SYSTEM AND METHOD FOR SECURE CONTAINMENT OF SENSITIVE FINANCIAL INFORMATION STORED IN A MOBILE COMMUNICATION TERMINAL
A method for securing information over-the-air (OTA) in a non-Universal Integrated Circuit Card (UICC) type secure element (SE) of a mobile terminal including receiving a request to initialize an OTA proxy of a mobile terminal, initializing the OTA proxy, receiving a request to secure information, and securing, using the OTA proxy, the requested information in the non-UICC type SE. A method for reconstructing a mobile wallet application including receiving a request to reconstruct the mobile wallet application for a user; transmitting stored mobile wallet application information associated with the user to the mobile terminal; receiving mobile terminal information and SE information; and transmitting a stored application associated with the mobile wallet application information to the mobile terminal. A mobile terminal to secure information OTA in a non-UICC type SE including an OTA proxy to receive a securing command from a TSM, and a non-UICC SE.
1 . A method for securing information in a non-Universal Integrated Circuit Card (UICC) type secure element (SE) of a mobile terminal, comprising:
receiving a request to initialize an over-the-air (OTA) proxy of a mobile terminal;
initializing the OTA proxy;
receiving a request to secure information stored in the SE; and
securing, using the OTA proxy, the information stored in the SE, wherein the SE is a non-UICC type SE.
2 . The method of claim 1 , further comprising:
requesting installation of the OTA proxy;
receiving OTA proxy installation information; and
installing the OTA proxy in the mobile terminal.
3 . The method of claim 2 , wherein OTA proxy installation information is received from a Trusted Service Manager (TSM).
4 . The method of claim 3 , wherein initializing the OTA proxy comprises:
waking the OTA proxy; and
transmitting mobile terminal information and SE information to the TSM,
wherein the SE information comprises an SE status and an SE type.
5 . The method of claim 1 , wherein the request to secure information comprises an Application Protocol Data Unit (APDU) command.
6 . The method of claim 5 , wherein securing the requested information in the non-UICC type SE comprises executing the APDU command for securing the requested information, wherein the non-UICC type SE comprises a Micro Secure Digital (SD), an Embedded SE, or a SE that does not support either a Short Message Service Point to Point (SMS-PP) protocol or a Bearer Independent Protocol (BIP).
7 . The method of claim 1 , wherein securing the requested information in the SE comprises deleting information stored in the non-UICC type SE.
8 . The method of claim 1 , wherein securing the requested information in the SE comprises locking access to information stored in the non-UICC type SE.
9 . The method of claim 1 , wherein the request to initialize the OTA proxy is received from a push server.
10 . The method of claim 1 , further comprising preparing the SE for securing information before securing the requested information, wherein preparing the SE comprises:
retrieving mobile terminal information and SE information, wherein the SE information comprises an SE status and an SE type;
receiving a key based on the SE status; and
using the key to access the SE.
11 . The method of claim 10 , wherein the mobile terminal information comprises at least one of International Mobile Equipment Identity (IMEI), Mobile Equipment Identifier (MEID), and Mobile Subscriber Integrated Services Digital Network Number (MSISDN).
12 . The method of claim 10 , wherein the key comprises at least one of an initial issuer master key and a final issuer master key.
13 . The method of claim 12 , wherein securing the information stored in the SE comprises providing at least one of the initial issuer master key and the final issuer master key to the SE in response to a determination that the SE status is Operating System (OS) native.
14 . The method of claim 12 , wherein securing the information stored in the SE comprises providing the final issuer master key to the SE in response to a determination that SE status is initialized.
15 . The method of claim 10 , wherein using the key to access the SE further comprises processing a protocol for enabling provisioning of the SE, the SE type being a Micro Secure Digital (SD) type.
16 . A method for authenticating a mobile terminal, comprising:
receiving mobile terminal information and secure element (SE) information from the mobile terminal;
comparing the received information with stored mobile terminal information and SE information; and
transmitting a command based on the comparison result.
17 . The method of claim 16 , wherein the mobile terminal information comprises at least one of International Mobile Equipment Identity (IMEI), Mobile Equipment Identifier (MEID), and Mobile Subscriber Integrated Services Digital Network Number (MSISDN).
18 . The method of claim 16 , wherein the SE information comprises at least one of Card Image Number (CIN), Card Reference Number (CRN), Card Production Life Cycle (CPLC), and Card Serial Number (CSN).
19 . The method of claim 16 , wherein transmitting a command based on the comparison result comprises transmitting a command to delete information stored in the SE of the mobile terminal, in response to the received information being different from the stored information.
20 . The method of claim 19 , wherein the SE is a non-Universal Integrated Circuit Card (UICC) type SE.
21 . The method of claim 16 , wherein transmitting a command based on the comparison result comprises transmitting a command to lock access to the information stored in the SE of the mobile terminal, in response to the received information being different from the stored information.
22 . The method of claim 21 , wherein the SE is non-UICC type SE.
23 . A method for reconstructing a mobile wallet application of a mobile terminal, comprising:
receiving a request to reconstruct the mobile wallet application of a user;
transmitting stored mobile wallet application information associated with the user to the mobile terminal;
receiving mobile terminal information and secure element (SE) information; and
transmitting a stored application associated with the mobile wallet application information to the mobile terminal.
24 . The method of claim 23 , wherein transmitting stored mobile wallet application information associated with the user to the mobile terminal comprises transmitting an over-the-air (OTA) proxy application associated with the user.
25 . The method of claim 23 , wherein transmitting stored mobile wallet application information associated with the user to the mobile terminal comprises transmitting an OTA proxy application associated with the mobile wallet application information.
26 . The method of claim 23 , wherein receiving a request to reconstruct the mobile wallet application comprises receiving identifying information associated with the user.
27 . The method of claim 23 , wherein the stored application information associated with the mobile wallet application comprises at least one of a contactless card applet, a wallet management applet, and a widget application for interfacing the user.
28 . A mobile terminal to secure information over-the-air (OTA) in a non-Universal Integrated Circuit Card (UICC) type secure element (SE), comprising:
an OTA proxy configured to connect to a Trusted Service Manager (TSM), and to receive a securing command from the TSM; and
a non-UICC type SE.
29 . The mobile terminal of claim 28 , wherein the securing command is a command to delete information stored in the non-UICC type SE or to lock access to information stored in the non-UICC type SE.
30 . The mobile terminal of claim 28 , wherein the OTA proxy is configured to transmit mobile terminal information and SE information to the TSM, wherein the SE information comprises an SE status and an SE type.
31 . The mobile terminal of claim 30 , wherein the OTA proxy is further configured to receive a key from the TSM to access the SE based on the SE information sent to the TSM, wherein the key comprises at least one of an initial issuer master key and a final issuer master key.
32 . The mobile terminal of claim 30 , wherein the OTA proxy is further configured to receive a protocol to prepare the SE to be provisioned, the SE type being a Micro Secure Digital (SD) type.
33 . The mobile terminal of claim 28 , wherein the non-UICC type SE comprises:
a contactless card applet; and
a wallet management applet corresponding to the contactless card applet, wherein the wallet management applet comprises at least one of an account number associated with the contactless card applet, an expiration date, and a security code.