TW201216734A

Method and apparatus for trusted federated identity

Abstract

Trusted computing environments such as smart cards, UICC, Java cards, and global platforms can be used as local host trust centers and single sign-on (SSO) providers' agents. This is called the local SSO provider (OP). For example, by performing this process, the verification traffic can be kept locally, and over-the-air communications that may burden the operator's network can be avoided. In order to establish an OP proxy in a trusted environment, the trusted environment can be bound to the SSO provider in a variety of ways. For example, the SSO provider can interact with UICC-based UE authentication or GBA. In this way, the user equipment can balance the trusted environment in order to provide improved security and reduce the burden of over-the-air communication and verification on the OP or the operators network.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

47 claims: 46 independent, 1 dependent

  1. 1
    A user environment for enabling a relying party (RP) to authenticate a user by enabling an open management security protocol, the user environment including:A user interface that uses a single sign-on security protocol to communicate with the RP so as to request access to a service provided by the RP on behalf of the user, and wherein the RP and a single sign-on certificate To communicate with a trusted provider in order to initiate a verification of the user;andA processor that authenticates the user for the trusted provider within the user environment, the processor is configured to locally execute at least some of the trusted provider of a single sign-on certificate Function in order to restrict communications outside of the users environment during the authentication process. 一種用於通過啟用一開放管理安全協議來使一可依賴方(RP)能夠驗證一使用者的使用者環境,該使用者環境包括:一使用者介面,該使用者介面使用一單點登錄安全協議來與所述RP進行通信,以便代表使用者來請求存取所述RP提供的一服務,並且其中所述RP與單點登錄證書的一可信供應方進行通信,以便發起對所述使用者的一驗證;以及一處理器,該處理器在所述使用者環境內部為所述可信供應方驗證所述使用者,所述處理器被配置成在本地執行單點登錄證書的該可信供應方的至少一些功能,以便在驗證過程中限制所述使用者環境以外的通信。
  2. 2
    The user environment described in the first item of the patent application, wherein the user interface receives an instruction from the RP, the instruction indicating that the RP wishes to authenticate the user. 如申請專利範圍第1項所述的使用者環境,其中所述使用者介面接收來自所述RP的一指示,該指示表明所述RP希望對所述使用者進行驗證。
  3. 3
    According to the user environment described in claim 1, wherein the user interface receives a redirect message from the RP, and the redirect message instructs the user interface to authenticate the user. 如申請專利範圍第1項所述的使用者環境,其中所述使用者介面接收來自所述RP的一重定向消息,該重定向消息指示所述使用者介面對所述使用者進行驗證。
  4. 4
    The user environment described in the first item of the scope of patent application, wherein the user interface receives a user certificate from the user. 如申請專利範圍第1項所述的使用者環境,其中所述使用者介面接收來自所述使用者的使用者證書。
  5. 5
    The user environment described in the first item of the scope of patent application, wherein the processor is a trusted computing environment. 如申請專利範圍第1項所述的使用者環境,其中所述處理器是一可信計算環境。
  6. 6
    In the user environment described in item 5 of the scope of patent application, the entire or part of the user interface is protected by the trusted computing. 如申請專利範圍第5項所述的使用者環境,其中所述使用者介面整體或部分是由該可信計算環境保護的。
  7. 7
    In the user environment described in item 5 of the scope of patent application, when the user has been verified, the trusted computing environment sends a verification response to the RP. 如申請專利範圍第5項所述的使用者環境,其中當所述使用者已被驗證時,所述可信計算環境向所述RP傳送一驗證回應。
  8. 8
    For example, the user environment described in item 5 of the scope of patent application, wherein the trusted computing environment is one of the following:universal integrated circuit card (UICC), user identification module (SIM), machine-to-machine ( M2M) device, smart card, java card, global platform smart card, or security integrated chip card (ICC). 如申請專利範圍第5項所述的使用者環境,其中所述可信計算環境是下列各項之一:通用積體電路卡(UICC)、使用者標識模組(SIM)、機器對機器(M2M)設備、智慧卡、java卡、全球平臺智慧卡、或安全集成晶片卡(ICC)。
  9. 9
    The user environment described in item 5 of the scope of patent application, wherein the trusted computing environment is implemented using a smart card web server (SCWS). 如申請專利範圍第5項所述的使用者環境,其中所述可信計算環境是使用智慧卡網路伺服器(SCWS)來實施的。
  10. 10
    The user environment described in item 5 of the scope of patent application, wherein the trusted computing environment and the OpenID provider share secrets. 如申請專利範圍第5項所述的使用者環境,其中所述可信計算環境與OpenID供應方共用秘密。
  11. 11
    The user environment described in the 5th patent application, wherein the trusted computing environment calculates a signature, and provides the signature to the RP via the user interface, so as to allow the RP to verify the availability Trust the certificate of the computing environment. 如申請專利範圍第5項所述的使用者環境,其中所述可信計算環境計算簽名,並且將所述簽名經由所述使用者介面提供給所述RP,以便允許所述RP核驗所述可信計算環境的證書。
  12. 12
    The user environment according to the fifth item of the scope of patent application, wherein the trusted computing environment calculates a signature, and provides the signature to the OP via the user interface, so as to allow the OP to verify the availability Trust the certificate of the computing environment. 如申請專利範圍第5項所述的使用者環境,其中所述可信計算環境計算簽名,並且將所述簽名經由所述使用者介面提供給所述OP,以便允許所述OP核驗所述可信計算環境的證書。
  13. 13
    The user environment described in item 10 of the scope of patent application, wherein the trusted computing environment calculates a signature based on the secret, and provides the signature to the RP via the user interface so as to allow the The RP verifies the certificate of the trusted computing environment. 如申請專利範圍第10項所述的使用者環境,其中所述可信計算環境基於所述秘密來計算簽名,並且將所述簽名經由所述使用者介面提供給所述RP,以便允許所述RP核驗所述可信計算環境的證書。
  14. 14
    The user environment described in claim 10, wherein the trusted computing environment calculates a signature based on the secret, and provides the signature to the OP via the user interface so as to allow the The OP verifies the certificate of the trusted computing environment. 如申請專利範圍第10項所述的使用者環境,其中所述可信計算環境基於所述秘密來計算簽名,並且將所述簽名經由所述使用者介面提供給所述OP,以便允許所述OP核驗所述可信計算環境的證書。
  15. 15
    The user environment according to the fifth item of the scope of patent application, wherein the trusted computing environment and the OP establish a shared secret through the user interface. 如申請專利範圍第5項所述的使用者環境,其中所述可信計算環境與所述OP經由所述使用者介面建立共用秘密。
  16. 16
    The user environment according to the 15th patent application, wherein the user interface receives a verification request from the RP that includes association control, and provides the association control to the trusted computing environment. 如申請專利範圍第15項所述的使用者環境,其中所述使用者介面接收來自所述RP的包含了關聯控制的驗證請求,並且將所述關聯控制提供給所述可信計算環境。
  17. 17
    The user environment according to the 15th patent application, wherein the user interface receives the redirection message including the association control from the trusted computing environment, and provides the association control to the RP. 如申請專利範圍第15項所述的使用者環境,其中所述使用者介面接收來自所述可信計算環境的包含了關聯控制的重定向消息,並且將所述關聯控制提供給所述RP。
  18. 18
    The user environment according to the 16th patent application, wherein the trusted computing environment generates a signature based on the shared secret, and generates a verification response including the signature and the associated control. 如申請專利範圍第16項所述的使用者環境,其中所述可信計算環境基於所述共用秘密來產生簽名,並且產生包含了所述簽名和所述關聯控制的驗證響應。
  19. 19
    The user environment described in item 18 of the scope of patent application, wherein the user interface provides the verification response generated by the trusted computing environment to the RP. 如申請專利範圍第18項所述的使用者環境,其中所述使用者介面將所述可信計算環境產生的所述驗證響應提供給所述RP。
  20. 20
    The user environment described in the first item of the scope of patent application, wherein the integrated circuit generates a signature and receives a signature assertion message from the OP. 如申請專利範圍第1項所述的使用者環境,其中所述積體電路產生簽名,並且接收來自所述OP的簽名斷言消息。
  21. 21
    The user environment according to the 20th patent application, wherein the integrated circuit transmits a signature response message to the RP. 如申請專利範圍第20項所述的使用者環境,其中所述積體電路向所述RP傳送簽名響應消息。
  22. 22
    The user environment described in the first item of the patent application, wherein the user interface and the integrated circuit are on the same device. 如申請專利範圍第1項所述的使用者環境,其中所述使用者介面和所述積體電路處於相同設備上。
  23. 23
    The user environment described in the first item of the patent application, wherein the user interface and the integrated circuit are on separate devices. 如申請專利範圍第1項所述的使用者環境,其中所述使用者介面和所述積體電路處於分離的設備上。
  24. 24
    The user environment described in item 1 of the scope of patent application, wherein the authentication of the user is performed by verifying the user with a password or PIN code, biometric identification, token, or a combination thereof . 如申請專利範圍第1項所述的使用者環境,其中對所述使用者的驗證是通過用密碼或PIN碼、生物測定標識、權杖或是其組合來核驗所述使用者而被執行的。
  25. 25
    A method for protecting the user environment and/or local assertion provider (LAP) to authenticate a user for a relying party (RP) in an open management security protocol, the method includes:Receiving an instruction from the RP via a user interface indicating that the RP wishes to authenticate the user, and the RP can communicate with a trusted provider of single sign-on (SSO) certificates;Receiving a user certificate from the user through the user interface;Use the received user certificate to authenticate the user for the RP, so as to perform at least some functions of the trusted provider of the SSO certificate locally, while restricting outside the user environment during the verification process Communications;andA verification response is sent to the RP via the user interface. 一種用於保護使用者環境和/或本地斷言供應方(LAP),以便在一開放管理安全協議中為可依賴方(RP)驗證一使用者的方法,該方法包括:經由一使用者介面接收來自所述RP且表明所述RP希望對所述使用者進行驗證的一指示,所述RP能夠與單點登錄(SSO)證書的一可信供應方進行通信;通過所述使用者介面接收來自所述使用者的使用者證書;使用接收到的所述使用者證書來為所述RP驗證所述使用者,以便在本地執行SSO證書的所述可信供應方的至少一些功能,而在驗證過程中限制所述使用者環境以外的通信;以及經由所述使用者介面來將一驗證回應傳送到所述RP。
  26. 26
    The method described in item 25 of the scope of patent application, wherein the LAP is in a trusted computing environment. 如申請專利範圍第25項所述的方法,其中所述LAP處於可信計算環境內部。
  27. 27
    The method according to item 26 of the scope of patent application, wherein the indication is a redirect message. 如申請專利範圍第26項所述的方法,其中所述指示是重定向消息。
  28. 29
    The method described in item 27 of the scope of patent application, wherein the authentication of the user is performed through a trusted computing environment. 如申請專利範圍第27項所述的方法,其中驗證所述使用者是經由可信計算環境執行的。
  29. 30
    Such as the method of item 29 of the scope of patent application, wherein the trusted computing environment is one of the following:UMTS integrated circuit card (UICC), user identification module (SIM), machine-to-machine (M2M) equipment, Smart card, java card, global platform smart card, or secure integrated chip card (ICC). 如申請專利範圍第29項的方法,其中所述可信計算環境是下列各項之一:UMTS積體電路卡(UICC)、使用者標識模組(SIM)、機器對機器(M2M)設備、智慧卡、java卡、全球平臺智慧卡、或安全集成晶片卡(ICC)。
  30. 31
    The method described in item 26 of the scope of patent application, wherein the verification response is sent when the user has been verified. 如申請專利範圍第26項所述的方法,其中所述驗證回應是在所述使用者已被驗證時被傳送的。
  31. 32
    The method described in item 26 of the scope of patent application, wherein the trusted computing environment is used to authenticate the user by using a secure web server such as a smart card web server (SCWS). 如申請專利範圍第26項所述的方法,其中使用可信計算環境驗證所述使用者是藉由使用智慧卡網路伺服器(SCWS)之類的安全網路伺服器而發生的。
  32. 33
    Such as the method described in item 26 of the scope of patent application, the method also includes:sharing secrets with an open management security provider associated with a mobile network operator (MNO). 如申請專利範圍第26項所述的方法,該方法還包括:與關聯於行動網路營運商(MNO)的開放管理安全供應方共用秘密。
  33. 34
    Such as the method described in item 26 of the scope of patent application, the method also includes:sharing secrets with an OpenID provider associated with a mobile network operator (MNO). 如申請專利範圍第26項所述的方法,該方法還包括:與關聯於行動網路營運商(MNO)的OpenID供應方共用秘密。
  34. 35
    For the method described in item 29 of the scope of patent application, the method further includes:calculating a signature, and providing the signature to the RP via the user interface, so as to allow the RP to verify the authenticity of the trusted computing environment Certificate. 如申請專利範圍第29項所述的方法,該方法還包括:計算簽名,並且將所述簽名經由所述使用者介面提供給所述RP,以便允許所述RP核驗所述可信計算環境的證書。
  35. 36
    For the method described in item 35 of the scope of patent application, the method further includes:establishing a shared secret with the RP through the user interface. 如申請專利範圍第35項所述的方法,該方法還包括:經由所述使用者介面而與所述RP建立共用秘密。
  36. 37
    For the method described in item 36 of the scope of patent application, the method further includes:receiving association control from the RP. 如申請專利範圍第36項所述的方法,該方法還包括:接收來自所述RP的關聯控制。
  37. 38
    For the method described in item 37 of the scope of patent application, the method further includes:generating a signature based on the shared secret, and generating a verification response including the signature and the association control. 如申請專利範圍第37項所述的方法,該方法還包括:基於所述共用秘密來產生簽名,以及產生包含了所述簽名和所述關聯控制的驗證響應。
  38. 39
    For the method described in item 38 of the scope of patent application, the method further includes:receiving a signature assertion message from the RP. 如申請專利範圍第38項所述的方法,該方法還包括:接收來自所述RP的簽名斷言消息。
  39. 40
    For the method described in item 39 of the scope of patent application, the method further includes:transmitting a signature response message to the RP. 如申請專利範圍第39項所述的方法,該方法還包括:向所述RP傳送簽名響應消息。
  40. 41
    For the method described in item 29 of the scope of patent application, the method further includes:calculating a signature, and providing the signature to the OP via the user interface, so as to allow the OP to verify the authenticity of the trusted computing environment Certificate. 如申請專利範圍第29項所述的方法,該方法還包括:計算簽名,並且將所述簽名經由所述使用者介面提供給所述OP,以便允許所述OP核驗所述可信計算環境的證書。
  41. 42
    For the method described in item 41 of the scope of patent application, the method further includes:establishing a shared secret with the OP via the user interface. 如申請專利範圍第41項所述的方法,該方法還包括:經由所述使用者介面而與所述OP建立共用秘密。
  42. 43
    For the method described in item 36 of the scope of patent application, the method further includes:receiving the association control from the trusted computing environment, and transmitting the association control to the OP. 如申請專利範圍第36項所述的方法,該方法還包括:接收來自所述可信計算環境的關聯控制,並且將該關聯控制傳送給所述OP。
  43. 44
    According to the method described in item 43 of the scope of patent application, the method further includes:generating a signature based on the shared secret, and generating a verification response including the signature and the association control. 如申請專利範圍第43項所述的方法,該方法還包括:基於所述共用秘密來產生簽名,並且產生包含了所述簽名和所述關聯控制的驗證響應。
  44. 45
    As the method described in item 44 of the scope of patent application, the method further includes:receiving a signature assertion message from the OP. 如申請專利範圍第44項所述的方法,該方法還包括:接收來自所述OP的簽名斷言消息。
  45. 46
    As the method described in item 45 of the scope of patent application, the method further includes:transmitting a signature response message to the OP. 如申請專利範圍第45項所述的方法,該方法還包括:向所述OP傳送簽名響應消息。
  46. 47
    The method described in item 25 of the scope of the patent application, wherein the verification of the user is performed by verifying the user with a password or PIN code, biometric identification, token, or a combination thereof. 如申請專利範圍第25項所述的方法,其中驗證所述使用者是通過用密碼或PIN碼、生物測定標識、權杖或是其組合來核驗所述使用者而被執行的。
Independent claims46