TWI575969B

Methods for establishing a secure communication channel

Abstract

A method for establishing a secure communication channel between an off-card entity and an electronic Universal Integrated Circuit Card (eUICC) is provided. The method involves establishing symmetric keys that are ephemeral in scope. Specifically, an off-card entity, and each eUICC in a set of eUICCs managed by the off-card entity, possess long-term Public Key Infrastructure (PKI) information. When a secure communication channel is to be established between the off-card entity and an eUICC, the eUICC and the off-card entity can authenticate one another in accordance with the respectively-possessed PKI information (e.g., verifying public keys). After authentication, the off-card entity and the eUICC establish a shared session-based symmetric key for implementing the secure communication channel. Specifically, the shared session-based symmetric key is generated according to whether perfect or half forward security is desired. Once the shared session-based symmetric key is established, the off-card entity and the eUICC can securely communicate information.

TWI575969B, drawing sheet 1
Sheet 1 of 7

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

18 claims: 4 independent, 14 dependent

  1. 1
    A method for establishing a secure connection between a server and an electronic universal integrated circuit card (eUICC) included in a mobile device, the electronic universal integrated circuit card (Euicc) and a long-term public key (PKeUICC) And a long-term private key (SKeUICC), the method includes:connecting with a long-term public key (PKserver) And a long-term private key (SKserver) At the associated server: a request for establishing the secure connection with the mobile device is received from the mobile device, wherein the request includes a PKeUICC;And using PKeUICCImmediately after authenticating the mobile device: Generate a short public key (ePKserver) And a short private key (eSKserver);Use SKserverSign ePKserverTo generate a signed ePKserver;The signed ePKserverProvide to the mobile device;receive and use SK from the mobile deviceeUICCOne of the signature ephemeral keys (ePKeUICC);use eSKserverAnd ePKeUICCGenerate a shared symmetric key;use the shared symmetric key to establish the secure connection;and cache the shared symmetric in a secure network domain associated with the eUICC for later establishing a different secure connection with the mobile device Key. 一種用於在一伺服器與包括於一行動器件中之一電子通用積體電路卡(eUICC)之間建立一安全連接之方法,該電子通用積體電路卡(Euicc)與一長期公開金鑰(PKeUICC)及一長期私密金鑰(SKeUICC)相關聯,該方法包含:在與一長期公開金鑰(PKserver)及一長期私密金鑰(SKserver)相關聯之該伺服器處:自該行動器件接收與該行動器件建立該安全連接的一請求,其中該請求包括PKeUICC;及在使用PKeUICC鑑認該行動器件之後即刻:產生一短暫公開金鑰(ePKserver)及一短暫私密金鑰(eSKserver);使用SKserver簽署ePKserver以產生一經簽署之ePKserver;將該經簽署之ePKserver提供至該行動器件;自該行動器件接收使用SKeUICC簽署之一短暫金鑰(ePKeUICC);使用eSKserver及ePKeUICC產生一共用對稱金鑰;使用該共用對稱金鑰建立該安全連接;且在與該eUICC相關聯之一安全網域內快取用於稍後與該行動器件建立一不同安全連接之該共用對稱金鑰。
  2. 5
    A method for establishing a secure connection between a server and an electronic universal integrated circuit card (eUICC) included in a mobile device, the electronic universal integrated circuit card (eUICC) and a long-term public key (PKeUICC) And a long-term private key (SKeUICC), the method includes:connecting with a long-term public key (PKserver) And a long-term private key (SKserver) At the associated server: a request for establishing the secure connection with the mobile device is received from the mobile device, wherein the request includes a PKeUICC;And using PKeUICCImmediately after authenticating the mobile device: Generate a short public key (ePKserver) And a short private key (eSKserver);Use SKserverSign ePKserverTo generate a signed ePKserver;The signed ePKserverProvide to the mobile device;use eSKserverAnd PKeUICCGenerate a shared symmetric key;and use the shared symmetric key to establish the secure connection. 一種用於在一伺服器與包括於一行動器件中之一電子通用積體電路卡(eUICC)之間建立一安全連接之方法,該電子通用積體電路卡(eUICC)與一長期公開金鑰(PKeUICC)及一長期私密金鑰(SKeUICC)相關聯,該方法包含:在與一長期公開金鑰(PKserver)及一長期私密金鑰(SKserver)相關聯之該伺服器處:自該行動器件接收與該行動器件建立該安全連接的一請求,其中該請求包括PKeUICC;及在使用PKeUICC鑑認該行動器件之後即刻:產生一短暫公開金鑰(ePKserver)及一短暫私密金鑰(eSKserver);使用SKserver簽署ePKserver以產生一經簽署之ePKserver;將該經簽署之ePKserver提供至該行動器件;使用eSKserver及PKeUICC產生一共用對稱金鑰;且使用該共用對稱金鑰建立該安全連接。
  3. 10
    A method for establishing a secure connection between an electronic universal integrated circuit card (eUICC) and a server, the server and a long-term public key (PKserver) And a long-term private key (SKserver), the method includes:connecting with a long-term public key (PKeUICC) And a long-term private key (SKeUICC) At the associated eUICC: transmit a request for establishing the secure connection with the server to the server, wherein the request includes a PKeUICC;Receive PK from this serverserver;And using PKserverImmediately after authenticating the server: Generate a short public key (ePKeUICC) And a short private key (eSKeUICC);Use SKeUICCSign ePKeUICCTo generate a signed ePKeUICC;The signed ePKeUICCProvide to the server;receive SK from the serverserverOne of the signature ephemeral keys (ePKserver);Use SKeUICCAnd ePKserverGenerate a shared symmetric key;use the shared symmetric key to establish the secure connection;and cache the shared symmetric key in a secure network domain of the eUICC for later establishing a different secure connection with the server. 一種用於在一電子通用積體電路卡(eUICC)與一伺服器之間建立一安全連接之方法,該伺服器與一長期公開金鑰(PKserver)及一長期私密金鑰(SKserver)相關聯,該方法包含:在與一長期公開金鑰(PKeUICC)及一長期私密金鑰(SKeUICC)相關聯之該eUICC處:向該伺服器傳輸與該伺服器建立該安全連接的一請求,其中該請求包括PKeUICC;自該伺服器接收PKserver;及在使用PKserver鑑認該伺服器之後即刻:產生一短暫公開金鑰(ePKeUICC)及一短暫私密金鑰(eSKeUICC);使用SKeUICC簽署ePKeUICC以產生一經簽署之ePKeUICC;將該經簽署之ePKeUICC提供至該伺服器;自該伺服器接收使用SKserver簽署之一短暫金鑰(ePKserver);使用SKeUICC及ePKserver產生一共用對稱金鑰;使用該共用對稱金鑰建立該安全連接;且在該eUICC之一安全網域內快取用於稍後與該伺服器建立一不同安全連接之該共用對稱金鑰。
  4. 14
    A method for establishing a secure connection between an electronic universal integrated circuit card (eUICC) and a server, the server and a long-term public key (PKserver) And a long-term private key (SKserver), the method includes:connecting with a long-term public key (PKeUICC) And a long-term private key (SKeUICC) At the associated eUICC: transmit a request for establishing the secure connection with the server to the server, wherein the request includes a PKeUICC;Receive PK from this serverserver;And using PKserverImmediately after authenticating the server: Receive SK from the serverserverOne of the signature ephemeral keys (ePKserver);Use SKeUICCAnd ePKserverGenerate a shared symmetric key;and use the shared symmetric key to establish the secure connection. 一種用於在一電子通用積體電路卡(eUICC)與一伺服器之間建立一安全連接之方法,該伺服器與一長期公開金鑰(PKserver)及一長期私密金鑰(SKserver)相關聯,該方法包含:在與一長期公開金鑰(PKeUICC)及一長期私密金鑰(SKeUICC)相關聯之該eUICC處:向該伺服器傳輸與該伺服器建立該安全連接的一請求,其中該請求包括PKeUICC;自該伺服器接收PKserver;及在使用PKserver鑑認該伺服器之後即刻:自該伺服器接收使用SKserver簽署之一短暫金鑰(ePKserver);使用SKeUICC及ePKserver產生一共用對稱金鑰;且使用該共用對稱金鑰建立該安全連接。