Authorizing an application on a security element
A method for authorizing an application installed on a security element includes the steps of transmitting authorization information from a user verification element to the security element, comparing the authorization information with at least one requirement from a list on the security element; and selecting the application on the security element and/or performing a transaction by means of the application, provided that the authorization information meets the requirements from the list.
1 . A method for authorizing an application installed on a security element, comprising the following steps:
transmitting authorization information from a user verification element to a broker application installed on the security element;
comparing, by the broker application, the authorization information with at least one requirement from an application identifier list on the security element, wherein when comparing a check is carried out in order to determine whether the authorization information concerns a security-related status, including a positive user verification status; and
selecting the application on the security element by the broker element, provided that the authorization information meets the requirements from the list,
wherein the application identifier list is stored in the broker application, and
wherein the security element is a chip card, smart card, embedded secure element (eSE), and/or an embedded universal integrated circuitry (eUICC) card.
2 . The method according to claim 1 , comprising the step of providing a device which comprises the security element and the user verification element.
3 . The method according to claim 1 , comprising the step of transmitting authorization information from at least one further user verification element to the security element,
wherein the at least one further user verification element is provided separately from a device which comprises the security element.
4 . The method according to claim 1 , wherein the list is provided as a blacklist or protection trigger list.
5 . The method according to claim 1 , wherein a check is carried out in connection with the step of comparing in order to determine whether the application is recorded in an application identifier list.
6 . The method according to claim 1 , wherein the broker application installed on the security element stores the authorization information and carries out the steps of comparing and selecting and/or performing.
7 . The method according to claim 1 , wherein the user verification status is generated by means of a biometric sensor.
8 . The method according to claim 7 , wherein the biometric sensor is provided as a component of the user verification element.
9 . The method according to claim 7 , wherein, following the selection of the application, the user verification status is reset so that a further selection requires a user verification.
10 . The method according to claim 1 , wherein the authorization information is transmitted in encrypted form.
11 . The method according to claim 1 , wherein the application is configured to perform a transaction in a contactless manner by means of the security element.
12 . The method according to claim 1 , wherein the application is configured to perform a transaction that is performed is an authentication transaction, a payment transaction and/or an access control transaction.
13 . The method according to claim 1 , wherein the broker application is configured to permit or prevent access to one or more JavaCard applets and/or Quick Visa Smart Debit/Credit (qVSDC) applications installed on the security element.
14 . The method according to claim 1 , wherein transmitting authorization information comprises transmitting authorization information from a verification controller to the broker application, wherein the verification controller is configured to receive a user verification status from the user verification element and to transmit the user verification status as the authorization information to the broker application.
15 . The method according to claim 14 , wherein the verification controller is connected to the broker application via a cryptographically secured link.
16 . The method according to claim 1 , wherein the broker application is pre-personalized by personalization data which comprises a cryptographic key set for securing the transmitting of the authorization information.
17 . A device comprising a user verification element and a security element with an application installed thereon, the security element being a chip card, smart card, embedded secure element (eSE), and/or an embedded universal integrated circuitry (eUICC) card, wherein:
the user verification element is configured to transmit authorization information to a broker application installed on the security element, and
in order to authorize the application, the broker application installed on the security element is configured to compare the authorization information received from the user verification element with at least one requirement from an application identifier list stored on the broker application, to carry out a check in order to determine whether the authorization information concerns a security-related status, including a positive user verification status, and to select the application, provided that the authorization information meets the requirements from the list.
18 . The device according to claim 17 , wherein the device is configured to carry out a method for authorizing an application installed on a security element, comprising the following steps:
transmitting authorization information from a user verification element to the security element;
comparing the authorization information with at least one requirement from a list on the security element; and
selecting the application on the security element and/or performing a transaction by means of the application, provided that the authorization information meets the requirements from the list.