Wireless device, user access control client request method and access control client method
Abstract
FIELD: radio engineering, communication. SUBSTANCE: invention relates to wireless communication and specifically to a method for secure access control client transmission. The method includes requesting a user access control client from a wireless network, wherein the request is associated with a first acknowledgement certificate; receiving the user access control client and a second acknowledgement certificate, wherein the first and second acknowledgement certificates are issued by a trusted entity; and storing the user access control client in a safe element if the second acknowledgement certificate is valid; wherein the user access control client is stored in a particular segment from a plurality of segments making up the safe element, and subsequent modifications of the stored user access control client can be performed only using the second acknowledgement certificate; and access to the wireless network is limited (i) by access through the user access control client and (ii) user access control client requests. EFFECT: improved security. 22 cl, 8 dwg

Term
5.1 yearsleft in the term
Expires 28 October 2031.
- Priority
- Filed
- Granted
- Today
- Expires
22 claims: 3 independent, 19 dependent
- 1Беспроводное устройство связи, содержащее br / один или большее количество интерфейсов беспроводной связи, обеспечивающих возможность осуществления связи с по меньшей мере одной сетью; br / безопасный элемент, выполненный с возможностью хранения клиента управления доступом; br / интерфейс к безопасному элементу, который связан с криптографическим ключом и связанным с ним первым сертификатом; br / вычислительное устройство и br / устройство хранения, соединенное с возможностью обмена данными с вычислительным устройством и содержащее выполняемые компьютером инструкции, при этом выполняемые компьютером инструкции при их выполнении вычислительным устройством обеспечивают выполнение вычислительным устройством следующих действий:br / посредством интерфейса передают запрос одного или большего количества компонентов для клиента управления доступом, относящегося к по меньшей мере одной сети;br / принимают один или большее количество запрошенных компонентов и второй сертификат;br / верифицируют второй сертификат и br / в ответ на успешную верификацию второго сертификата сохраняют клиент управления доступом в безопасном элементе, причем клиент управления доступом сохраняют в индивидуальном сегменте из числа множества сегментов, из которых состоит безопасный элемент, и последующие модификации сохраненного клиента управления доступом могут быть выполнены только с использованием второго сертификата.
- 2Устройство по п.1, отличающееся тем, что клиент управления доступом включает один или большее количество электронных модулей идентификации абонента (eSIM);безопасный элемент включает электронную универсальную карту с интегральной схемой (eUICC), а каждый из указанных одного или большего количества модулей eSIM связан с международным идентификационным номером оборудования абонента (IMSI);и каждый из модулей eSIM дополнительно обеспечивает возможность установления безопасного соединения с сотовой сетью на основании, по меньшей мере частично, процедуры авторизации и согласования ключа (АКА).
- 3Устройство по п.2, отличающееся тем, что указанная по меньшей мере одна сеть включает сеть глобального стандарта мобильной связи (GSM).
- 4Устройство по п.2, отличающееся тем, что указанная по меньшей мере одна сеть включает сеть универсальной системы мобильной связи (UTMS).
- 5Устройство по п.2, отличающееся тем, что указанная по меньшей мере одна сеть включает сеть с множественным доступом с кодовым разделением 2000 (CDMA 2000).
- 6Устройство по п.1, отличающееся тем, что указанный запрос включает первый сертификат.
- 7Устройство по п.6, отличающееся тем, что криптографический ключ уникальным образом связан с первым сертификатом.
- 8Устройство по п.1, отличающееся тем, что криптографический ключ имеет асимметричный дополняющий ключ, который может распространяться открыто.
- 9Устройство по п.8, отличающееся тем, что указанный асимметричный дополняющий ключ обеспечивает безопасную передачу в беспроводное устройство связи.
- 10Устройство по п.1, отличающееся тем, что указанные один или большее количество компонентов включают клиент управления доступом, зашифрованный посредством сеансового ключа, а первый и второй сертификаты содержат соответственно первый и второй подтверждающий сертификаты.
- 11Устройство по п.10, отличающееся тем, что указанный сеансовый ключ сформирован случайным образом.
- 12Способ запроса пользовательского клиента управления доступом для использования с беспроводной сетью, включающий:br / запрос пользовательского клиента управления доступом из беспроводной сети, при этом запрос связан с первым подтверждающим сертификатом;br / прием пользовательского клиента управления доступом и второго подтверждающего сертификата, при этом первый и второй подтверждающий сертификаты выданы доверенной структурой;и br / сохранение пользовательского клиента управления доступом в безопасном элементе, если второй подтверждающий сертификат действителен;причем пользовательский клиент управления доступом сохраняют в индивидуальном сегменте из числа множества сегментов, из которых состоит безопасный элемент, и последующие модификации сохраненного пользовательского клиента управления доступом могут быть выполнены только с использованием второго подтверждающего сертификата;а br / доступ к беспроводной сети ограничен (i) доступом посредством пользовательского клиента управления доступом и (ii) запросами пользовательских клиентов управления доступом.
- 13Способ по п.12, отличающийся тем, что пользовательский клиент управления доступом включает электронный модуль идентификации абонента (eSIM).
- 14Способ по п.12, отличающийся тем, что первый и второй подтверждающий сертификаты уникальным образом связаны с первой и второй криптографическими парами ключей соответственно.
- 15Способ по п.14, отличающийся тем, что первая и вторая криптографические пары ключей содержат асимметричные пары ключей.
- 16Способ по п.12, отличающийся тем, что пользовательский клиент управления доступом зашифрован посредством сеансового ключа.
- 17Способ выполнения клиента управления доступом, включающий:выполнение самозагружаемой операционной системы, которая выбирает безопасный сегмент, связанный с клиентом управления доступом, причем клиент управления доступом обладает возможностью аутентификации в сети;br / верификацию безопасного сегмента, включающего общую операционную систему и клиент управления доступом;и br / выполнение общей операционной системы, которая загружает один клиент управления доступом.
- 18Способ по п.17, отличающийся тем, что клиент управления доступом включает электронный модуль идентификации абонента (eSIM).
- 19Способ по п.17, отличающийся тем, что шаг выбора включает идентификацию сети по умолчанию.
- 20Способ по п.19, отличающийся тем, что верификация включает проверку сертификата, связанного с безопасным сегментом.
- 21Способ по п.20, отличающийся тем, что безопасный сегмент включает одно или большее количество активных дополнений, каждое из которых связано с сертификатом.
- 22Способ по п.17, отличающийся тем, что шаг выбора включает выбор безопасного сегмента из множества безопасных сегментов, каждый из которых связан лишь с одним клиентом управления доступом.
Independent claims22
105 paragraphs in 5 sections, as filed
TECHNICAL FIELD OF THE INVENTION
The present invention relates generally to the field of wireless communication and data networks. In particular, the present invention provides in one exemplary aspect relates to a method and apparatus for secure modification of structure conservation and performance or customer access control.
BACKGROUND
Access control is required for secure communication in a wireless radio communication systems most of the prior art. For example, a simple access control scheme may include: (i) verification of the identification of the parties in communication and (ii) the allocation of access levels commensurate verified identification. In the context of an exemplary cellular communication system, such as universal mobile telecommunications system (Universal Mobile Telecommunications System, UMTS), the access control means customer access control is called a universal subscriber identity module (Universal Subscriber Identity Module, USIM), running on a physical universal card with integral scheme (Universal Integrated Circuit Card, UICC). Customer access control USIM performs subscriber authentication in a cellular network, UMTS. After successful authentication, the subscriber is allowed access to the cellular network. As used herein, the term "client access management" generally refers to a logical structure, implemented either in hardware or in software to control the access of the first device in the network. Common examples are customers access controls include the aforementioned Universal Subscriber Identity Module (USIM), a Subscriber Identity Module CDMA (CSIM), identification module multimedia services protocol IP (ISIM), a subscriber identity module (SIM), a removable Subscriber Identity Module (RUIM), etc .P.
Typically, the USIM module (or the whole module SIM) has a well-known procedure of authentication and key agreement (AKA, Authentication and Key Agreement), which is verified and decrypted data, and applicable security software initialization. In particular, the USIM module must simultaneously (i) to successfully respond to the remote verification request for confirmation of the identification of the network operator and (ii) transmit probe requests on network identification verification.
However, the existing subscriber identity module have many flaws and shortcomings. Firstly, the software subscriber identity module SIM rigidly programmed physical media UICC card, and the new subscriber needs to change the UICC card of the module identification number. This can be a drawback for the operators and the mobile communication network and the subscribers, for example, if the authentication procedure "broken" (e.g., by hostile hacking), the subscriber must be allocated a new card UICC, wherein the process is time consuming and costly. Furthermore, for the reasons described herein below, a physical subscriber identity module recognizes only one trusted structure, in particular mobile network operator (MNO), with which it can communicate. Thus, there is currently no any way to enable the system programming is performed after deployment, except for using existing trusted relationship between a device and the mobile network operator. For example, third-party developers subscriber identity modules wishing to provide new or updated software subscriber identity module, do not have this opportunity because of the inflexibility of physical media card Subscriber Identity Module, as well as the inability to establish a trusted relationship between them and the subscriber identity module. This critical time control significantly limits the number of potential users and the opportunities offered by providers subscriber identification module.
Thus, the need for new solutions for distribution performed after deployment and modification of subscriber identity modules. Ideally, such decisions should allow the mobile device to make and implement changes in the subscriber identity module, the device is in the "field" (after deployment). In addition, the required methods and apparatus should support the other functions, including such as support multiple profiles subscriber identification module, flexibility, updates, etc.
Overall, however, these methods and apparatus are needed to ensure the safe modification, maintenance and implementation of customer access control. Need a way to modify the access control of the client to support features such as multiple access subscriber profiles, update the device safe, alternative methods to deliver services to the subscriber, etc. In addition, because of the importance of access control and the ability to hide the theft and use of services is the main task of safe ways to implement such changes.
Disclosure of invention
The above objects are achieved in the present invention by providing an improved apparatus and method for secure modification, save and execute customer access control.
In a first aspect the present invention provides a wireless device. In one embodiment, the device includes one or more wireless communication channels, enabling communication with the at least one network through a customer access control secure element configured to store customer access control interface to a secure element comprising a cryptographic key and its associated confirming to him a certificate, a computing device and a storage device coupled with the possibility to communicate with the computing device and comprising computer executable instructions. At least a subset of computer-executable instructions further divided into one or more segments.
In one embodiment, these instructions while performing the computing device through an interface transmitting a request of one or more components for customer access control related to at least one network, wherein the request comprises confirming the certificate and a cryptographic key that accept one or more of the requested components, wherein said components are connected to the second confirmatory certificate verifying a second confirmation certificate and, in response to a successful verification of the certificate confirming the second downloadable client access control.
In a second aspect the present invention provides a method for mutual authentication. In one embodiment, the method comprises: a request of one or more components, wherein the request is associated with the first recording certificate receiving one or more components and a second confirmation of the certificate and loading one or more components if the second confirmation certificate is valid, wherein first and second confirmation certificates issued by a trusted structure.
In a third aspect the present invention provides a method for performing access control of the client. In one embodiment, the method comprises performing the first bootable operating system that selects the safest segment associated with only one client access control, verification of the secure segment, which includes a common operating system and a single client access control, and execution of a common operating system that loads a client access control. The client has the ability to control access authentication in the network, such as the external network.
In a fourth aspect, the present invention provides a mobile device. In one embodiment, the mobile device is adapted to request, receive, and use the data structures of the virtual electronic or subscriber identity module using a bootable operating system architecture.
In a fifth aspect the present invention provides a computer-readable device. In one embodiment, the device includes a storage medium with at least one running thereon a computer program, said at least one program is capable of receiving, processing requests and providing electronic or virtual subscriber identification module using a bootable operating system.
In a sixth aspect the present invention provides a system of sharing among users of virtual or electronic subscriber identity modules. In one embodiment, the system includes a device for the delivery of the components of the operating system that supports the transmission of the electronic subscriber identity module on the network such as the Internet, or MAN, or WLAN.
Other features and advantages of the present invention will become apparent to those skilled in the art who are familiar with the accompanying drawings and the detailed description of exemplary embodiments below.
BRIEF DESCRIPTION OF DRAWINGS
1 is a diagram showing an example of procedure of authentication and key agreement (AKA) using a subscriber identification module in the prior art.
2 is a flowchart of one embodiment of a method of assigning a pair of device keys program structure (e.g., user equipment (UE, user terminal) or a third-party software vendor provider subscriber identification module, etc.) in accordance with the invention.
3 illustrates an example of a transaction for the secure transmission time components between the UE and the provider of the software in accordance with one embodiment of the invention.
4 is an embodiment of a method for performing secure electronic subscriber identity module (eSIM) in accordance with the invention.
4A illustrates an embodiment of an architecture bootable operating system, card modules and eUICC eSIM in accordance with the invention.
5 is a flowchart of one embodiment of a generalized method for modifying and maintaining safe components for use with the customer access control.
6 is a flowchart of one embodiment of a generalized method for performing secure and preserve the components for use with the customer access control in accordance with the invention.
7 is a block diagram of an exemplary apparatus for implementing the proposed method.
The copyright in all drawings © 2010 Apple Inc. All rights reserved.
EMBODIMENTS
Further reference is made to the drawings in which like reference numerals refer to like elements throughout.
Overview
The present invention provides a safe, including (protected) methods and apparatus by which a user device and any trusted parties can mutually verify the structure of each other. Also, a method and apparatus that allow any side of the frame structure be trusted even after the user device sent to the consumer. For example, the mobile device (eg, a UE network UMTS) can identify an electronic subscriber identity module (eg, a virtual or electronic module SIM, further - module eSIM) third-party suppliers and initiate trusted two-way communication in order to acquire, obtain or upgrade their module eSIM . Likewise, a third party vendor eSIM module can verify that the UE is a trusted device and a secure module eSIM encoded for transmission. Trusted bidirectional communication based on a unique device key and validates the certificate, while, as described further herein, in one exemplary embodiment, the device is based on key cryptography using a public / private key.
Various aspects of the present invention are directed to providing secure receiving customer access control (fully or partially). In view of the important nature of the content access control for network operators in existing solutions used form factors of physical cards. However, the present invention provides a secure transmission of virtual or electronic customer access control (eg, modules eSIM), thereby eliminating the need for physical cards and associated restrictions.
Furthermore, in contrast to existing solutions, the present invention provides a content delivery client access control without pre-existing customer access control, which substantially increases the flexibility and usability of the user.
In yet another aspect of the invention a device (e.g., mobile user device) may be activated and to perform one of several stored customer access control (e.g., modules eSIM). In particular, when the module is loaded eSIM operating system (OS) only need to download the list of software required for the current runtime environment. This effect is isolated environment ("sandbox") enables the use of several modules eSIM in one and the same device without inappropriate access to other modules eSIM.
DETAILED DESCRIPTION OF EXEMPLARY EMBODIMENTS
Further detail exemplary embodiments and aspects of the present invention. Despite the fact that these aspects and embodiments are primarily discussed in the context of a subscriber identification module (SIM module) cellular networks, GSM, GPRS / EDGE or UMTS, one skilled in the art will appreciate that the present invention is not limited thereto. Rather, various aspects of the present invention may be applied to any wireless network (cellular or otherwise), which require secure modification, and performing preserving structures or customer access control.
It should also be understood that although herein the term "subscriber identity module" (e.g., module eSIM), this term is not intended to and does not require (i) used directly by the subscriber (i.e., the present invention can be used as a customer, and not by the subscriber), (ii) the presence of an individual (i.e., the present invention may be used on behalf of a group of people such as family immaterial or imaginary group, such as an enterprise), (iii) any material equipment or hardware "module ".
The operation known subscriber identity module (module SIM)
In the context of UMTS cellular networks of the prior art user equipment (UE) includes a mobile device and a universal subscriber identity module (USIM, Universal Subscriber Identity Module). The module USIM is a logical program structure stored in the physical universal integrated circuit card (UICC) and perform with her. The module USIM stores different information, such as subscriber information, as well as keys and algorithms used to authenticate with your network operator to obtain wireless service network. The software module USIM is based on the programming language Java Card ™. Language Java Card is a type of programming language Java ™, modified for the "implanted" devices such as cards (such as the above card UICC).
Overall card UICC USIM module is programmed to spread among subscribers, with pre-programming or customization specific to each network operator. For example, prior to deployment module USIM associated with the international identification number of the subscriber equipment (IMSI, International Mobile Subscriber Identify), the unique identifier to an integrated circuit card (ICC-ID, Integrated Circuit Card Identifier) and individual authentication key (K). The network operator stores this link to register contained in the network authentication center (AuC, Authentication Center). After personalizing the card UICC can be disseminated to users.
Referring to Figure 1 described in detail one exemplary procedure for authentication and key agreement (AKA, Authentication and Key Agreement) using the above module USIM in the art. The usual procedure of authentication the UE receives an identification IMSI number of the module USIM. The UE transmits the UE identification IMSI number to the serving network (SN, Serving Network) or a guest network operator core network. The serving network SN sends an authentication request to an authentication center AuC home network (HN, Home Network). Home network HN compares the received identification IMSI number to register authentication center AuC and receives the appropriate key K. The home network HN generates random number (RAND) and signs it with the key to the algorithm to generate the expected response (XRES). Home network HN further generates an encryption key (SK, Cipher Key) and integrity key (IK, Integrity Key), for use in the encryption and integrity protection, and authentication token (AUTN, Authentication Token) using different algorithms. HN Home Network sends an authentication vector consisting of random numbers RAND, a response XRES, the cipher key CK and an authentication token AUTN, the serving network SN. The serving network SN retains only the authentication vector for use in one-time authentication process. The serving network SN transmits the random number RAND and the authentication token AUTN to the user device UE.
After receiving the UE random number RAND and the authentication token AUTN module USIM verifies the authenticity of the authentication token AUTN. In the positive case the UE uses the received random number RAND to compute its own response (RES) using the stored key K, and the same algorithm, which is formed by the response XRES. The UE returns a response RES to the serving network SN. The serving network SN compares response XRES to the received response RES and, if they match, the serving network SN allows the UE to use the services of the wireless network operator.
Example of operation
The following describes various aspects of the present invention with reference to one example implementation. In the context of an exemplary embodiment of the present invention, instead of using a physical card UICC, as in the prior art, the card UICC simulate how the virtual or electronic structure, such as a software application, which will hereinafter be called electronic universal card with an integrated circuit (eUICC), which is contained in a secure element (for example, a secure microprocessor or storage device) in the user equipment UE. Map eUICC configured to store and manage multiple elements of the module SIM, hereinafter referred to as electronic subscriber identity module (eSIM). ESIM Each module is a software emulation of a typical module USIM and contains similar software and associated user data. Map eUICC chooses the module based on the identifier eSIM ICC-ID module eSIM. After the card eUICC select the desired module (required modules) eSIM, the UE can initiate authentication for wireless network services from the network operator, the corresponding module eSIM. Furthermore, each application module eSIM generally covers client access control such as the above modules USIM, CSIM, ISIM, SIM, RUIM etc. It is understood that each module eSIM associated with a user account, and thus, the module can be widely eSIM span multiple customer access control (for example, the module USIM and SIM module can be linked to one account module eSIM user).
As indicated above, in the previously described procedure module USIM in the art previously used to authenticate the key handed out to the core network (e.g., the above home network (HN), the serving network (SN) and Authentication Center (AUC) and the like) . Accordingly, the procedure module USIM necessarily a closed system for the network operator, as previously handed out the key should be carefully protected. In the present invention, by contrast, offer a safe way designed to ensure mutual trust relationship between the card and eUICC any party structure that allows any third party structure be trusted even after the deployment of user devices.
Accordingly, the present invention is in some respect makes considerably more stringent safety requirements, but also allows for much greater flexibility. Furthermore, those skilled in the art will appreciate that although various aspects of the present invention may be used virtual programming constructs (e.g., card eUICC, module eSIM), these advantages are not limited to these virtual embodiments. In contrast, the disclosed principles herein are equally applicable to secure modification conservation and performance management client access concluded including physical media card, special hardware protection etc.
Establish a trusted connection
Figure 2 illustrates one exemplary method of assigning key pair the device structure of the program (eg, map eUICC, third-party vendor software provider of SIM, etc.). In step 202, the program structure is assigned a cryptographic key pair public / private (for example, the algorithm Rivest, Shamir and Adieman (RSA)) and keep it in a physically secure safe element of the program structure, such as a map eUICC in the user device UE, secure database, a third-party software. For example, the card is programmed by the trusted eUICC structure or, alternatively, can form inside the key pair public / private during initial manufacture / activation.
To note, the key pair is a public / private based on the secret key to hide and distribute public keys. Scheme public / private key are called asymmetric because keys used for encryption and decryption are different, and thus, encrypt and decrypt the sides have a common key. In symmetric key schemes, by contrast, uses the same key (or keys are converted in a simple manner) and for encryption and decryption. The algorithm is RSA (Rivest, Shamir and Adieman) represents one of the types of cryptography key pairs public / private commonly used in the art, but it should be understood that the present invention is not limited to the RSA algorithm.
Cryptographic schemes public / secret may be used to encrypt a message and / or generating signatures. In particular, the message can be encrypted and decrypted by the secret key of public key, whereby it can be ensured that the message is not modified during transmission. Likewise, the signature generated using a private key can be verified public key, whereby it can be ensured that the structure forming the signature is trusted. In both cases, the private key is kept secret, and the public key is distributed freely.
In step 204 for a pair of key public / private issue confirmation certificate. For example, the trusted structure confirms the authenticity of the card eUICC and secrecy secret key by issuing a certificate attesting to the key pair cards eUICC. This key pair is a public / private key pair is now a device for card eUICC.
In one embodiment, confirming a certificate comprises a set of data, which may include, among other things: (i) identification information for the identification (the certifier) body, (i) the identification information for the device, (iii) the metadata describing algorithms certification, and / or ( iv) Appropriate public keys. These components can additionally be signed by the private key confirmer. In one embodiment, during normal operation, the digital signature is verified host for verification that the content is protected and it has not been made extraneous changes.
Since the device key pairs are asymmetric, public keys can be distributed without any harm to the security and integrity of secret keys. Accordingly, the device key and the certificate can be used for protection and verification of communication between the previously unknown to each other (eg, the card eUICC and the other side). Consider the following exemplary transaction for the secure transfer of run-time components between the card and eUICC software vendor (see Fig. 3).
In step 302 shown in Figure 3, the card module eSIM eUICC requests from third-party modules eSIM. Although in the example described secure transmission module application eSIM, other common examples of application runtime operating environment may include additions, full-scale operating system, etc.
In step 304, a third-party supplier of modules eSIM received device public key corresponding to the map eUICC, of confirming the certificate, such as confirming the certificate may be obtained from the database, by sending a request to the card eUICC etc. It should be noted that the corresponding private key card eUICC in this process will never be disclosed to third-party suppliers of modules eSIM.
In step 305 a third-party supplier of modules eSIM verifies confirmation certificate. In one exemplary embodiment, the confirmation certificate signed by a trusted uniquely structure (eg, a spokesman for Apple ™). After a third-party supplier of modules eSIM verify certificate proving he can be sure that the card is trusted eUICC trusted structures (for example, Apple ™), and therefore is safe, protected.
In step 306, a working runtime module eSIM encrypted and then signed by a third-party provider of software for a specific card eUICC, the corresponding user device UE. In other embodiments, the runtime workspace module eSIM first signed and then encrypted. In one exemplary embodiment, the supplier uses its own asymmetric key signatures and public / private key algorithm of RSA, as well as for signing the certificate chain module eSIM, and uses short-term or temporary symmetric key encryption module eSIM. This temporary symmetric key is randomly generated when preparing the package for the card eUICC.
In step 308, signed and encrypted working environment eSIM module is divided into several packets for transmission (eg, wirelessly, etc.) to third-party supplier of modules eSIM. For example, the signed and encrypted module eSIM broken into packets corresponding to qualities of the communication channel (Packet supports various required error correction scheme is well known in the art).
At step 310, a short-term symmetric key is securely transmitted to the card eUICC, for example, by encrypting it with the corresponding public key card eUICC. The certificate provider can be transmitted as plain text or, alternatively, may be encrypted. In general, issuer certificate is not encrypted to reduce the processing load on the receiving side (however, this is not a requirement of the system, and the encryption can be used either in all cases, or alternatively can be used selectively).
In step 312 eUICC card verifies the certificate vendor. It should be noted that the successful verification of the certificate provider using the public key signature of the card eUICC provides proof that the signature is not forged.
In some cases, the certificate provider may include additional signatures made trusted external structure (e.g., a mobile network operator, etc.). If the issuer certificate is valid, then the UE decodes short symmetric key using its secret key (secret key card eUICC). Successful completion of the above-mentioned exchange provides a secure channel between the card and eUICC side of the structure and its encrypted channel using a shared symmetric key for short-term follow-up data.
Accordingly, in step 314 card eUICC can safely take a lot to recover and decrypt encrypted packets. In this particular example, the card packs loads eUICC module eSIM.
In one embodiment, the certificate of the key and the encrypted packets are transmitted together. In alternative embodiments, other approaches are used for example transmitted certificate and key, and a secure connection is first established, and then initiates the transmission of the encrypted packets over the secure connection.
In an exemplary embodiment of the present invention, the eSIM treated as a separate structure from the map eUICC. Accordingly card eUICC can establish a secure connection from the structure in the absence of the module eSIM and even after the deployment of user devices. This example maps eUICC provides secure transfer of eSIM module, which allows third-party vendor modules eSIM directly distribute modules eSIM among mobile devices, and the dependence on existing procedures SIM AKA, as in the prior art, is missing.
In other words, the device has an asymmetric key pair devices, separate from the symmetric key associated with any individual module eSIM (and the network operator, MNO, issuing units eSIM). The difference between the module and the card eDICC eSIM has a significant impact on the complexity of the device's operating system.
Performing security segments
As indicated above, the existing solutions for the physical maps contain one UICC USIM structure, but those skilled in the art will recognize that various aspects of the invention are also suitable for storing and executing several client profiles access control. Accordingly, in another embodiment of the present invention map eUICC must determine the accuracy of both the network and module eSIM. Given the complexity of the problems indicated above architecture module SIM prior art is no longer sufficient for the initialization. Instead, in one exemplary embodiment, the bootable operating system (bootstrap operating system, bootstrap OS) loads a common or resident operating system, common operating system loads the appropriate module eSIM, and loaded module eSIM can perform the above procedure of authentication and key agreement (AKA) .
In particular, bootable operating system of the present invention, in one embodiment, is responsible for the cryptographic verification, decryption and loading of a common operating system and all additions associated with activated module eSIM. Bootable operating system executes in a virtual program card eUICC, therefore eSIM module and associated operating system are performed in an isolated environment ("sandbox") and can access only the relevant amendments, which are accessed through the card eUICC. For example, in one exemplary embodiment, card eUICC activates only those additions that use the same signer that module eSIM.
Referring to Figure 4 describes one exemplary method for performing segmentation module eSIM safe manner.
In step 402, the card eUICC bootable operating system starts when you restart the chip. In step 404, bootable operating system analyzes a given list of additions to the work environment runtime. For example, a bootable operating system can identify the default network and the associated supplement. At least one of these supplements is common operating system and other additions include eSIM active unit and any further additions associated with the module eSIM.
At step 406 bootable operating system verifies the integrity of additions, for example, by analysis of a certificate or other means. For example, in one embodiment, trusted structure (e.g., a registered representative) may provide certificates or otherwise serve as a source of the root for chain verification of signatures. If the supplement is properly signed, bootable operating system can execute them. Downloads only verified supplements corresponding module eSIM (other additions can be stored, but not executed in the "sandbox").
In step 408, bootable operating system launches a common operating system. Total operating system provides an interface between the module and the rest of eSIM hardware. Total operating system as a whole provides the input and output functions that emulate card UICC, characteristic for a particular module eSIM. In general, these functions are functions such as file input and output (10) etc.
Then, in step 410, the total operating system can perform the appropriate module eSIM.
Figure 4 shows the relationship 450 between software bootable operating system 452, a common operating system 454 and 456 modules eSIM. It should be noted that in the exemplary embodiment (shown in Figures 4 and 4A) different profiles eSIM function module in its own general operating systems. By separating the execution time of working environments for different profiles eSIM into isolated environment ("sandbox"), the above embodiment is compatible with conventional architectures SIM and simultaneously possesses the advantages of the present invention. In general, by ensuring the implementation of each module eSIM in their own environment, the existing software module SIM can be directly virtualized. In addition, the isolated environment ("sandbox") provide that the existence of other modules eSIM not cause adverse interactions, which is a requirement needed to support a wide range of third-party modules eSIM (for example, who may have proprietary protocols and features and the like ).
As indicated above, the above description is mainly based on the technology and properties of networks based on the subscriber identification module. Accordingly, the following describes exemplary embodiments of generalized method and apparatus for implementing one or more aspects of the present fig eteniya.
Methods
Referring to Figure 5 describes one embodiment of a generalized method 500 for modifying and maintaining safe components for use with the customer access control.
At step 502, requested or offer one or more components for use with the customer access control. In one exemplary embodiment, the one or more components entirely or partly include (i) a common operating system, (ii) at least one module eSIM and / or (iii) one or more personalizing additions eSIM associated with the module. In other implementations, processing packets can be connected with the subscriber identity module CDMA (CSIM), multimedia services identity module protocol IP (ISIM), a subscriber identity module (SIM), removable Subscriber Identity Module (RUIM), etc. Those skilled in the art familiar with the present description, will be apparent to a plurality of combinations of similar structures, with the modification described herein, methods and devices for implementing such similar structures and combinations will be apparent given to those familiar with the present description .
In one embodiment, one or more components of the requested or downloaded by the subscriber unit or connected to a device that is user / device connection or issuing a confirmation request. In alternative embodiments, one or more components administered or delivered to the device, i.e. without the above-mentioned connection request or according to some other criteria, or circuit, for example periodically, based on the occurrence of an event, etc. Information about the existence of one or more components may communicate or otherwise transmitted, or stored in a repository, which may be granted access and which may be searched.
In other embodiments, one or more components of the requested or otherwise activated by means of one or more contextual events, such as when the input device in a predetermined area exceeds the specified volume of use etc.
A request or proposal may include a signature or a certificate generated by a trusted party. In other alternative embodiments, a bid request or contain cryptographic information call. In other embodiments, the bid request or includes means for determining the authenticity (e.g., password authentication using the user interface, etc.).
A request or offer may also include a transaction key. In one such embodiment, the transaction key is short key. This may also apply other permanent transaction keys such as a key can be the same for several sessions transaction multiple users, etc. In other embodiments, the transaction key is a symmetric key, or alternatively, the asymmetric key.
In step 504, a request or proposal is verified to determine the authenticity (authentication). In one embodiment, the signature or certificate, a trusted party formed, checked for plausibility. In some cases this may require an external trusted party. In an alternate embodiment, the accuracy of the signature or certificate may be self-evident or may be determined otherwise verifier without recourse to a trusted party. Other schemes may be based on data provided by the subscriber, such as a user name and password or simple verification schemes, etc.
A successful verification may also require one or more challenge-response exchanges. In some embodiments, verification may be unidirectional (e.g., verified only one side of the transaction) or bidirectional (for example, must be successfully verified both sides of the transaction). In other schemes verification performed outside the band of communication (e.g., via another communications channel), or by the called party, etc.
The positive results of the verification lead to an agreement on one or more parameters necessary for a secure transaction. For example, in one embodiment, the determined one or more transaction keys. In some embodiments, the transaction key is generated after verification. In alternative embodiments, the transaction key is generated or proposed to use after verification and verification under certain conditions.
Then, in step 506, the device receives one or more packets associated with the customer access control. Packets may be further encrypted using the transaction key for secure transmission. In one embodiment, the packets are encrypted in an asymmetrical manner, that is, packets encrypted with the public key. In other embodiments, the packets are encrypted with a symmetric manner using a pre-agreed public key. In alternative embodiments, the packets are signed signature, providing the possibility of identification. The present invention can be used many other solutions for the packet with the possibility of verification, known in the art.
At step 508 the device decrypts the packets, and restores one or more components. In one exemplary embodiment, one or more components associated with the respective common operating system. For example, as described above, may include additions of at least one module eSIM and / or one or more personalizing additions eSIM associated with the module, as described above. Upon completion of step 508, one or more components to successfully and safely transferred to the target device.
Referring to Figure 6 discloses an exemplary embodiment of the generalized method 600 for performing the secure component for use with the customer access control.
At step 602, identifies the customer access control and one or more of the respective supplements. In one exemplary embodiment, the customer access control and one or more additions selected respective operating system. In one implementation, the operating system is loaded from the simple addition bootable operating system.
In one configuration bootable operating system provides several sound segments, each segment differs from the other segments, and software that runs from the memory segment may not have access to other unrelated segments, and other unrelated segments do not have access to it. For example, one exemplary apparatus performs a simple bootable operating system that loads and executes the general operating system and associated modules eSIM, as well as additions to one segment of the isolated environment ("sandbox").
In various embodiments of the present invention, all components are available and additions are separated in accordance with one or more categories. In one such embodiment, components and add-linked in accordance with the general signed by the parties or by a trusted source. For example, in one case, a simple bootable operating system may allow for the implementation of a common operating system and modules eSIM, signed by the same supplier of modules eSIM. In other embodiments, the components and additions may be compared in accordance with the choice of the user or the different levels of confidence. For example, the various components can be taken from various interacting structures (for example, a trusted provider of modules and personalization eSIM trusted network, etc.).
At step 604 client 600 process management and access appropriate additions are verified for operation. In one embodiment, customer access control and the appropriate additions are checked for integrity, i.e. check, whether they were made illegal changes or whether they are changed otherwise. By common methods such integrity checks are checksums, cryptographic hash functions or deductions, etc. Other solutions for verifying the authenticity of the additions can include the verification of the certificate, verification status, etc.
In step 606 is executed verified client access control. Upon successful download and execute the client performs initial access control procedures for controlling access to the appropriate network. For example, verified eSIM module can perform the procedure of authentication and key agreement.
An exemplary mobile device
Referring to Figure 7, exemplary device 700 adapted to implement the methods in accordance with the present invention.
Estimated user device UE, as shown in Figure 7, is a wireless device with a computer subsystem 702, such as a digital signal processor, a microprocessor, a field programmable gate array or a plurality of computing components mounted on one or more substrates. Computing subsystem may also comprise an internal cache memory. Computing subsystem 704 is coupled to a memory subsystem comprising memory that may include, for example, components SRAM, flash memory and SDRAM. The memory subsystem may implement one or more hardware with direct access to memory for faster access to data, which is well known in the art. The memory subsystem includes a computer-executable instructions that execute computing subsystem.
In one exemplary embodiment of the present invention, the apparatus may comprise one or more wireless interfaces (706) adapted to connect to one or more wireless networks. Several wireless interfaces may support different radio technologies such as GSM, CDMA, UMTS, LTE / LTE-A, WiMAX, WLAN, Bluetooth, etc., through the respective antenna and the modem subsystem.
UI subsystem 708 includes any number of known input / output (I / O), including, inter alia, a keyboard, a touch screen (e.g., touch interface «multi-touch»), liquid crystal display, the backlight, a speaker and / or microphone. However, it is clear that in certain circumstances one or more of these components may be omitted. For example, in embodiments with a client on a PCMCIA card may be no user interface (since they can use the user interface of the host device to which the card is physically and / or electrically connected).
In the illustrated embodiment, the device includes a safety element 710, which contains the map application and operates the UICC. Map eUICC implemented to store and access the customer access control set, designed to authenticate the operator network. To secure element may access the memory subsystem at the request of the computing subsystem.
In one exemplary embodiment, the secure element comprises at least segmentiruemuyu memory, wherein segmentiruemaya memory may comprise one or more customer access control and related addenda. Each segment is different from the other segments, and the software that runs from the memory segment can not have access to other unrelated segments, and other unrelated segments do not have access to it.
Secure element may also comprise a so-called safe microprocessor (SM), are well known in the field of security.
Additionally, various implementations of the exemplary embodiment includes instructions, which when executed by a simple trigger bootable operating system. Bootable operating system further enables selection of at least one segment of the secure element and load the appropriate customer access control being loaded with it. In various embodiments, clients access control may further be provided with one or more certificate associated with a trusted signer. Bootable operating system can verify client certificates to perform access control.
Furthermore, in one embodiment, the secure element maintains a list, or specification of access control stored yet. This specification may include information about the current state of the stored access control customers, while such information may include information about the availability, completeness, validity, arose earlier mistakes, etc. The specification can be further associated or connected with the user interface to ensure the user to select the available client access control.
As shown in Figure 7, the secure element 710 can receive and store components intended for use with one or more customer access control to authenticate the operator network. In one exemplary embodiment, the secure element has a corresponding device key and confirmation certificate. This key is used to protect the device and verification of communication between the previously unknown to each other (eg, the UE and the other party).
In one such embodiment, the device key is a secret key is an asymmetric key pair public / private. Complementary public key can be distributed freely without affecting the integrity of the secret keys. For example, the device may be assigned (or the device itself may generate) a public / private key algorithm RSA, while the public key is available for communication after deployment.
Furthermore, in some embodiments, confirmation certificate is uniquely signed the digital signature structure corresponding to the trusted. In one exemplary embodiment, a certificate confirming the verifier structures and proves the integrity of an exemplary device.
While the above methods and apparatus for programming the secure element described with reference to the RSA key pair algorithm, those skilled in the art will recognize that it can also use other authentication schemes. For example, in other embodiments, the device key may be a public key, wherein the public key distribution carefully protected. Other embodiments may be based on certificates, rather than exchanging encryption keys.
It is clear that despite the fact that certain aspects of the invention are described with reference to a specific order of method steps, this description is only an example of implementation of a generalized method in accordance with the requirements of the particular task order may be changed. Under certain conditions, some steps may be unnecessary or optional. Additionally, certain steps or functionality may be added to the described embodiments may be changed or the order of the two or more steps. All such variations be within the described invention.
While the above detailed description shown uncovered and isolated novel features of the invention, in various embodiments, it is understood that those skilled in the art without departing from the scope of the invention can be made various omissions, substitutions and changes in the present apparatus or method. The foregoing description represents the best embodiment. This description is not limiting and should be regarded as an illustration of the general principles of the invention. The scope of protection of the invention should be determined by the appended claims.
Contents5
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both waysCites: the store holds 7 of 8
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10389709B2 | Cited by | United States of America | Applicant |
| US10303879B1 | Cited by | United States of America | Applicant |
| RU2679188C2 | Cited by | Russian Federation | Search report |
| US20090205028A1 | Cites | United States of America | – |
| US20090271850A1 | Cites | United States of America | – |
| US20080016504A1 | Cites | United States of America | – |
| RU2008118949A | Cites | Russian Federation | – |
| RU2006134030A | Cites | Russian Federation | – |
| US20100062808A1 | Cites | United States of America | – |
| CN101625645A | Cites | China | – |
| Michael Kasper et al., "Subscriber Authentication in mobile cellular Networks with virtual software SIM Credentials using Trusted<p num="1">Computing", Advanced Communication Technology, 2008, ICACT. 10th International Conference on, 03.2008, найдено в Интернете по адресу "http://www.researchgate.net/publication/4325291_Subscriber_Authentication_in_Cellular_Networks_with_Trusted_Virtual_SIMs"</p> | Non-patent | – | – |
168 members in 10 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 40786610 | United States of America | P | |
| 40786610 | United States of America | P | |
| 61407866 | United States of America | – | |
| 13080521 | United States of America | – | |
| 201113080521 | United States of America | A | |
| 201113080521 | United States of America | A | |
| 13080521 | – | – | – |
| 61407866 | – | – | – |
| US20100407866P | – | – | – |
| US201113080521 | – | – | – |
Members168
| Document | Office | Kind | |
|---|---|---|---|
| EP2410777A1 | European Patent Office (EPO) | A1 | |
| WO2012012526A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2012047227A1 | United States of America | A1 | |
| KR20120021186A | Republic of Korea | A | |
| JP2012085272A | Japan | A | |
| MX2011011432A | Mexico | A | |
| MX2011011434A | Mexico | A | |
| EP2448215A1 | European Patent Office (EPO) | A1 | |
| EP2448216A1 | European Patent Office (EPO) | A1 | |
| EP2448301A1 | European Patent Office (EPO) | A1 | |
| US2012108204A1 | United States of America | A1 | |
| US2012108205A1 | United States of America | A1 | |
| US2012108206A1 | United States of America | A1 | |
| US2012108207A1 | United States of America | A1 | |
| US2012108295A1 | United States of America | A1 | |
| WO2012058092A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2012058099A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2012058429A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2012058446A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2012058450A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20120044914A | Republic of Korea | A | |
| KR20120044916A | Republic of Korea | A | |
| US2012115441A1 | United States of America | A1 | |
| US2012117635A1 | United States of America | A1 | |
| WO2012061516A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2012061561A2 | World Intellectual Property Organization (WIPO) | A2 | |
| KR20120047813A | Republic of Korea | A | |
| CN102457833A | China | A | |
| CN102457834A | China | A | |
| JP2012095306A | Japan | A | |
| WO2012065112A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2012135710A1 | United States of America | A1 | |
| JP2012109973A | Japan | A | |
| JP2012120163A | Japan | A | |
| CN102572805A | China | A | |
| CN102595404A | China | A | |
| TW201233203A | Taiwan Province of China | A | |
| WO2012065112A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW201234186A | Taiwan Province of China | A | |
| TW201234827A | Taiwan Province of China | A | |
| TW201234830A | Taiwan Province of China | A | |
| TW201234831A | Taiwan Province of China | A | |
| TW201234892A | Taiwan Province of China | A | |
| WO2012061561A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW201236433A | Taiwan Province of China | A | |
| TW201242409A | Taiwan Province of China | A | |
| BRPI1103233A2 | Brazil | A2 | |
| RU2011130762A | Russian Federation | A | |
| MX2011011435A | Mexico | A | |
| BRPI1106658A2 | Brazil | A2 | |
| BRPI1106663A2 | Brazil | A2 | |
| RU2479151C2 | Russian Federation | C2 | |
| KR20130041878A | Republic of Korea | A | |
| RU2011143257A | Russian Federation | A | |
| RU2011144919A | Russian Federation | A | |
| RU2011144921A | Russian Federation | A | |
| CN103250434A | China | A | |
| EP2633711A1 | European Patent Office (EPO) | A1 | |
| KR101304779B1 | Republic of Korea | B1 | |
| US8555067B2 | United States of America | B2 | |
| KR101347527B1 | Republic of Korea | B1 | |
| JP2014017878A | Japan | A | |
| KR20140012950A | Republic of Korea | A | |
| RU2507710C2 | Russian Federation | C2 | |
| US8660608B2 | United States of America | B2 | |
| US2014099925A1 | United States of America | A1 | |
| WO2012058429A3 | World Intellectual Property Organization (WIPO) | A3 | |
| JP5490772B2 | Japan | B2 | |
| KR101396725B1 | Republic of Korea | B1 | |
| US8738729B2 | United States of America | B2 | |
| RU2518924C2This record | Russian Federation | C2 | |
| KR20140072841A | Republic of Korea | A | |
| RU2524368C2 | Russian Federation | C2 | |
| JP5571042B2 | Japan | B2 | |
| JP2014147075A | Japan | A | |
| TWI450613B | Taiwan Province of China | B | |
| US2014248924A1 | United States of America | A1 | |
| KR101447766B1 | Republic of Korea | B1 | |
| JP5627558B2 | Japan | B2 | |
| US2014349705A1 | United States of America | A1 | |
| US8913992B2 | United States of America | B2 | |
| JP2014241648A | Japan | A | |
| US8924715B2 | United States of America | B2 | |
| TWI468943B | Taiwan Province of China | B | |
| TWI469612B | Taiwan Province of China | B | |
| TWI469654B | Taiwan Province of China | B | |
| KR20150013946A | Republic of Korea | A | |
| CN102572805B | China | B | |
| US8966262B2 | United States of America | B2 | |
| US2015074780A1 | United States of America | A1 | |
| TWI478615B | Taiwan Province of China | B | |
| US2015099560A1 | United States of America | A1 | |
| KR20150043275A | Republic of Korea | A | |
| CN104683972A | China | A | |
| KR101535361B1 | Republic of Korea | B1 | |
| TWI492603B | Taiwan Province of China | B | |
| US9100393B2 | United States of America | B2 | |
| US9100810B2 | United States of America | B2 | |
| US2015312698A1 | United States of America | A1 | |
| BRPI1106659A2 | Brazil | A2 |
Numbers
- Publication
- 0002518924
- Publication, DOCDB
- 2518924
- Publication, EPODOC
- RU2518924
- Application
- 14491908
- Application, DOCDB
- 2011144919
- Application, EPODOC
- RU20110144919
Titles2
- Russian
- БЕСПРОВОДНОЕ УСТРОЙСТВО, СПОСОБ ЗАПРОСА ПОЛЬЗОВАТЕЛЬСКОГО КЛИЕНТА УПРАВЛЕНИЯ ДОСТУПОМ И СПОСОБ ВЫПОЛНЕНИЯ КЛИЕНТА УПРАВЛЕНИЯ ДОСТУПОМ
- English
- WIRELESS DEVICE, USER ACCESS CONTROL CLIENT REQUEST METHOD AND ACCESS CONTROL CLIENT METHOD
Classification
- CPC, 11
- H04W12/06
- H04W8/205
- H04L63/0823
- H04W8/18
- H04W4/50
- H04W4/60
- H04W12/35
- H04W12/086
- H04L9/3234
- H04W12/08
- H04W8/265
- IPC, 4
- H04W8 00
- G06F21 30
- H04W4 50
- H04W4 60