Global secure service provider directory
Systems and methods enable members of a secure transaction network to readily identify the appropriate trusted service manager (TSM) to support a particular transaction. A global directory of TSM providers is provided that a secure service provider can use for determining which TSM provider is the authorized manager of a security domain for the particular transaction. In aspect the directory of TSM providers may be stored within a mobile device secure element. In another aspect, the directory of TSM providers may be stored in a central TSM repository. In a further aspect, the directory of TSM providers may be distributed among a number of secondary TSM repositories. The appropriate TSM may be identified based upon a secure element identifier and an application identifier provided by a secure element as part of the transaction. Communication of the identifiers from mobile devices may be via cellular or near field communication links.
1. A mobile device comprising:
a processor;
a secure element coupled to the processor, wherein the secure element comprises a secure element identifier, an identifier of a wallet application within the secure element, and a cryptographic key associated with the wallet application and corresponding to a secret key of a trusted service manager (TSM) server;
a transceiver coupled to the processor; and
a memory storing executable instructions that, when executed by the processor, cause the processor to perform the steps of:
downloading a setup application;
launching the setup application;
retrieving, via the setup application, the secure element identifier and the identifier of the wallet application from the secure element;
transmitting, via the setup application and the transceiver, the secure element identifier and the identifier of the wallet application to a central repository via a bank server;
receiving, from the TSM server, a message comprising credit card account information via the transceiver;
verifying, using the cryptographic key, the message is encoded using the secret key of the TSM server; and
updating the wallet application with the credit card account information.
2. The mobile device of claim 1 , further comprising a system bus connecting the processor to the secure element, wherein retrieving, via the setup application, the secure element identifier corresponding to the secure element further comprises:
sending a query to the secure element via the system bus; and
receiving the secure element identifier from the secure element via the system bus.
3. The mobile device of claim 2 , wherein retrieving, via the setup application, the identifier of the wallet application within the secure element further comprises:
sending a query to the secure element via the system bus; and
receiving the identifier of the wallet application from the secure element via the system bus.
4. A financial system comprising:
a communication system;
a first repository server of trusted service manager (TSM) providers connected to the communication system;
a TSM server of one of the TSM providers connected to the communication system;
a mobile device connected to the communication system, the mobile device comprising:
a processor;
a secure element coupled to the processor, wherein the secure element comprises a secure element identifier, an identifier of a wallet application, and a cryptographic key associated with the wallet application and corresponding to a secret key of the TSM server;
a transceiver coupled to the processor; and
a memory storing executable instructions that, when executed by the processor, cause the processor to perform the steps of:
downloading a setup application;
launching the setup application;
retrieving, by the setup application, the secure element identifier and the identifier of the wallet application from the secure element;
transmitting, by the transceiver, the secure element identifier and the identifier of the wallet application to the first repository server of TSM providers via a bank server;
receiving, from the TSM server, an encoded message comprising credit card account information via the transceiver;
verifying, using the cryptographic key, that the encoded message is encoded using the secret key of the TSM server; and
updating the wallet application with the credit card account information.
5. The financial system of claim 4 , wherein retrieving the secure element identifier further comprises:
sending a query to the secure element via a system bus connecting the processor of the mobile device to the secure element; and
receiving the secure element identifier from the secure element via the system bus.
6. The financial system of claim 5 , wherein retrieving the identifier of the wallet application further comprises:
sending a query to the secure element via the system bus; and
receiving the identifier of the wallet application from the secure element via the system bus.