IP Library Granted Patent US 9,883,395
Granted Patent B2
US 9,883,395 · App. 14/952,776 · Granted Jan 30, 2018

Securely accessing secure elements

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,883,395
App. No.
14/952,776
Granted
Jan 30, 2018
Kind
B2
Abstract

Direct management of secure element data life cycles by backend servers without requiring direct communications between a trusted service manager (TSM) and a secure element is provided. A backend server client application executing on a mobile computing device enables users to request loading of application data on the secure element. A backend server receives the request to load application data. The backend server requests command scripts needed to load application data from the TSM and encrypts the command scripts with data stored on the backend server. The encrypted command scripts and application data are communicated to the backend server client application, which executes the command scripts and loads the application data onto the secure element via an interface of the mobile computing device.

Claims (40)

1. A computer-implemented method to access secure elements on mobile computing devices, comprising:

receiving, at one or more computing devices and from a backend server client application executing on a mobile computing device, a request to load application data onto a secure element of the mobile computing device;

communicating, using the one or more computing devices, a request for loading instructions needed to load the requested application data onto the secure element to a trusted service manager (TSM) server;

receiving, at the one or more computing devices, the loading instructions from the TSM server, the loading instructions comprising one or more computer executable scripts for loading the application data onto the secure element;

communicating, by the one or more computing devices, the loading instructions and the requested application data to the backend server client application executing on the mobile computing device;

receiving, by the backend server client application, the loading instructions and the requested application data from the one or more computing devices;

loading, by the backend server client application of the mobile computing device, the application data received by the backend server client application from the one or more computing devices, onto the secure element of the mobile computing device by executing the loading instructions and communicating the requested application data to the secure element of the mobile computing device.

2. The method of claim 1 , further comprising:

receiving, at the one or more computing devices, a loading report from the backend server client application of the mobile computing device after an attempt to load the application data in the secure element of the mobile computing device, the loading report comprising one or more messages regarding the success or failure of loading the application data;

communicating, by the one or more computing devices, the loading report to the TSM server for verification; and

receiving, at the one or more computing devices, a verification notification from the TSM server, the verification notification indicating whether the attempt to load the application data to the secure element of the mobile computing device failed or succeeded.

3. The method of claim 1 , further comprising: communicating, by the one or more computing, devices, computer-executable instructions to the backend server client application to display a feedback request on a user interface of the user computing device.

4. The method of claim 3 , wherein the feedback request comprises a request to confirm network access for a defined time period, or a request to continue or delay loading of the application data.

5. The method of claim 1 , wherein the one or more computing devices are an electronic wallet server, and wherein the backend server client application is a wallet application.

6. The method of claim 1 , wherein the application data comprises payment account information, a rotation of keys from the TSM server, a re-upload of an expired payment instance, or deletion of an existing payment instance.

7. The method of claim 1 , wherein the one or more computing devices, encrypt the requested application data and the one or more executable program instructions from the TSM server prior to communicating the application loading instructions and the requested application data to the backend server client application on the mobile computing device.

8. The method of claim 1 , wherein the application data is payment account information.

9. A computer program product, comprising:

a non-transitory computer-readable storage device having computer-executable program instructions embodied thereon that when executed by a computer cause the computer to manage secure elements on mobile computing devices, the computer-executable program instructions comprising:

computer-executable program instructions to receive a request from a backend server application executing on a mobile computing device to load application data onto a secure element;

computer-executable program instructions to communicate a request for loading instructions needed to load the requested application data onto the secure element to a TSM server;

computer-executable program instructions to receive the loading instructions from the TSM server; and

computer-executable program instructions to encrypt and communicate the loading instructions and requested application data to the backend server client application executing on a mobile computing device for loading onto the secure element, wherein the backend server client application executes the program instructions and communicates the application data to the secure element via a contact interface on the mobile computing device.

10. The computer program product of claim 9 , wherein the computer is an electronic wallet server.

11. The computer program product of claim 9 , wherein the application data comprises payment account information, a rotation of security keys, re-loading of an expired payment instance, or deletion of an existing payment instance.

12. The computer program product of claim 9 , wherein the request for loading instructions further comprises a request for the application data.

13. A system to manage secure elements on mobile computing devices, comprising:

a backend server application executing on a mobile computing device, the mobile computing device comprising a secure element and a contact interface in communication with the secure element; and

a storage device and a processor communicatively coupled to the storage device, wherein the processor executes application code instructions that are stored in the storage device to cause the system to:

receive a request to load application data onto a secure element from a mobile computing device;

communicate a request for loading instructions needed to load a type of application data onto the secure element to a TSM server;

receive the loading instructions from the TSM server;

encrypt a data package comprising the loading instructions and application data using a security key of a security key pair;

communicate the encrypted data package to a client application, wherein the client application decrypts the data package, executes the loading instructions, and communicates the application data to the secure element via the contact interface.

14. The system of claim 13 , wherein the processor further executes application code instructions that cause the system to:

receive a loading report from the client application, the loading report comprising one or more messages regarding application data loading status;

communicate the loading report to the TSM sever for verification; and

receive a verification notification from the TSM sever, the verification notification indicating whether the attempt to load the application data failed or succeeded.

15. The system of claim 13 , wherein the storage device is an electronic wallet server.

16. The system of claim 13 , wherein the application data comprises payment account information, a rotation of security keys, re-loading of an expired payment instance, or deletion of an existing payment instance.

Assignments (2)
CHANGE OF NAME Recorded Oct 5, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044129/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2016
From: RANGANATHAN, BALAMOUROUGAN; SHAH, HITESHKUMAR M.; TAILLON, PASCAL
To: GOOGLE INC.
Reel/Frame 037400/0205 →