Security 203
Figure 7.10 shows the security domains of the telecom operator,
that of the TSM and those of the applications. All of this is complex to
manage, and the rights to the SDs of the operator and of the TSM are
imperfectly defined.
Figure 7.10. The security domains
7.5. Solution without a TSM
A solution without a TSM has been developed by some companies,
including Google and EtherTrust. This solution entails deporting the
secure elements to servers which can be controlled by the service
providers (banks, companies, etc.) or by a security grid provider.
With this solution, all the shortcomings of the current
implementation of TSM are eliminated. However, a new constraint is
introduced, replacing the drawbacks of TSM: the mobile device must
constantly be connected. This solution is represented in Figure 7.11.
www.it-ebooks.info
Figure 7.10 shows the security domains of the telecom operator,
that of the TSM and those of the applications. All of this is complex to
manage, and the rights to the SDs of the operator and of the TSM are
imperfectly defined.
Figure 7.10. The security domains
7.5. Solution without a TSM
A solution without a TSM has been developed by some companies,
including Google and EtherTrust. This solution entails deporting the
secure elements to servers which can be controlled by the service
providers (banks, companies, etc.) or by a security grid provider.
With this solution, all the shortcomings of the current
implementation of TSM are eliminated. However, a new constraint is
introduced, replacing the drawbacks of TSM: the mobile device must
constantly be connected. This solution is represented in Figure 7.11.
www.it-ebooks.info
