Systems and methods for initialization and activation of secure elements
Abstract
Disclosed herein are secure transaction systems having secure elements that are initialized and activated independent from each other. The secure element is first initialized to make the secure element turn to a state in which the secure element can be packaged, sold within retail stores, and then injected with encryption keys. The initialization process of the secure element formulates the secure element to ensure trust between the secure elements and secure element activation servers. The process of independently initializing and activating the secure elements while still addressing the security protocols allows the secure element to be packaged and sold within retail stores after initialization, and then activating the secure element at a later date and time when the secure element is ready to be used by a merchant.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for initialization and activation of a secure element for use in a terminal device, the method comprising:
transmitting, by at least one at least one service provider server, a service provider certificate, a set of encryption keys, and one or more attributes associated with the secure element to a processor of the secure element; receiving, by the at least one service provider server, an activation request from the secure element, the set of encryption keys, and the one or more attributes associated with the secure element; authenticating, by the at least one service provider server, an identity of the secure element by:
extracting a public key from the secure element, the public key corresponding to the service provider certificate and the set of encryption keys, and
determining whether the extracted public key corresponds to the service provider certificate;
generating, by the at least one service provider server, a session with the secure element based on mutual authentication with the secure element using at least the service provider certificate; and in response to the processor of the secure element validating an activation certificate, loading, by the at least one service provider server, a master key and a working key into a memory of the secure element.
2 . The method of claim 1 , further comprising:
generating, by the processor of the secure element, a public key corresponding to the service provider certificate and the set of encryption keys;
3 . The method of claim 1 , further comprising:
validating, by the processor of the secure element, the activation certificate by determining that the activation certificate is associated with a certification authority server.
4 . The method of claim 1 , wherein the service provider server transmits the activation certificate to the secure element.
5 . The method of claim 1 , further comprising:
determining, by the at least one service provider server, whether a firmware of a censor of the secure element stored in the memory of the secure element needs to be updates upon establishing a communication with the secure element.
6 . The method of claim 1 , wherein the one or more attributes associated with the secure element comprises a manufacture ID of a vendor of the secure element, whereby the at least one service provider server uses the one or more attributes to authenticate the secure element by comparing the manufacture ID of the vendor of the secure element with a manufacture ID of the vendor of the secure element stored within a database.
7 . The method of claim 1 , further comprising uploading, by the at least one service provider server, a firmware of a vendor of the secure element into the memory of the secure element.
8 . The method of claim 1 , wherein the activation certificate comprises a subject field with a one or more parameters associated with a service provider server, whereby the processor of the secure element validates the activation certificate by determining whether the subject field comprises a domain address associated with a certification authority server.
9 . The method of claim 1 , wherein the secure element is a printed circuit board of the terminal device, wherein the terminal device is selected from a group consisting of a card reader, a mobile phone, a vending machine, a wearable device, or an internet of things (IOT) device.
10 . The method of claim 1 , wherein the secure element is detachably connected to the terminal device.
11 . A system comprising a server comprising a processor and a non-transitory computer-readable medium containing instructions that when executed by the processor causes the processor to perform operations comprising:
transmitting a service provider certificate, a set of encryption keys, and one or more attributes associated with the secure element to a processor of the secure element; receiving an activation request from the secure element, the set of encryption keys, and the one or more attributes associated with the secure element; authenticating an identity of the secure element by:
extracting a public key from the secure element, the public key corresponding to the service provider certificate and the set of encryption keys, and
determining whether the extracted public key corresponds to the service provider certificate;
generating a session with the secure element based on mutual authentication with the secure element using at least the service provider certificate; and in response to the processor of the secure element validating an activation certificate, loading a master key and a working key into a memory of the secure element.
12 . The system of claim 11 , further comprising:
generating, by the processor of the secure element, a public key corresponding to the service provider certificate and the set of encryption keys;
13 . The system of claim 11 , further comprising:
validating, by the processor of the secure element, the activation certificate by determining that the activation certificate is associated with a certification authority server.
14 . The system of claim 11 , wherein the service provider server transmits the activation certificate to the secure element.
15 . The system of claim 11 , further comprising:
determining, by the at least one service provider server, whether a firmware of a censor of the secure element stored in the memory of the secure element needs to be updates upon establishing a communication with the secure element.
16 . The system of claim 11 , wherein the one or more attributes associated with the secure element comprises a manufacture ID of a vendor of the secure element, whereby the at least one service provider server uses the one or more attributes to authenticate the secure element by comparing the manufacture ID of the vendor of the secure element with a manufacture ID of the vendor of the secure element stored within a database.
17 . The system of claim 11 , further comprising uploading, by the at least one service provider server, a firmware of a vendor of the secure element into the memory of the secure element.
18 . The system of claim 11 , wherein the activation certificate comprises a subject field with a one or more parameters associated with a service provider server, whereby the processor of the secure element validates the activation certificate by determining whether the subject field comprises a domain address associated with a certification authority server.
19 . The system of claim 11 , wherein the secure element is a printed circuit board of the terminal device, wherein the terminal device is selected from a group consisting of a card reader, a mobile phone, a vending machine, a wearable device, or an internet of things (IOT) device.
20 . The system of claim 11 , wherein the secure element is detachably connected to the terminal device.Join the waitlist — get patent alerts
Track US2022044237A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.