202 Software Networks
– scalability: the TSM must be able to handle all types of
credentials for all applications (banks, badges, coupons, transport,
etc.);
– the TSM must be able to support all types of form factor such as
SIM cards, “secure microcontrollers”, SD cards, eSEs, etc.
The specific problems of the TSM are that:
– the credentials must be isolated for each application from the
same issuer and from each different issuer. A variety of options have
been defined to create security domains (SD);
– access to the SD is complex. In addition, there may be several
secure elements, and it is complex to ensure access to the right secure
element;
– multi-tasking is another fairly complex characteristic. No one
application should be allowed to obstruct another for too long, on all
the security elements. In particular, we need to manage priorities
between different issuers;
– the use of SMS or BIP (TCP/IP) for the transport of the applets
between the TSM and secure element is problematic. It leads to
several problems, including OTA (Over The Air) security, and the
creation of SDs in a highly-secure manner;
– the process of installation of the applets must be common to all
operators and all issuers;
– there is a DAP (Data Authentication Pattern) mechanism, which
enables the issuer to be sure that the installed applet has not been
modified by the operator;
– the problem of who is authorized to manage the SDs needs to be
precisely defined;
– the personalization of the applets in the SDs needs to be done
with caution;
– secure elements have a stringent limitation on the number of SDs.
This is a major constraint for the number of NFC applications.
www.it-ebooks.info
Précédent

- 226/262

Suivant