Method, system, trusted service manager, service provider and memory element for managing access rights for trusted applications

US9608989B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9608989-B2
Application numberUS-67987408-A
CountryUS
Kind codeB2
Filing dateSep 22, 2008
Priority dateSep 27, 2007
Publication dateMar 28, 2017
Grant dateMar 28, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for granting trusted applications (SP 1 _WL) of a Service Provider (SP 1 , SP 2 )access to applications (appSP 1.1 , appSP 1.2 ; appSP 2.1 ) of that Service Provider (SP 1 , SP 2 ) that have been stored in a secure element (SE) comprises: the Service Provider (SP 1 , SP 2 ) transmits a request (REQ 1 ) for granting access to its applications to a Trusted Service Manager (TSM); the Trusted Service Manager (TSM) generates an access right code (AC 1 ) and transmits it to both the Service Provider (SP 1 , SP 2 ) and a service manager (SM) in the secure element (SE); the Service Provider (SP 1 , SP 2 ) generates the trusted application (SP 1 _WL), provides it with the access right code (AC 1 ) and sends it to the secure element (SE); the trusted application (SP 1 _WL) connects to the service manager (SM) with the access right code (AC 1 ) whereupon the service manager (SM) grants the wallet (SP 1 _WL) access to the applications (appSP 1.1 , appSP 1.2 ; appSP 2.1 ).

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for granting a wallet of a Service Provider access to applications of the Service Provider which have been stored in a secure element, wherein the secure element comprises a service manager configured to restrict access of wallets to stored applications, comprising: at the Service Provider, transmitting a request to a Trusted Service Manager which controls the service manager in the secure element for granting the Service Provider access to the applications of the Service Provider; at the Trusted Service Manager, generating an access right code and transmitting the access right code to both the Service Provider and the service manager in the secure element; at the Service Provider, generating the wallet, providing the wallet with the access right code and sending the wallet to the secure element, wherein the wallet, when intending to access the applications of the Service Provider in the secure element connects to the service manager with the access right code whereupon the service manager grants the wallet access to the applications of the Service Provider. 2. The method as claimed in claim 1 , wherein the Service Provider and the Trusted Service Manager communicate with each other via a computer network, using HTTPS. 3. The method as claimed in claim 1 , wherein at least one of the Trusted Service Manager and the Service Provider communicate with the secure element being arranged in a mobile communication device via an Over-The-Air service of a Mobile Network Operator. 4. A telecommunication system comprising: at least one Service Provider; at least one Trusted Service Manager; and a plurality of mobile communication devices being equipped with secure elements to store applications of the Service Provider, the secure element granting a wallet of the Service Provider access to the applications of the Service Provider, wherein the secure element comprises a service manager, wherein the Trusted Service Manager sends an access right code to the Service Provider and one of the secure elements, wherein the Service Provider comprises a computing unit configured to: transmit a request to a Trusted Service Manager which controls the service manager in the secure element for granting the Service Provider access to the applications of the Service Provider, receive the access right code from the Trusted Service Manager, generate a wallet with the access right code, and send the wallet and the access right code to the secure element. 5. The system as claimed in claim 4 , wherein the Service Provider and the Trusted Service Manager communicate with each other via a computer network using HTTPS. 6. The system as claimed in claim 4 , wherein at least one of the Trusted Service Manager and the Service Provider communicate with the secure element (SE) arranged in a mobile communication device via an Over-The-Air service of a Mobile Network Operator using a Short Message Service. 7. The system as claimed in claim 4 , wherein the secure element is a SmartMX device. 8. A Trusted Service Manager comprising: a computing unit being adapted to receive from a Service Provider a request for granting the Service Provider access to applications of the Service Provider stored in a secure element, wherein the secure element comprises a service manager that hinders access to stored applications, wherein the Trusted Service Manager is adapted to generate an access right code and to transmit the access right code to both the Service Provider and the service manager in the secure element. 9. The Trusted Service Manager as claimed in claim 8 , wherein the Trusted Service Manager communicates with the Service Provider via a computer network, using HTTPS. 10. The Trusted Service Manager as claimed in claim 8 , wherein the Trusted Service Manager communicates with the secure element arranged in the mobile communication device via an Over-The-Air service of a Mobile Network Operator, using Short Message Service. 11. A Service Provider comprising: a computing unit being adapted to store applications in a secure element that is arranged in a mobile communication device, wherein the Service Provider is further adapted to transmit a request for granting access to applications of the Service Provider in the secure element to a Trusted Service Manager, to receive an access right code from the Trusted Service Manager, to generate a wallet, to provide it with the access right code, and to send the access right code to the secure element. 12. The Service Provider as claimed in claim 11 , wherein the Service Provider communicates with the Trusted Service Manager via a computer network, using HTTPS. 13. The Service Provider as claimed in claim 11 , wherein the Service Provider communicates with the secure element arranged in the mobile communication device via an Over-The-Air service of a Mobile Network Operator, using Short Message Service. 14. A secure element comprising an arithmetic-logic unit and a non-transitory memory, the non-transitory memory storing a plurality of applications, the non-transitory memory further comprising instructions for: receiving a first access right code from a Trusted Services Manager; storing the first access right code in association with a set of the applications, the first access right code restricting access to the set of the applications; connecting to a wallet that is installed in the secure element; receiving from the wallet a second access right code; comparing the second access right code to the stored first access right code; and if the access right codes match, granting the wallet access to the set of applications installed in the secure element which are restricted by the first access right code. 15. The secure element according to claim 14 , being configured as a SmartMX device. 16. The secure element of claim 14 , wherein the wallet is received from a Service Provider.

Assignees

Inventors

Classifications

  • communicating wirelessly · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

  • for accessing specific resources, e.g. using Kerberos tickets · CPC title

  • RFID or NFC payments by means of M-devices · CPC title

  • to features or functions of an application · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9608989B2 cover?
A method for granting trusted applications (SP 1 _WL) of a Service Provider (SP 1 , SP 2 )access to applications (appSP 1.1 , appSP 1.2 ; appSP 2.1 ) of that Service Provider (SP 1 , SP 2 ) that have been stored in a secure element (SE) comprises: the Service Provider (SP 1 , SP 2 ) transmits a request (REQ 1 ) for granting access to its applications to a Trusted Service Manager (TSM); the Trus…
Who is the assignee on this patent?
Corda Alexandre, Bobo Luis, Azoulai Jonathan, and 1 more
What technology area does this patent fall under?
Primary CPC classification H04L63/0853. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 28 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).