Method of locating information content with limited access in the secure storage unit of a communication device
Abstract
The invention relates to a method for enabling post issuance operation on a secure element connectable to a communication device. The method allows an SE controlling party to perform remotely operations such as creation of new security domains for an external party, loading, and installation of applications of an external party and management functions including personalization and activation of applications loaded on the SE for an external party. The method includes the steps of: collecting data stored on the SE suitable for identification of the SE and data for contacting the SE controlling party; creating an initial data packet from the collected data, sending the data packet to a party which can be the external party, an agent of the external party, the SE controlling party, an agent of the SE controlling party. The invention further relates to a communication device and a software application for implementing the method.
Term
2 yearsto projected expiry
Projected expiry 6 October 2028, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
14 claims: 10 independent, 4 dependent
- 1Zastrzeżenia patentowe 1. Sposób lokalizowania zawartości informacji dostawcy usług w zabezpieczonej jednostce pamięci (20) urządzenia komunikacyjnego (10) mającego jednostkę centralną (11) i wymienioną zabezpieczoną jednostkę pamięci (20), który to sposób obejmuje przeprowadzenie wymiany danych z dostawcą usług (30) przy pomocy urządzenia komunikacyjnego (10) w wyniku czego nowa unikalnie dostępna zawartość informacji (22) znajduje się w zabezpieczonej jednostce pamięci (20) urządzenia komunikacyjnego (10); oraz zapewnienie dostępu do unikalnie dostępnej zawartości informacji (22) dla dostawcy usług, znamienny tym, że obejmuje etapy:- konfigurowania początkowego pakietu danych (40) z informacji zarejestrowanych (41) zawierających dane identyfikacyjne zabezpieczonej jednostki pamięci (20) oraz dane do kontaktowania się z partnerem kontrolującym (50) zabezpieczonej jednostki pamięci (20) przez sieć przesyłania informacji (70), oraz z informacji uzupełniających (42) , - wysyłania początkowego pakietu danych (40) z urządzenia komunikacyjnego (10) do dostawcy usług (30) sprawuj ącego nadzór nad zawartością informacji;- sprawdzania początkowego pakietu danych (40) u dostawcy usług (30), podczas którego stosując początkowy pakiet danych (40) identyfikowana jest informacja kontaktowa partnera kontrolującego (50) danej zabezpieczonej jednostki pamięci (20), - konfigurowania pakietu danych z żądaniem informacji o położeniu (60), w tym zawierających jako dane (61) dane identyfikacyjne danej zabezpieczonej jednostki pamięci (20), - wysyłania pakietu danych z żądaniem informacji o położeniu (60) od dostawcy usług do partnera kontrolującego (50) danej zabezpieczonej jednostki pamięci (20) lub do jego agenta (51) przez sieć przesyłania informacji (70);- sprawdzania pakietu danych z żądaniem informacji o położeniu (60) przychodzących do partnera kontrolującego (50) danej zabezpieczonej jednostki pamięci (20) lub jego agenta (51) i identyfikowania zabezpieczonej jednostki pamięci (20), - przesyłania w oparciu o identyfikowanie zabezpieczonej jednostki pamięci grupy instrukcji do urządzenia komunikacyjnego (10) przez sieć przesyłania informacji (70), a przez to zainstalowania unikalnie dostępnych zawartości informacji (22) w danej zabezpieczonej jednostce pamięci (20), i - informowania dostawcy usług (30) o zainstalowaniu unikalnie dostępnej zawartości informacji (22) i wysyłania do dostawcy usług (80) pakietu danych dostępowych (30).
- 2Sposób według zastrzeżenia 1, znamienny tym, że określa się informację kontaktową partnera kontrolującego (50) danej zabezpieczonej jednostki pamięci (20) bezpośrednio z początkowego pakietu danych (40).
- 3Sposób według zastrzeżenia 1, znamienny tym, że określa się informację kontaktową partnera kontrolującego (50) danej zabezpieczonej jednostki pamięci (20) ze zdalnych baz danych przy użyciu informacji pojawiających się w początkowym pakiecie danych (40) jako adres.
- 4Sposób według któregokolwiek z zastrzeżeń 1-3, znamienny tym, że informacje uzupełniające (42) odpowiednie do identyfikowania urządzenia komunikacyjnego (10) połączonego z zabezpieczoną jednostką pamięci (20) i / lub użytkownikiem urządzenia komunikacyjnego (10) i / lub dostawcą usług (30) zawarte są w początkowym pakiecie danych (40).
- 5Sposób tworzenia unikalnie dostępnego obszaru pamięci (22) do lokalizacji zawartości informacji dostawcy, umieszczonej w zabezpieczonej jednostce pamięci (20) urządzenia komunikacyjnego (10) mającego jednostkę centralną (11) i wymienioną zabezpieczoną jednostkę pamięci (20), który to sposób obejmuje wymianę danych z inną stroną przy pomocy urządzenia komunikacyjnego (10), w wyniku czego tworzony jest w zabezpieczonej jednostce pamięci (20) urządzenia komunikacyjnego (10) nowy unikalnie dostępny obszar pamięci (22); i zapewnienie dostępu do nowego unikalnie dostępnego obszaru pamięci (22) dla upoważnionej strony, znamienny tym, że zawiera etapy:- tworzenia początkowego pakietu danych z żądaniem informacji o położeniu (60) z informacji zarejestrowanych (41) odpowiednich do zidentyfikowania danej zabezpieczonej jednostki pamięci (20) i z informacji uzupełniających (42) do utworzenia unikalnie dostępnego obszaru pamięci (22) służącego do odbioru zawartości informacji, a następnie - wysyłania początkowego pakietu danych z żądaniem informacji o położeniu (60) do partnera kontrolującego (50) danej zabezpieczonej jednostki pamięci (20) lub do jego agenta (51) przez sieć przesyłania informacji (70) przy użyciu informacji zarejestrowanych zawierających dane kontaktowe partnera kontrolującego (50);- sprawdzania pakietu danych z żądaniem informacji o położeniu (60) przychodzących do partnera kontrolującego (50) lub jego agenta (51) i identyfikowania zabezpieczonej jednostki pamięci (20), - przesyłania w oparciu o identyfikowanie zabezpieczonej jednostki pamięci grupy instrukcji do urządzenia komunikacyjnego (10) przez sieć przesyłania informacji (70), a tym samym tworzenia unikalnie dostępnego obszaru pamięci (22) w danej zabezpieczonej jednostce (20) pamięci, - informowania operatora przenośnego urządzenia komunikacyjnego (10) lub innej strony określonej przez operatora w celu utworzenia unikalnie dostępnego obszaru pamięci (22) oraz wysłania operatorowi lub innej stronie pakietu danych dostępowych (80).
- 6Sposób według któregokolwiek z zastrzeżeń 1-5, znamienny tym, że unikalnie dostępna zawartość informacji umieszczona jest przez tworzenie unikalnie dostępnego obszaru pamięci (22), i przez włączenie w pakiet danych z żądaniem informacji o położeniu (60) danych o położeniu (62) dotyczących wymiaru unikalnie dostępnego obszaru pamięci (22), jaki ma być tworzony, i korzystnie informacji uzupełniających (42) odpowiednich do zidentyfikowania urządzenia komunikacyjnego (10) i / lub dostawcy usług (30).
- 7Sposób według zastrzeżenia 6, znamienny tym, że na podstawie danych o położeniu (62) występujących w pakiecie danych z żądaniem informacji o położeniu (60) i odnoszących się do wielkości unikalnie dostępnego obszaru pamięci (22), który to unikalnie dostępny obszar pamięci (22) o początkowo ustalonej wielkości wyznaczony jest w zabezpieczonej jednostce pamięci (20).
- 8Sposób według zastrzeżenia 1, w której unikalnie dostępna zawartość informacji umieszczona jest poprzez utworzenie obszaru pamięci (22) o ograniczonym dostępie do umieszczenia unikalnie dostępnej zawartości informacji.
- 9Którykolwiek ze sposobów według zastrzeżeń 1-8 znamienny tym, że informacje zarejestrowane (41) obejmują co najmniej serię znaków identyfikujących daną zabezpieczoną jednostkę pamięci (20) i / lub serię znaków identyfikujących urządzenie komunikacyjne (10) i / lub serię znaków, które mogą służyć do identyfikowania partnera kontrolującego (50) i / lub serię znaków identyfikujących użytkownika urządzenia komunikacyjnego (10).
- 10Którykolwiek ze sposobów według zastrzeżeń 1-9 znamienny tym, że informacje uzupełniające (42) obejmują co najmniej serię znaków identyfikujących, które mogą być użyte do identyfikowania partnera kontrolującego (50) i / lub serię znaków identyfikujących użytkownika urządzenia komunikacyjnego (10) i / lub serię znaków identyfikujących urządzenie komunikacyjne (10) i / lub serię znaków identyfikujących daną zabezpieczoną jednostkę pamięci (20).
- 11Którykolwiek ze sposobów według zastrzeżeń 1-10 znamienny tym, że wykorzystywana jest sieć przesyłania informacji (70) do komunikacji realizowanej z dostawcą usług (30) sprawującym nadzór nad zawartością informacji i / lub partnerem kontrolującym (50) danej zabezpieczonej jednostki pamięci (20) lub jego agenta (51), a przez to do przekazywania początkowego pakietu danych (40) i / lub pakietu danych z żądaniem informacji o położeniu (60).
- 12Którykolwiek ze sposobów według zastrzeżeń 1-10 znamienny tym, że wykorzystywany jest interfejs (90) wspomagający bezpośrednią transmisję danych celem przesyłania danych do dostawcy usług (30) sprawującym nadzór nad zawartością informacji i / lub partnerem kontrolującym (50) danej zabezpieczonej jednostki pamięci (20) lub jego agenta (51), a przez to do przesyłania początkowego pakietu danych (40) i / lub pakietu danych z żądaniem informacji o położeniu (60).
- 13Którykolwiek ze sposobów według zastrzeżeń 1-12 znamienny tym, że dane kontaktowe odnoszące się do danych kontaktowych partnera kontrolującego (50) przynależnych do zabezpieczonej jednostki pamięci (20) przechowywane są w identyfikatorze sieci informacyjnej znajdującym się w zabezpieczonej jednostce pamięci (20).
- 14Urządzenie komunikacyjne, realizujące wszystkie etapy związane z urządzeniem komunikacyjnym według którejkolwiek ze sposobów według zastrzeżeń od 1 do 13, które to urządzenie komunikacyjne (10) ma jednostkę centralną (11) i zabezpieczoną jednostkę (20) pamięci, znamienne tym, że informacje zarejestrowane (41) i informacje uzupełniające (42) zapisywane są w urządzeniu komunikacyjnym (10), przy czym informacje zarejestrowane (41) zawierają dane odpowiednie do identyfikowania zabezpieczonej jednostki pamięci (20) i zawierają dane do kontaktowania się z partnerem kontrolującym (50) danej zabezpieczonej jednostki pamięci (20) przez sieć przesyłania informacji oraz informacje uzupełniające (42) zawierające dane do identyfikowania urządzenia komunikacyjnego (10), przy czym urządzenie komunikacyjne (10) przystosowane jest do:- wykorzystywania informacji zarejestrowanych (41) oraz informacji uzupełniających (42) do tworzenia pakietu danych (40, 60) oraz - wysyłania pakietu danych (40, 60) adresatowi wybranemu z grupy obejmującej dostawcę usług (30), partnera kontrolującego (50) i jego agenta (51).
Independent claims14
56 paragraphs, as filed
The present invention relates to a method for determining a uniquely accessible memory region and a method for installing uniquely available data content in a secure storage unit managed by an external controlling partner. The invention further relates to a communication device including a protected memory unit.
The object of the invention relates to a method for determining a uniquely accessible memory region for receiving information, the storage area of which is to be located in a protected memory unit of the communication device, during which the data exchange is carried out by means of a communication device that has a central unit and a protected memory unit, comprising at least one memory register that is associated therewith, whereby a new uniquely accessible memory region is created in the secure storage unit of the communication device, and access is provided to the service provider.
The subject of the invention also relates to a method of locating the content of information in a protected memory unit of a communication device, during which, by means of a communication device that has a central unit and a protected memory unit containing at least one memory register that is associated with it, it takes place. data exchange with the service provider, as a result of which a new uniquely accessible content of information is installed in the secure communication unit of the communication device, and access is provided to the service provider.
[0004] As a result of the development of communication devices, in particular mobile phone sets as well as processor cards, an increasing range of services for communication devices is available to users . Some of these services are already included in the basic design of the communication device, but there are also services regarding the content of information which, in a given case, must or are preferably downloaded later to the user's communication device based on the user's choice, This is done in a secured memory unit.
[0005] However, according to the prior art, a general area of secure memory suitable for receiving such content information is associated with a single person and is substantially under the supervision of that person. However, such circumstances are disadvantageous both for providers of communication devices and for their users. This is because the protected memory unit is not used properly and as required in a large number of cases. The protected memory unit located in the communication device generally consists of a single memory area, or if, despite this, the partial areas are separated from each other, they are divided by the manufacturer himself during the production of the processor cards, because then neither the supplier, nor even the user is able to reformat them. This practice may cause the entire card's capacity or some areas of memory to remain unused, because during production, you can not know the real commercial requirements of the services in question, and thus unused applications are placed on the card, whereas in the case of the service Users are looking for they are not being introduced there.
[0006] US 2002/053090 discloses a device receiving data having a memory unit in which an exclusive storage area can be secured for a service provider, such as a broadcast service provider. However, the exclusive storage area is secured (or deleted) by a program running on the device receiving the data. Because the exclusive storage area is managed locally and there is no external control side, the exclusive storage area is more vulnerable to manipulation, which makes it unsuitable for use in connection with services requiring a high level of security.
The object of the solution according to the invention was to eliminate the unfavorable practices of using secure memory units placed in communication devices and to create procedures by which uniquely available memory areas for receiving different content of information can be dynamically created after producing the card and entering it for distribution, or stopped if necessary, and in such a way that the initiator of creating new areas and the issuer of the basic data required for this could be the user of the communication device, and so that he could use his own communication device to implement the procedure.
[0008] The object was further to enable the content of information to be installed on a well-defined portion of a defined memory area of a memory unit, for information service providers containing different content of information, isolated from each other and isolated from the cardholder, for the data and information required in appropriate security frameworks, are provided in the simplest form and with the simplest access.
[0009] Moreover, another purpose for the secure installation of the unique available content of the user-initiated information communication device was that it could be performed even when the secured memory unit can be treated only as a single unit.
The recognition which led to the method according to the invention consists in the fact that, directly or indirectly, for example, in a database that facilitates searching in the database, the contact information of the card manufacturer or control partner in a specific data group of the protected memory unit and using them data, the controlling partner is notified of information regarding the device and / or the operating environment and / or user and / or information service provider, and then after the chip card has been manufactured and delivered to the user it becomes possible to create uniquely accessible memory areas in the secured a memory unit, in addition, authorizing access to a uniquely accessible memory region formed for a predetermined portion, e.g., a service provider,so the task can be solved.
[0011] The recognition also includes that, with the unique location of suitably selected data elements and the novel application of coding solutions, it can also be achieved that one or more specific uniquely defined memory areas are created by a remote communication connection in such a way that only the page or the pages designated by the user of the communication device to read the contents of the information, have access to them, and thus, the desired and required level of data protection can be appropriately solved.
[0012] The idea of the invention also includes recognizing that if data packets with corresponding content are created and transmitted in a suitable manner to a suitable location, the uniquely available content of the information may reside in a single non-divided part of the protected memory unit to which they have access. only designated pages, so that the task can be solved in this way.
[0013] According to a predetermined purpose, the method according to the invention for establishing a uniquely accessible memory area for receiving information, the storage area of which should be in a protected memory unit of the communication device, during which data exchange is carried out by means of a communication device that has the central unit and the protected storage unit comprises at least one memory register associated with it, resulting in a new uniquely accessible memory area in the secured storage unit of the communication device, and access is provided to the service provider - in this way that to establish a uniquely accessible memory area for receiving information content,a data packet is created from the registered information relevant to identify the secured storage unit and from the supplementary information, and then the initial data packet is forwarded to the service provider to supervise the information content, the service provider testing the initial data packet during which the initial data packet is identified by the contact information of a controlling partner of a given secured storage unit, and a data packet is sent with a request for location information to a controlling partner of a given secured storage unit or its agent, in which data packet with requesting location information appear at least the data suitable for identification of the protected memory unit concerned,and then a data packet is interpreted with a request for location information appearing at the controlling partner of a given secured storage unit or its agent, and depending on the result of interpretation, a uniquely accessible memory area is created in a given secured storage unit, and then the service provider is informed as to the existence of a uniquely accessible memory area and an access data packet is sent to it that provides access.and then the service provider is informed of the existence of a uniquely available memory area and an access data packet is sent to him that provides access.and then the service provider is informed of the existence of a uniquely available memory area and an access data packet is sent to him that provides access.
[0014] Another feature of the method according to the invention may be that the contact information of the controlling partner of a given secure storage unit is determined directly from the initial data packet.
[0015] In a further embodiment of the method, the contact information of the controlling partner of a given secure storage unit is determined from a remote database using the information appearing in the initial data packet as an address.
[0016] In the case of a different, different embodiment of the method, supplementary information suitable for identifying the communication device connected to the secure storage unit and / or user of the communication device and / or the service provider is included in the initial data packet.
[0017] Also according to the object, another method according to the invention is shown in order to establish a uniquely accessible memory area for locating the content of information contained in a protected memory unit of the communication device, during which data exchange is carried out by means of a communication device that has a central unit and a protected storage unit including at least one memory register associated with it, resulting in a new uniquely accessible memory area of the secured communication unit of the communication device and access to the authorized party is provided for it - in principle,that a data packet with a location information request is created containing appropriately logged information to identify a given secured storage unit to create a uniquely accessible memory area for receiving information content and supplementary information, then the data packet with the location information request is forwarded to the controlling partner of the secure data the memory unit or its agent, and the controlling partner or its agent is interpreted as a data packet with a request for location information, and then, depending on the interpretation result, a uniquely accessible memory area is created in the given protected memory unit,whereupon the operator of the portable communication device or other party determined by him / her is informed of creating a uniquely-accessible memory area, and then an access data packet is sent to him / her providing access.
[0018] From a method viewpoint, it may be advantageous if the location data relating to the size of the uniquely accessible memory area and, where appropriate, supplementary information suitable for identifying the communication device and / or the service provider are included in the data packet from requesting position information, and furthermore, if, based on the location data present in the data packet, requesting location information and relating to the size of the uniquely available memory region, the uniquely accessible memory area of the initially determined amount is determined in the secured memory unit.
Also according to a predetermined purpose, the method according to the invention for locating the information content in a secure communication unit of the communication device, during which data exchange is carried out with the service provider by means of a communication device that has a central unit and a protected memory unit containing at least one a memory register that is associated with it, as a result of which a new uniquely accessible content of information is installed in the secure communication unit of the communication device, and access is provided to the service provider to it - based on the principle that the initial data packet is created from registered information adequate to identify a given secure storage unit and supplementary information to the location of the uniquely accessible information content,and then the initial data packet is forwarded to the service provider supervising the data content, and the service provider is tested the initial data packet during which, using the initial data packet, the contact information of the controlling partner of the given protected storage unit is identified, and the data packet is then sent. with requesting location information to a controlling partner of a given secured storage unit or its agent, in which data packet with requesting location information at least data suitable to identify a given protected storage unit appears, and then a data packet with a request for information about the data is interpreted. position appearing at the controlling partner of a given secured storage unit or its agent,and then, depending on the result of the interpretation, the uniquely available data content is located in a given secured memory unit, whereby the service provider is informed about the location of uniquely available information content and an access data packet is sent to it, which provides access.
[0020] In yet another embodiment of the invention, the recorded information includes at least a series of characters identifying a given secure storage unit and / or a series of characters identifying the communication device and / or a series of characters that can be used to identify the controlling partner and / or a series of identifying characters. the user of the communication device, while the complementary information comprises at least a series of characters that can be used to identify the controlling partner and / or a series of characters identifying the user of the communication device and / or a series of characters identifying the communication device and / or a series of characters identifying the security unit being protected.
[0021] In yet another embodiment of the method, the information transmission network or interface supporting direct data transmission for communication with a service provider supervising the content of information and / or the controlling partner of a given protected storage unit is used, and thus for forwarding the initial message. a data packet and / or a data packet with a request for location information.
[0022] In a preferred embodiment of the invention, a group of CPLC characters is used to identify a protected memory unit and / or a related control partner, in addition data relating to contact details of a controlling partner belonging to a secured memory unit are stored in the information network identifier finding in a protected memory unit.
[0023] In the case of the possible implementation of the methods, the service provider and the controlling partner are the same party.
The most important advantage of the methods according to the invention is that in the case where they are used, it becomes possible to reformat or simply reformat the memory area of the protected memory unit, even repeatedly, thus creating independent memory regions separated from each other in such a way that the required exchange of data between partners who are unknown to each other becomes possible with simple logistical support, without any separate administrative operations.
[0025] The advantage of this is that the entire protected memory unit becomes ready for use by fully independent providers of information services, and the information content - even without direct physical connection between participants - can in all cases be retrieved to the memory area which it is uniquely available, and unavailable to other sites. Therefore, the use of a secured memory unit can be optimal, which from the user's point of view allows access and use of several applications.
[0026] In the following, the set of equipment used for the method according to the invention is presented in more detail on the basis of exemplary embodiments and drawings.
Fig. 1 is a block diagram of a possible embodiment of a set of equipment used in this method.
[0027] Fig. 1 shows a drawn set of devices with which the method according to the invention can be carried out. You can see two communication devices 10, one of which is a mobile phone, the other is a portable mini-computer. The individual communication devices 10 can be connected via the information transmission network 70 and / or the interface 90 to the service provider 30 and / or the controlling partner 50, and in a given case the controlling partner 50 with its agent 51.
[0028] The cellular telephone serving as a communication device 10 comprises a central unit 11 which controls the operation of the communication device 10, and a protected memory unit 20, which is connected to the central unit 11, and further a second memory area 12. The second memory area 12 comprises a register 21, while the protected memory unit 20 includes a uniquely accessible memory region 22 to be formed in accordance with the method.
In the present case, the memory register 21 includes the first encryption key 21a, while the second encryption key 21b is in a uniquely accessible memory region 22. The first encryption key 21a and the second encryption key 21b together form a key pair. Of course, it is conceivable that the first encryption key 21a and the second encryption key 21b are different. Then it is a pair of asymmetrical keys. It is however possible that the first encryption key 21a and the second encryption key 21b are the same. In this case, the pair of keys is symmetrical. The external encryption key 32 is in the second memory area 12 which belongs to the service provider 30 and which can be downloaded during the implementation of the method to other storage areas 12 via the information transmission network 70.
[0030] In a given case, the external encryption key 32 and the first encryption key 21a may also be in a protected memory unit 20.
The starting data packet 40 is also associated with a communication device 10 that contains registered information 41 and supplementary information 42. The registered information 41 and supplementary information 42 constitute a mass of data that can be forwarded to the service provider 30 or even to the controlling partner 50 , either via the information transmission network 70 or via the interface 90.
[0032] The registered information 41 or supplementary information 42 of the initial data packet 40 includes direct or indirect contact information of the checking partner 50, its information network identifier, which may be information that is suitable for identifying the communication device 10 and the service provider 30, Po6 too, they may include series of characters for identifying a protected memory unit 20 and a series of characters identifying the user of the communication device 10. The purpose of this initial data packet 40 is to clearly determine, during implementation of the method, which secured memory unit 20 on which a unique memory area is available. 22 is to be created, and who or which controlling partner 50 can do so.
[0034] It should be noted here that the identification of the controlling partner 50 does not necessarily have to be carried out directly. One can also imagine a solution in which the controlling partner 50 is represented by the so-called An "indicator" which, for example, indicates a given computer database element with remote access and this element contains actual direct details about the contact of the controlling partner 50.
The method also includes a solution for the data of the controlling partner 50 stored in the remote available database, which gives correct information even when the person at the controlling partner 50 changes. Accordingly, in the case of a change of the controlling partner 50 exercising control over the control partner by a secure storage unit 20, the previous control partner 50 initiates a database update by identifying the controlling partner 50 of the secure storage unit 20, and inserts the protected storage unit 20 into a transient state to change the access rights to the protected storage unit 20, and at the same time enables a new controlling partner 50 of a given secure memory unit 20 taking over the authorization to access a protected memory unit 20,and then the new control partner 50 updates the permission to access the secured storage unit 20, after which the activation of the identifier indicating the new control partner 50 in the database is used to identify the controlling partner 50 of the secure memory unit 50.
[0036] The access data pack 80 is associated with the controlling partner 50, which access data packet 80 means that the information group by means of which the required unique memory area 22 or the uniquely available content of information in the secure storage unit 20 of the communication device 10 becomes available.
[0037] In addition to the external encryption key 32, the service provider 30 has an encoded data packet 31 that is required to personalize the uniquely-accessible memory area 22 in the protected memory unit 20, and in that case includes the information content required by the user of the communication device 10 in such secure a form that can not be interpreted by unauthorized persons. A data packet with a request for location information 60, which may include identification data 61 and location data 62, is also associated with the service provider 30. The identification data 61 includes this information by which a specific secured memory unit 20 can be clearly identified, or optionally found,
[0038] The methods of the invention are set forth in more detail below on the basis of examples.
Example 1:
[0039] In this embodiment of the method according to the invention, the aim was to create a uniquely-accessible memory area 22 at 256 Kb of a secure storage unit 20 of the communication device 20 to receive information content, including an application servicing a mobile wallet. Accordingly, using the communication device 10, an initial data packet 40 was created, the registered information 41 which was entered to be direct contact information about the manufacturer of the protected memory unit 20, i.e., about the controlling partner 50, and further information identifiable by the secured memory units 20, except that the supplementary information 42 is the identification data of the communication device 10.
[0040] Once the initial data packet 40 has been collected by the communication device 10, it is sent to the service provider 30 with the mobile wallet application via the information transmission network 70. Upon receipt of the initial service packet 40 at the service provider 30 using the registered information 41 and of complementary information 42, the application for the requesting party, the communications device 10 and the protected memory unit 20 are identified, and the contact information of the controlling partner 50 that controls the protected storage unit 20 is defined.
[0041] Next, after the collected data packet with the request of the service provider location information 30, which packet contains data 61 as identification data of the protected memory unit 20, the identification information of the communication device 10 that includes the protected storage unit 20, as well as the service provider identifier 30. After that, the data packet with the request for location information 60 is sent to the controlling partner 50 also via the information transmission network 70, where the content of the data packet with the request for location information 60 is checked.
After analyzing the data packet with the request for location information 60, the protected memory unit 20, in which a uniquely accessible memory region 22 had to be formed, is identified, and on this basis, instruction groups are forwarded to the communication device 10 containing the protected unit a memory 20 with a uniquely-accessible memory region 22 formed therein.
[0043] With the creation of the uniquely-accessible memory region 22, the service provider 30 is notified of creating a uniquely-accessible memory area 22 by means of the information transmission network 70, and the access data packet 80 containing authorization parameter access operations to the uniquely-accessible memory area 22 is sent to the In this way, in the communication device 10, a unique memory area 22 requested by the user of the communication device 10 to which only the service provider 30 has access is created in the given secure storage unit 20 of the communication device 10.
Example 2:
For this embodiment of the method according to the invention, unlike the one shown in the previous procedure, the contact details of the controlling partner 50 were first determined based on the data stored in the protected memory unit 20 located in the palmtop communication device.
[0045] In order to obtain this data, a part of the database containing data of an undertaking involved in the supervision of multiple protected memory units 20 is obtained from the information located in the secured memory unit 20, from which the direct contact information of the manufacturer acting as the control partner of the given data has been obtained. Having this information, a data packet was created requesting position information 60 from registered information 41 suitable for identifying a protected memory unit 20 and from complementary information 42 identifying the communication device 10 and, moreover, from position data of the uniquely accessible memory region 22 having the desired size in the protected memory unit 20, and moreover,from details about the service provider 30, creating information content to be installed in a uniquely accessible memory area 22.
[0046] The data packet with requesting location information 60 was communicated via the interface 90 directly to the controlling partner 50, where after analysis of the information group, a unique memory area 22 of the desired size was created in the protected memory unit 20 of the communication device 10 and the service provider 30 this information was communicated by the information transmission network 70 and an access data packet 80 was simultaneously sent there. In this way a uniquely accessible memory area 22 was created in the secure storage unit 20 of the communication device capable of receiving information content offered by the service provider 30 that has not been divided in a protected memory unit 20 at the time of sale of the communication device 10.
Example 3:
[0047] With this version of the method, it has been made possible to protect a uniquely accessible memory region 22 formed in the secure storage unit of the communication device 10 in the following manner. It is to be emphasized that the procedure according to the invention is independent of what other procedural steps have been used to make the memory area 22 available in a protected memory unit 20 uniquely accessible. In this way, it is possible to imagine a solution in which uniquely accessible memory areas are created 22 in the secure storage unit 20 of the respective communication device 10 so that an access data packet 80 required for this from the controlling partner 50 is obtained, and even the required data packet can be prepared on its own.
[0048] In a first step, a second encryption key 21b is installed in a uniquely accessible memory region 22 for receiving the content of information from the service provider 30, and then the first encryption key 21a is placed in the second memory area 12 of the communication device 10 thereby preparing data exchange, which can be protected with asymmetrical keys, - in the present case - comprising the first encryption key 21a and the second encryption key 21b. Next, an external encryption key 32 was requested from the service provider 30 containing the given information content and downloaded to a second storage area 12 of the communication device 10.
In the uniquely accessible memory region 22, the encoded data packet 31 has been decoded by means of another encryption key 21b, and thus in the uniquely accessible memory region 22 the service provider has been allowed to personalize the designated memory area. Example 4:
[0050] The same was done as in the previous version, with the difference that the first encryption key 21a and the second encryption key 21b are the same, and thus the encryption was carried out using symmetric keys.
Example 5:
In this version of the method, similar to the previous examples was followed, with the exception that no uniquely accessible memory areas were created in the protected memory unit 20, but when the required information content is retrieved, access to the information content is only allowed to authorized parties using using an appropriately selected encryption key.
[0052] Based on the presented system and procedural examples, it can be seen that the methods of the invention can be used with any communication device for subsequent determination, transformation of uniquely accessible memory areas of a protected memory unit mounted in communication devices and for secure downloading of information content to these uniquely available areas of memory or they can be used to locate information content in common places of memory, but with the authorization of individual access.
24 members in 6 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| P0700685 | Hungary | A | |
| 2008000114 | Hungary | W |
Members24
| Document | Office | Kind | |
|---|---|---|---|
| HU0700685D0 | Hungary | D0 | |
| HU0700685D0 | Hungary | D0 | |
| HU0700685A2 | Hungary | A2 | |
| HUP0700685A2 | Hungary | A2 | |
| WO2009095724A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2215581A1 | European Patent Office (EPO) | A1 | |
| EP2215581A1 | European Patent Office (EPO) | A1 | |
| US2010275269A1 | United States of America | A1 | |
| US2010275269A1 | United States of America | A1 | |
| US2013042325A1 | United States of America | A1 | |
| US2013042325A1 | United States of America | A1 | |
| US9298646B2 | United States of America | B2 | |
| US9298646B2 | United States of America | B2 | |
| US2016212149A1 | United States of America | A1 | |
| US2016212149A1 | United States of America | A1 | |
| EP2215581B1 | European Patent Office (EPO) | B1 | |
| EP2215581B1 | European Patent Office (EPO) | B1 | |
| US9686290B2 | United States of America | B2 | |
| US9686290B2 | United States of America | B2 | |
| HU230695B1 | Hungary | B1 | |
| ES2640342T3 | Spain | T3 | |
| ES2640342T3 | Spain | T3 | |
| PL2215581T3This record | Poland | T3 | |
| PL2215581T3This record | Poland | T3 |
Numbers
- Publication
- 2215581
- Application
- 8871683
Titles2
- English
- METHOD OF LOCATING INFORMATION CONTENT WITH LIMITED ACCESS IN THE SECURE STORAGE UNIT OF A COMMUNICATION DEVICE
- Polish
- Sposób lokalizowania zawartości informacji o ograniczonym dostępie w bezpiecznej jednostce pamięci urządzenia komunikacyjnego
Classification
- CPC, 5
- G06F12/1408
- H04L63/123
- G06F12/1416
- H04L63/20
- H04L63/04
- IPC, 2
- G06F21 00
- H10D62 10