Untitled record
20 claims: 4 independent, 16 dependent
- 1PATENT CLAIMS SZABADALMI IGÉNYPONTOK 1. Eljárás kommunikációs eszköz biztonságos tároló részegységében elhelyezkedő, információtartalom fogadására szolgáló egyedi hozzáférésű tárterület létesítésére, amelynek során központi egységgel és azzal összeköttetésben álló, legalább egy darab tárolóregisztert tartalmazó biztonságos tároló részegységgel rendelkező kommunikációs eszköz segítségével szolgáltatóval adatcserét hajtunk végre, amelynek eredményeképpen a kommunikációs eszköz biztonságos tároló részegységében új egyedi hozzáférésű tárterületet hozunk létre, és ahhoz a szolgáltató részére hozzáférést biztosítunk, azzal jellemezve, hogy az információtartalom fogadására szolgáló egyedi hozzáférésű tárterület (22) létesítéséhez az adott biztonságos tároló részegység (20) azonosítására alkalmas rögzített információkból (41) és kiegészítő információkból (42) indító adatcsomagot (40) állítunk össze, majd az indító adatcsomagot (40) az információtartalom felügyeletét ellátó szolgáltatóhoz (30) továbbítjuk, a szolgáltatónál (30) az indító adatcsomagot (40) vizsgálatnak vetjük alá, amelynek során az indító adatcsomag (40) felhasználásával az adott biztonságos tároló részegység (20) felügyeleti partnerének (50) elérhetőségét megállapítjuk, ezt követően az adott biztonságos tároló részegység (20) felügyeleti partneréhez (50), vagy annak megbízottjához (51) helykérő adatcsomagot (60) juttatunk el, ahol a helykérő adatcsomagban (60) legalább az adott biztonságos tároló részegység (20) azonosítására alkalmas adatokat (61) szerepeltetjük, az adott biztonságos tároló részegység (20) felügyeleti partneréhez (50), vagy annak megbízottjához (51) érkező helykérő adatcsomagot (60) értelmezzük, majd az értelmezés eredményének megfelelően az adott biztonságos tároló részegységben (20) az egyedi hozzáférésű tárterületet (22) létrehozzuk, az egyedi hozzáférésű tárterület (22) létesítéséről pedig a szolgáltatót (30) értesítjük, és számára a hozzáférést biztosító hozzáférési adatcsomagot (80) megküldjük. First A method of providing a single-access storage area for receiving information content located in a secure storage unit of a communication device, comprising:exchanging data with a central unit and a communication device with a secure storage unit containing at least one storage register connected thereto, as a result, creating a new unique access storage area in the secure storage component of the communication device and providing it to the service provider, characterized in that, (41) and compiling a startup data pack (40) from additional information (42), and then transmitting the boot data packet (40) to the information content monitoring service provider (30), the service provider (30) subjecting the boot data packet (40) to a monitoring of said secure storage component (20) using the boot data packet (40). determining the availability of your partner (50), then contacting the management partner (50) of that secure storage unit (20), or transmitting to the agent (51) a requesting data pack (60), wherein the requesting data pack (60) includes at least data (61) identifying the secure storage unit (20) to the monitoring partner (50) of said secure storage unit (20). ), or interpreting a location request packet (60) to its agent (51), then, according to the result of the interpretation, creating a unique access storage area (22) in said secure storage component (20), and informing the service provider (30) of the establishment of the unique access storage area (22) and transmitting the access data packet (80).
- 5Eljárás kommunikációs eszköz biztonságos tároló részegységében elhelyezkedő, információ tartalom fogadására szolgáló egyedi hozzáférésű tárterület létesítésére, amelynek során központi egységgel és azzal összeköttetésben álló, legalább egy darab tárolóregisztert tartalmazó biztonságos tároló részegységgel rendelkező kommunikációs eszköz segítségével másik féllel adatcserét hajtunk végre, amelynek eredményeképpen a kommunikációs eszköz biztonságos tároló részegységében új egyedi hozzáférésű tárterületet hozunk létre, és ahhoz arra feljogosított fél részére hozzáférést biztosítunk, azzal jellemezve, hogy az információtartalom fogadására szolgáló egyedi hozzáférésű tárterület (22) létesítéséhez az adott biztonságos tároló részegység (20) azonosítására alkalmas rögzített információkból (41) és kiegészítő információkból (42) helykérő adatcsomagot (60) állítunk össze, majd a helykérő adatcsomagot (60) az adott biztonságos tároló részegység (20) felügyeleti partneréhez (50), vagy annak megbízottjához (51) továbbítjuk, a felügyeleti partnernél (50), vagy annak megbízottjánál (51) a helykérő adatcsomagot (60) értelmezzük, majd az értelmezés eredményének megfelelően az adott biztonságos tároló részegységben (20) az egyedi hozzáférésű tárterületet (22) létrehozzuk, az egyedi hozzáférésű tárterület (22) létesítéséről pedig a hordozható távközlési eszköz (10) kezelőjét vagy az általa meghatározott másik felet értesítjük, és számára a hozzáférést biztosító hozzáférési adatcsomagot (80) megküldjük. 5th A method of providing a single-access storage area for receiving information content located in a secure storage unit of a communication device, the data being exchanged with another party via a central unit and a communication device having a secure storage unit containing at least one storage register. as a result of which a new unique access storage space is created in the secure storage subunit of the communication device and accessed by an authorized party, characterized in that the fixed storage area (22) for identifying said secure storage subunit (20) compiling a location request packet (60) from information (41) and additional information (42), and transmitting the requesting data packet (60) to the management partner (50) or its agent (51) of the secure storage component (20), interpreting the requesting data packet (60) to the management partner (50) or its agent (51), and then, according to the result of the interpretation, creating a single access storage area (22) in said secure storage component (20), and notifying the operator of the portable telecommunication device (10) or the other party specified by it of the establishment of the unique access storage area (22) and transmitting to it the access data packet (80) providing the access.
- 8Eljárás információtartalomnak kommunikációs eszköz biztonságos tároló részegységében történő elhelyezésére, amelynek során központi egységgel és azzal összeköttetésben álló, legalább egy darab tárolóregisztert tartalmazó biztonságos tároló részegységgel rendelkező kommunikációs eszköz segítségével szolgáltatóval adatcserét hajtunk végre, amelynek eredményeképpen a kommunikációs eszköz biztonságos tároló részegységébe új egyedi hozzáférésű információtartalmat telepítünk, és ahhoz a szolgáltató részére hozzáférést biztosítunk, azzal jellemezve, hogy az egyedi hozzáférésű információtartalom elhelyezéséhez az adott biztonságos tároló részegység (20) azonosítására alkalmas rögzített információból (41) és kiegészítő információból (42) indító adatcsomagot (40) állítunk össze, majd az indító adatcsomagot (40) az információtartalom felügyeletét ellátó szolgáltatóhoz (30) továbbítjuk, a szolgáltatónál (30) az indító adatcsomagot (40) vizsgálatnak vetjük alá, amelynek során az indító adatcsomag (40) felhasználásával az adott biztonságos tároló részegység (20) felügyeleti partnerének (50) elérhetőségét megállapítjuk, ezt követően az adott biztonságos tároló részegység (20) felügyeleti partneréhez (50), vagy annak megbízottjához (51) helykérő adatcsomagot (60) juttatunk el, ahol a helykérő adatcsomagban (60) legalább az adott biztonságos tároló részegység (20) azonosítására alkalmas elérhetőségi adatokat (61) szerepeltetjük, az adott biztonságos tároló részegység (20) felügyeleti partneréhez (50), vagy annak megbízottjához (51) érkező helykérő adatcsomagot (60) értelmezzük, majd az értelmezés eredményének megfelelően az adott biztonságos tároló részegységben (20) az egyedi hozzáférésű információtartalmat elhelyezzük, az egyedi hozzáférésű információtartalom elhelyezéséről pedig a szolgáltatót (30) értesítjük, és számára a hozzáférést biztosító hozzáférési adatcsomagot (80) megküldjük. 8th A method for storing information content in a secure storage unit of a communication device, comprising:exchanging data with a provider using a communication device with a central unit and a communication unit having a secure storage unit comprising at least one storage register;and providing access to the provider, characterized in that, for storing the unique access information content, a boot data pack (40) is formed from the fixed information (41) and additional information (42) identifying the secure storage component (20) and then the boot data packet (40) transmitting to the information content monitoring service provider (30), the provider (30) subjecting the boot data packet (40) to an inspection, wherein, using the boot data packet (40), determining the availability of a management partner (50) for said secure storage assembly (20), and thereafter a location request packet (51) for the management partner (50) or its agent (51) for said secure storage assembly (20). 60) delivering at least the contact information (61) suitable for identifying the particular secure storage component (20) in the location request packet (60), interpreting the location request data packet (60) received by the management partner (50) or its agent (51) of said secure storage unit (20) and then, according to the result of the interpretation, placing the individually accessed information content in said secure storage unit (20) and informing the service provider (30) of the placement of the information content and sending the access data packet (80) providing the access.
- 15Eljárás kommunikációs eszköz biztonságos tároló részegységében elhelyezkedő, információtartalom fogadására szolgáló egyedi hozzáférésű tárterület kijelölésére, amelynek során központi egységgel és azzal összeköttetésben álló, legalább egy darab tárolóregisztert tartalmazó biztonságos tároló részegységgel rendelkező kommunikációs eszközbe kódolt adatforgalom lebonyolításához felhasználható egyik titkosító kulcsot olvasunk, és így védelemre alkalmas kommunikációs eszközt hozunk létre, majd a védelemre alkalmas kommunikációs eszköz segítségével szolgáltatóval adatcserét hajtunk végre, azzal jellemezve, hogy a szolgáltatóval (30) történő adatcserét megelőzően az adott hordozható távközlési eszköz (10) biztonságos tároló részegységében (20) egyedi hozzáférésű tárterületet (22) hozunk létre, és az egyedi hozzáférésű tárterületre (22) az egyik titkosító kulcs (21a) párját alkotó másik titkosító kulcsot (21b) olvasunk be, az ezt követő adatcsere során az egyedi hozzáférésű tárterület (22) létesítéséről a szolgáltatót (30) tájékoztatjuk, valamint az egyedi hozzáférésű tárterülethez (22) történő biztonságos hozzáférést lehetővé tevő egyik titkosító kulcsot (21a) a szolgáltatóhoz (30) eljuttatjuk, ezt követően az adatcsere eredményeképpen a szolgáltatónak (30) megküldött egyik titkosító kulccsal (21a) a szolgál18 tatónál (30) kódolt adatcsomagot (31) hozunk létre, a kódolt adatcsomagot (31) a kommunikációs eszköz (10) biztonságos tároló részegységének (20) meghatározott egyedi hozzáférésű tárterületén (22) eltároljuk, a másik titkosító kulccsal (21b) visszafejtjük, és így a kommunikációs eszköz (10) adott egyedi hozzáférésű tárterületéhez (22) a szolgáltató (30) részére hozzáférést teszünk lehetővé. 15th A method of designating a unique access storage area for receiving information content in a secure storage unit of a communication device, comprising:reading an encryption key useful for encrypting data traffic to a communication device having a central storage unit and a secure storage unit containing at least one storage register. we create a tool, and exchanging data with the service provider by means of a communication device suitable for protection, characterized in that prior to data exchange with the service provider (30), a unique access storage area (22) is created in the secure storage unit (20) of said portable telecommunications device (10);accessing storage space (22) reading another encryption key (21b) which is a pair of one encryption key (21a), during the subsequent data exchange, the service provider (30) is informed of the establishment of the unique access storage (22), and an encryption key (21a) allowing secure access to the unique access storage (22) is transmitted to the service provider (30);as a result, one of the encryption keys (21a) sent to the service provider (30) generates an encrypted data packet (31) at the service provider (30), storing the encrypted data packet (31) in a defined unique access storage area (22) of the secure storage component (20) of the communication device (10), decrypting it with the other encryption key (21b);) providing access to the service provider (30).
Independent claims4
72 paragraphs in 3 sections, as filed
A feature of this method is to provide a boot data pack (40) for storing the unique access information content from the recorded information (4d) and the additional information (42) for identifying the particular secure storage component (20) and the boot data pack (40). transmitting to the monitoring service provider (30), the service provider (30; the boot data pack (40) for inspection, wherein, using the boot data packet (40), determining the availability of the management partner (50) of said secure storage assembly (20), the access partner (50V) of said secure storage assembly (20) and its agent (51) transmitting a data packet (60), wherein the requesting data packet (60) includes at least contact information (61) suitable for identifying said secure storage component (20), interpreting the call request data packet (60) arriving at the management partner (G) of the secure storage unit (20) or its agent (51) and then, according to the result of the interpretation, placing the unique access information page in the secure storage unit (20); for accessing information content peoiga sol<sub>/</sub>notifying the provider (30) and sending the access data packet (80) providing access. The present invention also relates to a method for designating a single access storage area for receiving information content in a secure storage unit of a communication device, the method comprising encrypting a communication unit with a central unit and a secure storage unit having at least one storage register associated therewith. we read one of the encryption keys that can be used for data traffic, and thereby creating a security communication device and exchanging data with the other party using the security communication device, resulting in the creation of a new unique access space in the secure storage part of the communication device and providing access to the authorized party.
• · «··«
However, a feature of this method is that, by exchanging data with the service provider (30), a secure storage unit (22) is created in the portable storage device (10) and one of the unique access storage areas (22) the other encryption key (21b) forming a pair of encryption key (21a) is provided, and the service provider (30) is informed of the establishment of a subsequent access storage (22), and transmitting one of the encryption keys (21a7) to the server (30) for secure access to the single access storage space 02), and subsequently to the service provider (30) as a result of the data exchange (0). generating an encrypted data packet (31), storing the encrypted data packet (31) in a defined unique access storage area (22) of the communication means (20), decrypting it with the other encryption key (21b), thus allowing access to a given unique access area (22) of the communication device (10) by the service provider (30).
The typical figure is Figure 1
<img file="HU0700685A2_D0001.tif" />
• · » · • « • · · ·
DISCLOSURE COPY P 07 00 6 85 (X. 2007)
Represented by Tibor Rónaszéki, Budapest, HU
Procedure for Preparing and Locating Unique Access Information Content in a Secure Storage Component of a Communication Device
FIELD OF THE INVENTION The present invention relates to a method for providing a single-access storage area for receiving information content located in a secure storage unit of a communication device, comprising: exchanging data with a service provider using a central unit and a communication device with a secure storage unit containing at least one storage register. as a result of which, in the secure storage component of the communication device, we create a new unique access space and provide it to the service provider.
The invention also relates to a method for storing information content in a secure storage unit of a communication device, the data being exchanged with a service provider via a central unit and a communication device having a secure storage unit containing at least one storage register connected thereto, resulting in the installation of new unique access information content to the secure storage component of the communication device and providing the provider with access thereto
The present invention also relates to a method for designating a unique access storage area for receiving information content located in a secure storage unit of a communication device, comprising: using an encryption key for transmitting data encrypted in a communication device with a central unit and a secure storage unit containing at least one storage register. we read, and thereby creating a security communication device and exchanging data with the other party using the security communication device, resulting in the creation of a new unique access space in the secure storage part of the communication device and providing access to the authorized party.
10.519
I · · · · · · · · · · · · · · · ·
As a result of the development of communication devices, especially mobile phones and chip cards, communication devices are becoming more and more widely available to the user. Some of the services are already standard in the communication device itself, but there are also information content that implements the service, which may need to be retrospectively selected by the user or expediently downloaded into the user's own communication device for security reasons.
However, according to the state of the art, the entire storage space of a secure storage unit capable of receiving such information contents is generally associated with, essentially under the control of, a single person. However, this circumstance is also detrimental to the providers and users of the communication device. The same secure storage component is often not properly and appropriately utilized in most cases. The secure storage component that can be inserted into the communication device usually consists of a single storage area or, if separated, is partitioned by the manufacturer itself during chip card production and can no longer be reshaped by either the service provider or the user. This practice may result in unused card capacity or some storage space, as the true commercial needs for the particular services are not known at the time of manufacture, and unused applications may be placed on the card while the services sought by users may not be available. they can go there.
SUMMARY OF THE INVENTION The object of the present invention is to eliminate the unfavorable utilization practices of secure storage components embedded in communication devices and to provide methods for dynamically creating or, if necessary, eliminating unique access storage space for receiving various information contents after the card is manufactured and marketed, in a way, so that the initiator of the creation of new territories and the originator of the necessary primary data for this can be the users of the communication tools themselves and use their own communication means to carry out the procedure.
It was also a goal that content with different information contents be provided to a certain well-defined part of a specific storage area of the secure storage component. and isolated from the cardholder, to install information content in such a way that the data and information needed for that purpose are provided in the simplest form and with access, within appropriate security frameworks.
In addition, it is also an object of the present invention to provide a user-initiated secure installation of unique access information content even when the secure storage component can be managed as a single unit.
The process of the present invention has led to the discovery that when a particular data set of a secure storage component is directly or e.g. indirectly accessible from a database and using this data to communicate information about the device and / or the runtime environment and / or the user and / or content provider to the monitoring partner, even after the chip card has been manufactured and delivered to the user open retrospective storage areas for the secure storage component, and the unique access storage established is a specific party, e.g. access to the service provider, and so the task can be solved.
It has also been recognized that the specific placement of appropriately selected data elements and the use of encryption solutions other than conventional means allow one or more specified unique access storage to be created over a remote communication link solely and exclusively by the user of the communication device. designated by the party or parties reading the information therein, and the desired and expected level of data protection can be properly addressed.
The inventive idea also included the discovery that, by generating data packets with appropriate content and transferring them in an appropriate manner and location, single-access information contents that can only be accessed by designated parties can be placed in a single, indivisible secure storage unit, can also be solved.
According to an object of the invention, the method of the present invention comprises providing a single-access storage area for receiving information content in a secure storage unit of a communication device, comprising: exchanging data with a central unit and a communication device with a secure storage unit containing at least one storage register; as a result of which, in the secure storage component of the communication device, a new unique access storage space is created and accessed by the service provider, based on the principle of retrieving from the recorded information and additional information suitable for identifying the secure storage unit compile a data pack, then transmitting the boot data packet to the information content management service provider, subjecting the boot data packet to testing the availability of the management partner of that secure storage compartment using the boot data packet, and then requesting the management partner or agent of that secure storage companion delivering a data packet, interpreting the location request packet arriving to the security partner of the secure storage component or its agent, and then creating, in accordance with the result of the interpretation, a unique access storage area in said secure storage component, and the service provider will be notified, and sending the access data packet providing access thereto.
A further feature of the method of the present invention may be to determine the availability of a monitoring partner for that secure storage unit directly from the boot data packet.
In another embodiment of the method, the availability of the management partner of the secure storage component is determined from a remote database using the information contained in the boot data packet as addressing.
In another embodiment of the invention, the boot data packet includes additional information suitable for identifying the communication device associated with the secure storage unit and / or the user of the communication device and / or the service provider.
In accordance with another object of the present invention, another method of providing a single-access storage area for receiving information content located in a secure storage unit of a communication device is to exchange data with another party using a communication device with a central unit and a secure storage unit containing at least one storage register. we do, which results in the creation of a new unique access storage in the secure storage component of the communication device, and access granted to an authorized party, based on the principle of providing a unique access storage space for receiving information content compiling a location request packet of fixed information and additional information to identify the secure storage component, then transmitting the requesting data packet to the management partner or its agent of that secure storage component, interpreting the requesting data packet to the management partner or its agent, and then creating, in accordance with the result of the interpretation, a unique access storage in that secure storage component, and notifying the mobile telecommunication device operator or other party designated by it of the establishment of the unique access storage and sending the access data packet providing access thereto.
It may be advantageous from a procedural point of view to include in the requesting data package location data on the amount of unique access storage to be provided, as well as additional information and / or content related information identifying the communication device and / or service provider, and allocating, on the basis of location data for the size of the unique access storage to be created, a secure access component of the required amount of unique access storage.
According to a further object of the present invention, the method of storing information content in a secure storage unit of a communication device comprises: - exchanging data with a service provider via a central unit and a communication device with a secure storage unit containing at least one storage register; which results in the installation of new unique access information content to the secure storage component of the communication device and providing access to the service provider, based on the principle of compiling a data packet from fixed information and additional information identifying said secure storage unit to accommodate the unique access information content . then transmitting the boot data packet to the information content management service provider, subjecting the boot data packet to the provider, which determines the availability of the secure storage companion management partner using the boot data packet, and then to the secure storage companion management partner, or We send a place request data packet to its agent, wherein the requesting data packet includes at least the contact information suitable for identifying a particular secure storage component, interpreting the requesting data packet arriving at the management partner or agent of that secure storage component, and then, in accordance with the result of the interpretation, and we will notify the service provider of the content of the accessed information, and sending the access data packet providing access thereto.
In yet another embodiment of the invention, the recorded information includes at least the identifier string of the secure storage unit and / or the communication device identifier and / or the identifier of the communication partner and / or the user of the communication device, while the additional information includes at least the string that can be used to identify the monitoring partner and / or the user of the communication device and / or the identifier string of the communication device and / or the identifier of the secure storage unit.
In yet another embodiment of the method, the information transmission network or interface supporting direct data communication is used to communicate with the information content management service provider and / or the management partner of the secure storage unit, and thus for transmitting the boot data packet and / or request packet data packet.
In a preferred embodiment of the invention, the CPLC character set is used to identify the secure storage component and / or its associated monitoring partner, and the availability information of the secure storage unit monitoring partner is stored in an information network identifier located in the secure storage unit.
It is also within the scope of the present invention to provide a method for designating a unique access storage area in a secure storage unit of a communication device for receiving information content, in accordance with another aspect of the present invention, wherein: reading one of the encryption keys that can be encrypted into a communication device having a secure storage component containing at least one storage register, thereby creating a security communication device and then, with the security communication device, exchanging data with the service provider, prior to exchanging data with a service provider, creating a unique access storage in said secure storage unit of said portable telecommunications device and reading another encryption key that is paired with one encryption key on said access storage, and informing the service provider of the establishment of the unique access storage. . and transmitting one encryption key suitable for secure access to the unique access storage to the service provider; decrypt it with an encryption key, and thus providing the service provider with exclusive access to that particular access storage area of the communication device.
A further feature of this method of the present invention may be to encrypt another encryption key for a given unique access storage area before transmitting it to a provider, and to encrypt it using an external encryption key. The external cryptographic key is the public key of the service provider.
In one embodiment, one encryption key and the other encryption key are asymmetric key pairs, or one encryption key and the other encryption key are symmetric key pairs.
THE.
In a possible implementation of procedures, the service provider and the monitoring partner are the same person.
The most important advantage of the methods of the invention is that they allow the storage space of the secure storage unit to be retrofitted remotely or remotely or remotely with secure data management, thus creating independent storage areas, so that the necessary data exchange with each other even with partners unknown to it, it can be solved with simple logistical support, without the need for special administrative operations.
The benefit of this is that a complete secure storage component becomes fully usable by independent content providers, and the information content can be downloaded even without direct physical connection between the players - in any case, to individually accessible storage space. In this way, the utilization of the secure storage component can be optimized, allowing more applications to be accessed and used by the user.
A set of tools for use in the process of the present invention will now be described in more detail with reference to an exemplary embodiment. In the drawing it is
First FIG. 4 is a schematic view of a possible version of a tool set used in the process. FIG.
Figure 1 shows a schematic arrangement of means by which the method of the invention may be implemented. Communication devices 10 can be observed, one of which is a mobile telephone and the other is a portable minicomputer. Each communication device 10 may be interconnected by the information transfer network 70 and / or the interface 90 with the service provider 30 and / or the management partner 50 or, where appropriate, the agent 51 of the management partner 50.
The mobile telephone device serving as the communication device 10 comprises a central unit 11 controlling the operation of the communication device 10, a secure storage unit 20 connected to the central unit 11, and other storage space 12. The other storage 12 includes the storage register 21, while the secure storage assembly 20 includes the unique access storage 22 that can be created by the method.
THE
In this case, the storage register 21 contains one encryption key 21a, while the other encryption key 21b located in the unique access storage area 22. One encryption key 21a and the other encryption key 21b together form a key pair. It is, of course, conceivable that one encryption key 21a and another encryption key 21b are different. This is the asymmetric key pair. However, it is possible that one encryption key 21a and the other encryption key 21b are the same. In this case, the key pair is symmetric. The other storage area 12 houses the external encryption key 32, which ultimately belongs to the service provider 30, and may be read to the other storage space 12 through the information transmission network 70.
Optionally, the external encryption key 32 and one of the encryption keys 21a may also be located on the secure storage unit 20.
Also, the communication device 10 is assigned a start data pack 40 which includes the recorded information 41 and the additional information 42. The recorded information 41 and the auxiliary information 42 are masses of data that can be transmitted to the service provider 30 or to the monitoring partner 50 either through the information transfer network 70 or through the interface 90.
The recorded information 41 or additional information 42 of the start data pack 40 includes direct or indirect contact information of the monitoring partner 50, an information network identifier, and may include information identifying the communication device 10 and the service provider 30, and and a string identifying the user of the communication device 10.
The purpose of this start-up data pack 40 is to clearly determine which secure storage component 20 is to be provided with individual access storage 22 and which, i.e., which management partner 50 is capable of executing it.
It should be noted here that the identification of the 50 Supervisory Partners is not only direct. There is also a solution where the 50 monitoring partners are represented by only one so-called "pointer" points to a particular element of a remote access computer database, and that element actually contains the direct contact information of the 50 management partners.
THE
The method also includes a solution to ensure that the data of the management partner 50 stored in the remote access database results in correct information even if the person of the management partner 50 changes. Accordingly, in the event of a change in the management partner 50 deploying over said secure storage unit 20, the former management partner 50 initiates an update to the database identifying the management partner 50 of that secure storage unit and puts the secure storage unit 20 into a temporary state. to change your access rights, and at the same time allowing the new management partner 50 of the secure storage unit 20 to take over the access authority of the secure storage unit 20, then the new management partner 50 updates the access authorization of the secure storage unit 20 and The ID for the new 50 management partners is activated in the Identification Database.
• · • · ·
The access partner 80 is assigned to the management partner 50, which represents the information group by which the desired individual access storage 22 or individual access information content is made available on the secure storage unit 20 of a communication device 10.
While the service provider 30, in addition to the external encryption key 32, has the encrypted data packet 31 required to personalize the particular access area 22 of the secure storage unit 20 and optionally includes the information requested by the user of the communication device in a secure format that is unauthorized. not understandable to him. The service provider 30 also has a location request packet 60, which may include data 61 and location 62. The data 61 includes information that uniquely identifies or possibly locates the specified secure storage component 20, while the location data 62 is a data element relating to the size of the individual access storage 22 to be provided.
The methods of the invention will now be described in more detail by way of examples.
First example:
In this version of the method of the invention, it was intended to allocate a single access storage area 22 in the 256 Kb secure storage compartment 20 of the communication device 10 to receive information content including a mobile wallet management application. Accordingly, the communication device 10 created the starter data pack 40, the recorded information 41 of which is the direct contact information of the secure storage component manufacturer 20, the monitoring partner 50, and the identification of the secure storage unit 20 itself, The identity of 10 communication devices has been edited.
After the start-up data packet 40 has been assembled, it is transmitted via the communication device 10 to the service provider 30 operating the mobile wallet management application via the information transmission network 70. After receiving the start data packet 40, the service requester 30 identified the request request from the recorded information 41 and the additional information 42, as well as the requester, the communication device 10 and the secure storage unit 20, and and the availability of a monitoring partner.
Subsequently, the location request packet 60 of the service provider 30 was compiled, which included 61 the identity of the secure storage unit 20 and the communication device 10 including the secure storage unit 20, and the identity of the service provider 30. The request packet data packet 60 is then transmitted via the information transfer network 70 to the monitoring partner 50, where the contents of the request packet data packet 60 are subjected to inspection.
After analyzing the packet data packet 60, the secure storage unit 20 on which the access storage 22 was to be delimited was determined, and then, via the information transmission network 70, a set of instructions was transmitted to the communication device 10 containing the secure storage unit 20. 22 unique access storage spaces have been created.
Along with delimiting the requested unique access storage 22, the service provider 30 was informed of the production of the desired unique access storage 22 via the information network 70 and was provided with an access data packet 80 including parameters for enabling operation on the unique access storage 22. Thus, on the communication device 10, a single access storage space 22 accessible only by the service provider 30 but requested by the user of the communication device 10 is provided in a particular secure storage subunit 20 of the specified communication device 10.
Second example:
In this variant of the method of the invention, unlike those described in the previous method, the first step in determining the availability of the monitoring partner 50 is based on the data stored in the secure storage unit 20 in the palmtop communication device 10.
To obtain this data, we accessed a specific compartment of information from the information stored in the secure storage compartment 20, which contains information from a number of secure storage compartment management entities, from which the direct contact information of the manufacturer as the management partner of the secure storage compartment 20 was obtained. With this information, the service provider 30 generating information content to be installed on the required access storage 22 from the recorded information 41 and the additional information 42 identifying the communication device 10, the location data of the requested 22 individual access storage space of our data we formed 60 place request data packets.
The paging data packet 60 is transmitted directly to the management partner 50 via the interface 90, whereupon, after analyzing the specified group of information, the desired storage space 22 is generated on the secure storage unit 20 of the communication device 10. through which we received 80 access data packets. Finally, a unique access storage 22 for receiving information content provided by the service provider 30 has been created on the secure storage subunit 20 of the communication device 10, which at the time of sale of the communication device 10 was not partitioned on the respective secure storage subunit 20.
Third example:
In the present embodiment, the unique access storage area 22 formed on the secure storage unit 20 of the communication device 10 is protected as follows. It should be emphasized that the process according to the invention is independent of the other process steps that are used to create the single access storage area 22 of the secure storage unit 20 itself. Thus, it is conceivable that, on the secure storage component 20 of the communication device 10, the various individual access storage areas 22 are generated by obtaining the access data packet 80 required from the management partner 50 itself, or even the data packet itself. we produce it.
As a first step, another encryption key 21b is installed on the unique access storage 22 for receiving the information content of the service provider 30, and then one encryption key 21a is placed on the other storage 12 of the communication device 10, thereby forming a crypto key 21a and another encryption key 21b. In case I - we prepared data exchange with asymmetric keys. Subsequently, the service provider 30 providing the information content in question was requested for the external encryption key 32 and downloaded to the other storage space 12 of the communication device 10.
One of the encryption keys 21a in the other storage area 12 of the communication device and the data of the secure storage unit 20 are encrypted by means of the central processing unit all and the external encryption key 32 in the other storage area 12. service provider. At service provider 30, one of the encryption keys 21a received encrypted the information it generated to produce an encoded data packet 31. The encrypted data packet 31 is also downloaded to the individual access storage area 22 of the marked storage device 20 via the information transmission network 70. In the unique access storage area 22, the encrypted data packet 31 received is decrypted by means of another encryption key 21b, thus allowing the service provider 30 to personalize the designated storage space in the particular access storage area 22.
4th example:
The procedure was the same as in the previous procedure except that one encryption key 21a and the other encryption key 21b were identical and thus encryption was performed with symmetric keys.
5th example:
In this version of the procedure, the same procedure was followed except that in the secure storage component 20, we do not create individually accessible storage areas but, by downloading the requested information content, using appropriately chosen encryption keys, allow access to the information content only by authorized users added.
It will be apparent from the described layout and method examples that the methods of the invention can be used to retrospectively assign, modify, and securely populate and access information storage in a single storage device for any communications device in a secure storage unit inserted into the communication devices. by, but also for unique access.
Contents3
3 sheets
Sheet 1 Sheet 2 Sheet 3
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 0700685 | Hungary | A | |
| HU20070000685 | – | – | – |
Numbers
- Publication, DOCDB
- 0700685
- Publication, EPODOC
- HU0700685
- Application
- 700685
- Application, DOCDB
- 0700685
- Application, EPODOC
- HU20070000685
Titles
- English
- METHOD OF PREPARING STORING AND METHOD OF STORING SINGLE USER ACCESS INFORMATION INTO SAFE STORAGE UNIT OF A COMMUNICATION DEVICE
Classification
- CPC, 5
- H04L63/123
- G06F12/1408
- G06F12/1416
- H04L63/20
- H04L63/04
- IPC, 3
- H04M11 00
- G06F12 00
- H04L9 00
