Security 201
standards and data transfer to secure domains (SD) are defined by the
industrial federation “GlobalPlatform”. All types of secure elements
are handled. TSMs thus function as sorts of gateways between the
different service providers and the end clients.
The TSM infrastructure can also be used to make available and
manage critical applications for security which are not based on NFC.
Online authentication, as it is used in the context of online and mobile
banking services, is an example of this.
One of the challenges that needs to be overcome, in the context of
the establishment of the NFC economic system, relates to the fact that
the number of secure element providers, and therefore SEI TSM
providers, is relatively limited, whereas the number of service
providers is growing incessantly. If each service provider had its own
TSM, the number of integrations and professional agreements
required would simply explode. This is why there are now open SP
TSMs which handle several service providers, interacting with most
service provider TSMs on the market in question. Service providers
have access to a broad range of secure elements, and can thus target
most clients using smartphones, whilst secure element manufacturers
devote less time and money to the integration of projects including SP
TSMs.
As the name indicates, both types of TSM must be trustworthy and,
therefore, must satisfy the strictest security standards. This also
underlies the implementation of quality processes, such as security
measures integrated into the systems and the solutions – in particular,
the storage of secure keys. This is critical for the applications involved
in payment operations. Payment systems such as Visa or MasterCard
thus require a rigorous TSM certification process. Because of these
requirements in terms of security and savoir-faire in mobile
technologies and payment technologies, TSMs, and particularly open
SP TSMs, are usually run by a trusted intermediary.
The general problems of the TSM system are as follows:
– neutrality: the TSM must be independent of the issuer and the
operator;
www.it-ebooks.info
standards and data transfer to secure domains (SD) are defined by the
industrial federation “GlobalPlatform”. All types of secure elements
are handled. TSMs thus function as sorts of gateways between the
different service providers and the end clients.
The TSM infrastructure can also be used to make available and
manage critical applications for security which are not based on NFC.
Online authentication, as it is used in the context of online and mobile
banking services, is an example of this.
One of the challenges that needs to be overcome, in the context of
the establishment of the NFC economic system, relates to the fact that
the number of secure element providers, and therefore SEI TSM
providers, is relatively limited, whereas the number of service
providers is growing incessantly. If each service provider had its own
TSM, the number of integrations and professional agreements
required would simply explode. This is why there are now open SP
TSMs which handle several service providers, interacting with most
service provider TSMs on the market in question. Service providers
have access to a broad range of secure elements, and can thus target
most clients using smartphones, whilst secure element manufacturers
devote less time and money to the integration of projects including SP
TSMs.
As the name indicates, both types of TSM must be trustworthy and,
therefore, must satisfy the strictest security standards. This also
underlies the implementation of quality processes, such as security
measures integrated into the systems and the solutions – in particular,
the storage of secure keys. This is critical for the applications involved
in payment operations. Payment systems such as Visa or MasterCard
thus require a rigorous TSM certification process. Because of these
requirements in terms of security and savoir-faire in mobile
technologies and payment technologies, TSMs, and particularly open
SP TSMs, are usually run by a trusted intermediary.
The general problems of the TSM system are as follows:
– neutrality: the TSM must be independent of the issuer and the
operator;
www.it-ebooks.info
