control of secure element 126, and TSM A145A and TSM B145B create a zone master key to facilitate such transfer. I agree with you. In an exemplary embodiment, the zone master key may be used to facilitate transfer from TSM A145A to TSM B145B and vice versa for multiple user devices at any time after key creation.
In block 420, TSM A145A and TSM B145B generate the first part of the shared zone master key. In an exemplary embodiment, the zone master key is created within three separate parts and assembled by the HSM 147. In an alternative exemplary embodiment, the zone master key is created within a single part. In this embodiment, the method described in blocks 440-470 may be omitted. In yet another alternative exemplary embodiment, the zone master key is created within three or more parts. In this embodiment, the methods described in blocks 420-470 may be repeated as needed. In yet another alternative exemplary embodiment, the zone master key is created within two parts. In this embodiment, the method described in blocks 460-470 may be omitted.
At block 430, the first part of the zone master key is entered into the HSM 147 of the TSM A145A and TSM B145B. In an exemplary embodiment, the zone master key portion is input to the HSM147A of the TSM A145A and the HSM147B of the TSM B145B. In an exemplary embodiment, the TSM145 inputs zone master key parts and stores those parts within the HSM147. In an exemplary embodiment, once all parts of the zone master key are stored within the HSM147, the HSM147 assembles those parts.
In block 440, TSM A145A and TSM B145B generate a second part of the shared zone master key.
At block 450, the second part of the zone master key is entered into the HSM 147 of the TSM A145A and TSM B145B. In an exemplary embodiment, the TSM145 inputs zone master key parts and stores those parts within the HSM147. In an exemplary embodiment, when all parts of the zone master key are stored within the HSM147, the HSM147 assembles those parts.
In block 460, TSM A145A and TSM B145B generate a third part of the shared zone master key. In an exemplary embodiment, the zone master key is generated within three parts.
At block 470, the third part of the zone master key is entered into the HSM 147 of the TSM A145A and TSM B145B. In an exemplary embodiment, the TSM145 inputs zone master key parts and stores those parts within the HSM147. In an exemplary embodiment, when all parts of the zone master key are stored within the HSM147, the HSM147 assembles those parts.
At block 480, the zone master key is assembled within the HSM 147 of the TSM A145A and TSM B145B. In an exemplary embodiment, three parts of the zone master key are created, entered, and stored within the HSM 147 of the TSM A145A and TSM B145B and assembled to create a single key.
In block 490, the zone master key part is destroyed. In an exemplary embodiment, when the zone master key portion is assembled and a single key is created, the portion entered into the HSM 147 of the TSM A145A and TSM B145B is removed from the HSM 147 and destroyed, respectively.
From block 490, the method proceeds to block 310 in FIG.
Returning to FIG. 3, in block 310, the control of the secure element 126 resident on the user device 120 is controlled by the TSM A145A. In an exemplary embodiment, the TSM A145A can use the access key 149A to access and control the secure element 126. In an exemplary embodiment, control of secure element 126 may be by TSM B145B and control is transferred from TSM B145B to TSM A145A.
At block 315, secure element control 126 is transferred from TSM A145A to TSM B145B. The method for transferring control of the secure element 126 from the TSM A145A to the TSM B145B is described in more detail below with reference to the method described in FIG.
FIG. 5 is a block flow diagram showing a method for transferring control of secure element 126 from TSM A145A to TSM B145B according to an exemplary embodiment, as referenced in block 315 of FIG. Method 315 is described with reference to the components shown in FIG.
At block 505, the user (not shown) initiates the transfer of control of secure element 126 from TSM A145A to TSM B145B. In an exemplary embodiment, the user may access the application 122 residing on the user device through the user interface 121 and initiate a transfer of control. In an alternative exemplary embodiment, the user may initiate a transfer of control by registering a financial card managed by secure service provider B140B within the user's digital wallet application. In yet another alternative exemplary embodiment, the transfer of control may be initiated automatically when the user attempts to make a financial payment using the user device 120, and the financial card is managed by secure service provider B140B. Will be done.
At block 510, application 122 residing on user device 120 receives the user's request to transfer control of secure element 126. In an exemplary embodiment, application 122 is a secure element 126 portability service application.
At block 515, application 122 authenticates the transfer of control from TSM A145A to TSM B145B and instructs TSM A145A to transfer control of secure element 126 to TSM B145B. In an exemplary embodiment, the secure element portability service application 122 communicates instructions to the TSM A145A over network 130.
At block 520, TSM A145A receives and agrees to transfer control of secure element 126 to TSM B145B. In an exemplary embodiment, TSM A145A has previously established an agreement with TSM B145B regarding the transfer of control of secure element 126 between TSMs. TSM has previously created a zone master key to facilitate the transfer of such controls. In an exemplary embodiment, when the TSM A145A receives an instruction to transfer control, it confirms the existence of a transfer agreement between TSMs before agreeing to transfer control.
At block 525, the TSM A145A initiates a secure communication channel with the secure element 126 using the existing access key of the TSM A145A stored within the secure element 126. In an exemplary embodiment, the secure communication channel goes through network 130.
At block 530, TSM A145A removes all TSM A key 149A from secure element 126. In an exemplary embodiment, removing the TSM A key 149A from the secure element 126 ensures that the TSM A145A no longer has control or access to the secure element 126.
At block 535, TSM A145A creates a temporary key. In an exemplary embodiment, the temporary key is different from the TSM A key 149 previously deleted from secure element 126. In an exemplary embodiment, the temporary key provides a transfer of control from one TSM145 to another.
At block 540, the TSM A145A enters a temporary key into secure element 126. In an exemplary embodiment, the TSM A145A inputs and stores a temporary key within the secure element 126 to facilitate the transfer of control to the TSM B145B.
At block 545, the TSM A145A encrypts the temporary key with the zone master key established between the TSM A145A and the TSM B145B. In an exemplary embodiment, the zone master key was shared by TSM A145A and TSM B145B and created in block 305.
At block 550, the TSM A145A communicates to the TSM B145B a temporary key encrypted using the zone master key established between the TSM A145A and the TSM B145B, along with the user device 120 identifier. In an exemplary embodiment, the user device 120 identifier may be used by the TSM B145B to identify the user device 120 and the secure element 126 before accessing the secure element 126 to establish control.
The method then proceeds to block 320 of FIG.
Returning to FIG. 3, at block 320, the TSM B145B inputs a temporary key encrypted with the zone master key received from the TSM A145A into the HSM 147B. In an exemplary embodiment, the TSM B145B inputs and stores a temporary key encrypted with a zone master key into the HSM 147B.
At block 325, the TSM B145B decrypts the temporary key using the zone master key established between the TSM A145A and the TSM B145B.
At block 330, the TSM B145B uses the device identifier communicated by the TSM A145A to identify the user device 120. In an exemplary embodiment, the TSM B145B contacts the MNO 210 and uses the device identifier to identify the user device 120. In an exemplary embodiment, the MNO 210 facilitates identification of the user device 120 and the secure element 126.
At block 335, TSM B145B uses a temporary key to establish a secure communication channel with secure element 126. In an exemplary embodiment, the secure communication channel goes through network 130.
At block 340, TSM B145B removes the temporary key from secure element 126 and enters TSM B key 149B. In an exemplary embodiment, the TSM B145B inputs the TSM B key 149B and stores it in the secure element 126 to gain control of the secure element 126. In an exemplary embodiment, once the temporary key is removed from the secure element by the TSM B145B, the TSM A145A can no longer access or control the secure element.
At block 345, TSM B145B gains control of secure element 126. In an exemplary embodiment, the communication channel is terminated at any suitable time after the TSM B145B inputs and stores the TSM B key 149B into the secure element.
From block 345, method 300 ends.
FIG. 6 is a block flow diagram showing a method for transferring control of the secure element 126 through the device according to an exemplary embodiment. Method 600 is described with reference to the components shown in FIG.
In block 605, the MNO TSM215 establishes a separate zone master key with the TSM A145A and TSM B. In an exemplary embodiment, block 605 of FIG. 6 is described above with reference to block 305 of FIGS. 3-4, except that the MNO TSM215 performs method 305 individually with each of TSM A145A and TSM B145B. Can be done in the same style. In an exemplary embodiment, the MNO TSM215 may include an MNO, a third party entity, an operating system provider, or another TSM that facilitates the transfer of control of the secure element 126 from one TSM145 to another. Is.
In block 610, the TSM A145A controls the secure element 126 that resides on the user device 120. In an exemplary embodiment, the TSM A145A can use the access key 149A to access and control the secure element 126. In an exemplary embodiment, control of secure element 126 may be by TSM B145B and control is transferred from TSM B145B to TSM A145A.
At block 615, control of secure element 126 is transferred from the TSM A145A to the MNO TSM 215. The method 615 for transferring control of the secure element 126 from the TSM A145A to the MNO TSM215 is further detailed below with reference to the method described in FIG.
FIG. 7 is a block flow diagram showing a method for transferring control of the secure element 126 from the TSM A145A to the MNO TSM 215 according to an exemplary embodiment, as referred to in block 615 of FIG. Method 615 is described with reference to the components shown in FIGS.
In an exemplary embodiment, blocks 505-550 of FIG. 7 refer to blocks 505-550 of FIG. 5, except that the TSM A145A transfers control of the secure element 126 to the MNO TSM215 instead of the TSM B145B. Can be done in the manner described above. In an exemplary embodiment, the transfer of control from the TSM A145A to the MNO TSM215 is a zone master key established between the TSM A145A and the MNO TSM215 according to the method described above with reference to blocks 505-550 of FIG. Prompted by the creation of a first temporary key encrypted by.
From block 550 in FIG. 7, method 615 proceeds to block 620 in FIG.
Returning to FIG. 6, at block 620, control of the secure element 126 is transferred from the MNO TSM215 to the TSM B145B. The method 620 for transferring the secure element 126 from the MNO TSM215 to the TSM B145B is further detailed below with reference to the method described in FIG.
FIG. 8 is a block flow diagram showing a method for transferring control of the secure element 126 from the MNO TSM215 to the TSM B145B according to an exemplary embodiment, as referred to in block 620 of FIG. Method 620 is described with reference to the components shown in FIGS.
In block 805, the MNO TSM215 decrypts the first temporary key using the zone master key established between the MNO TSM215 and the TSM A145A.
In block 810, the MNO TSM215 uses the device identifier to identify the user device 120.
In an exemplary embodiment, blocks 525-550 of FIG. 8 refer to blocks 525-550 of FIG. 5, except that the MNO TSM215 transfers control of the secure element 126 to the TSM B145B instead of the TSM A145A. And can be done in the manner described above. In an exemplary embodiment, the transfer of control from the MNO TSM215 to the TSM B145B is a zone master key established between the MNO TSM215 and the TSM B145B according to the method described above with reference to blocks 525-550 of FIG. Prompted by the creation of a second temporary key encrypted by.
From block 550 in FIG. 8, method 620 proceeds to block 625 in FIG.
Returning to FIG. 6, at block 625, the TSM B145B decrypts the second temporary key using the zone master key established between the MNO TSM 215 and TSM B145B.
At block 630, the TSM B145B identifies the user device 120 using the device identifier communicated by the MNO TSM215.
At block 635, TSM B145B uses a second temporary key to establish a secure communication channel with secure element 126. In an exemplary embodiment, the secure communication channel goes through network 130.
At block 640, TSM B145B removes the second temporary key from secure element 126. In an exemplary embodiment, the MNO TSM215 can no longer access or control the secure element once the second temporary key has been removed from the secure element 126 by the TSM B145B.
In block 645, TSM B145B inputs TSM B key 149B. In an exemplary embodiment, the TSM B145B inputs the TSM B key 149B and stores it in the secure element 126 to gain control of the secure element 126.
At block 650, TSM B145B gains control of secure element 126. In an exemplary embodiment, the communication channel is terminated at any suitable time after the TSM B145B inputs and stores the TSM B key 149B into the secure element.
From block 650, method 600 ends. Overview
The user may be allowed to limit the behavior of the features disclosed herein or to act in another way. For example, the user may be given the opportunity to select or exclude the collection or use of certain data or the activation function of certain features. In addition, the user may be given the opportunity to change the way in which the feature is used, including situations in which the user may have privacy concerns. The user may be provided with instructions to inform the user about the policy regarding the use of information including personal information and the manner in which each user may influence the use of such information. Therefore, the information may be used to benefit the user, as appropriate, through the receipt of relevant advertisements, suggestions, or other information, without risking disclosure of personal information or the user's ID.
One or more of the exemplary embodiments may include a computer program that performs the functions described and exemplified herein, which computer program executes instructions stored on a machine-readable medium and executes the instructions. Implemented within a computer system that includes a processor. However, it should be clear that there may be many different ways to implement exemplary embodiments in computer programming, and exemplary embodiments should be considered as being limited to any set of computer program instructions. is not it. In addition, a seasoned programmer would be able to write such a computer program to implement the embodiment based on the attached flowcharts and related instructions in the application. Therefore, disclosure of a particular program code instruction set is not considered necessary for a proper understanding of how to make and use exemplary embodiments. Moreover, any reference to an action performed by a computer should not be considered as performed by a single computer, as multiple computers perform that operation.
The exemplary systems, methods, and blocks described in the aforementioned embodiments are exemplary, and in alternative embodiments, certain blocks are performed in different order or parallel to each other without departing from the scope and gist of the invention. It can be done by, or omitted altogether, and / or it can be done in combination with different exemplary methods, and / or some additional block can be done. Therefore, such alternative embodiments are included in the inventions described herein.
The present invention can be used with computer hardware and software that perform the methods and processing functions described above. As will be appreciated by those skilled in the art, the systems, methods, and procedures described herein can be embodied in programmable computers, computer executable software, or digital circuits. The software may be stored on a computer-readable medium. For example, computer-readable media may include floppy (registered trademark) disks, RAM, ROM, hard disks, removable media, flash memory, memory sticks, optical recording media, optical magnetic recording media, CD-ROMs, and the like. Digital circuits can include integrated circuits, gate arrays, building block logic, field programmable gate arrays (FPGA), and the like.
Specific embodiments of the present invention have been described in detail above, but this description is for illustration purposes only. Various modifications to the disclosed aspects of the exemplary embodiments, and corresponding equivalent blocks and components, in addition to those described above, without departing from the spirit and scope of the invention as defined in the following claims. , Can be made by one of ordinary skill in the art, the scope of which follows the broadest interpretation to include such modifications and equivalent structures.
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11893549B2 | Cited by | United States of America | Applicant |
| JP2002304610A | Cites | Japan | Examiner |
| WO2009040715A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| WO2010120222A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| US2010291904A1 | Cites | United States of America | Examiner |
| US2011087610A1 | Cites | United States of America | Examiner |
| WO2012052056A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| JP2002304610A | Cites | Japan | – |
| WO2009040715A1 | Cites | World Intellectual Property Organization (WIPO) | – |
| WO2010120222A1 | Cites | World Intellectual Property Organization (WIPO) | – |
| US20100291904A1 | Cites | United States of America | – |
| US20110087610A1 | Cites | United States of America | – |
| WO2012052056A1 | Cites | World Intellectual Property Organization (WIPO) | – |
| GlobalPlatform’s Proposition for NFC Mobile:Secure Element Management and Messaging,GlobalPlatform_NFC_Mobile_White_Paper,GlobalPlatform Inc.,2009年 4月,URL,http://www.paymentscardsandmobile.com/research/reports/GlobalPlatform_NFC_Mobile_White_Paper.pdf | Non-patent | – | – |
| 菅野利博,他,進化するおサイフケータイ―ドコモUIMカードへのNFC(Type A/B)対応サービス発行のしくみ―,NTT DOCOMOテクニカル・ジャーナル,Vol.21 No.1,URL,http://www.nttdocomo.co.jp/binary/pdf/corporate/technology/rd/technical_journal/bn/vol21_1/vol21_1_022jp.pdf | Non-patent | – | – |
| 中道 理,NFCは“おサイフ”を超えて,日経エレクトロニクス 第1052号 NIKKEI ELECTRONICS,日本,日経BP社 Nikkei Business Publications,Inc.,2011年 3月21日,第2部<海外動向> セキュア・エレメントの争奪へ Apple,Googleも参戦 | Non-patent | – | – |
| JPN6013044002; 'GlobalPlatform's Proposition for NFC Mobile:Secure Element Management and Messaging' GlobalPlatform_NFC_Mobile_White_Paper , 200904, GlobalPlatform Inc. | Non-patent | – | Examiner |
| JPN6013044005; 菅野利博,他: '進化するおサイフケータイ-ドコモUIMカードへのNFC(Type A/B)対応サービス発行のしくみ-' NTT DOCOMOテクニカル・ジャーナル Vol.21 No.1 | Non-patent | – | Examiner |
| JPN6013044007; 中道 理: 'NFCは"おサイフ"を超えて' 日経エレクトロニクス 第1052号 NIKKEI ELECTRONICS , 20110321, 日経BP社 Nikkei Business Publications,Inc. | Non-patent | – | Examiner |
| CSND201100086007; 中道 理: 'NFCは"おサイフ"を超えて' 日経エレクトロニクス 第1052号 NIKKEI ELECTRONICS , 20110321, 日経BP社 Nikkei Business Publications,Inc. | Non-patent | – | Examiner |
24 members in 8 offices
Members24
| Document | Office | Kind | |
|---|---|---|---|
| US8385553B1 | United States of America | B1 | |
| AU2013202956B1 | Australia | B1 | |
| AU2013202956B8 | Australia | B8 | |
| AU2013207623A1 | Australia | A1 | |
| CA2811215A1 | Canada | A1 | |
| US2013223623A1 | United States of America | A1 | |
| WO2013130414A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20130108590A | Republic of Korea | A | |
| EP2661839A1 | European Patent Office (EPO) | A1 | |
| US8625800B2 | United States of America | B2 | |
| CN103518348A | China | A | |
| KR20140019875A | Republic of Korea | A | |
| AU2013207623B2 | Australia | B2 | |
| EP2661839A4 | European Patent Office (EPO) | A4 | |
| KR101404211B1 | Republic of Korea | B1 | |
| JP5519086B1This record | Japan | B1 | |
| JP2014518027A | Japan | A | |
| JP2014150565A | Japan | A | |
| KR101463587B1 | Republic of Korea | B1 | |
| CN103518348B | China | B | |
| EP2661839B1 | European Patent Office (EPO) | B1 | |
| CA2811215C | Canada | C | |
| CN104992319A | China | A | |
| CN104992319B | China | B |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of nameJAPANESE INTERMEDIATE CODE: R313533S533 | S533 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD |
Numbers
- Publication
- 5519086
- Application
- 2014502707
Titles2
- Japanese
- ポータブルセキュアエレメント
- English
- Portable secure element
Classification
- CPC, 12
- G06Q20/027
- G06F21/30
- H04L9/0861
- G06Q20/3227
- H04L9/0822
- H04L9/0877
- H04L63/062
- H04L2463/062
- H04W12/04
- H04W12/35
- G06F21/35
- G06F21/44
- IPC, 1
- H04L9 08