Device and Method for Secure Connection
Claim Score by NHIP
Abstract
An electronic device is provided. The electronic device includes a first short-range communication module configured to execute short-range communication with a second electronic device, a security module configured to store security information, and a processor configured to receive, from the second electronic device, a pairing key that registers the electronic device as being linked to the second electronic device, transmit session key generation information to the second electronic device when authentication with the second electronic device is completed based on the pairing key, generate a session key based on the session key generation information, encrypt the security information based on the session key, and transmit the encrypted information to the second electronic device.

Term
9.6 yearsto projected expiry
Projected expiry 29 April 2036, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
27 claims: 6 independent, 21 dependent
- 1An electronic device comprising:a first short-range communication module configured to execute short-range communication with a second electronic device;a security module configured to store security information;and a processor configured to: receive, from the second electronic device, a pairing key that registers the electronic device as being linked to the second electronic device, transmit session key generation information to the second electronic device when authentication with the second electronic device is completed based on the pairing key, generate a session key based on the session key generation information, encrypt the security information based on the session key, and transmit the encrypted information to the second electronic device.
- 6An electronic device comprising:a first short-range communication module configured to execute short-range communication with a first electronic device;a second short-range communication module configured to execute short-range communication with a third electronic device;and a processor configured to: transmit, when a pairing key that registers the first electronic device as being linked to the electronic device is received from a server device, the pairing key to the first electronic device, transmit, to the server device, session key generation information received from the first electronic device, decode encrypted security information that is received from the first electronic device based on a session key received from the server device, and transmit the decoded information to the third electronic device.
- 10Broadest claimClaim Score 73, broad(NHIP)A server device comprising:a processor configured to: generate and store a pairing key for registering a first electronic device as being linked to an electronic device based on unique information of the first electronic device received from the electronic device, transmit the pairing key to the electronic device, generate a session key identical to a session key of the first electronic device based on session key generation information of the first electronic device received from the electronic device, and transmit the session key to the electronic device.
- 14A secure connection method of an electronic device, the method comprising:receiving a pairing key that registers the electronic device as being linked to a second electronic device, from the second electronic device that is connected over a first short-range communication;transmitting session key generation information to the second electronic device when authentication with respect to the second electronic device is completed based on the pairing key;generating a session key based on the session key generation information, encrypting security information through the session key;and transmitting the encrypted information to the second electronic device.
- 19A method of an electronic device, the method comprising:transmitting, when a pairing key that registers a first electronic device as being linked to the electronic device, is received from a server device, the pairing key to the first electronic device that is connected over a first short-range communication;transmitting, to the server device, session key generation information received from the first electronic device;decoding, when a session key is received from the server device, encrypted security information that is received from the first electronic device, based on the session key;and transmitting the decoded information to a third electronic device that is connected over a second short-range communication.
- 23A secure connection method of a server device, the method comprising:generating and storing, when unique information of a first electronic device is received from an electronic device, a pairing key for registering the first electronic device as being linked to the electronic device based on the unique information of the first electronic device, and transmitting the pairing key to the electronic device;and generating a session key identical to a session key of the first electronic device based on the session key generation information, and transmitting the session key to the electronic device, when session key generation information of the first electronic device is received from the electronic device.
Independent claims6
186 paragraphs in 6 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATION(S)
0001This application claims the benefit under 35 U.S.C. §119(a) of a Korean patent application filed on Oct. 21, 2014 in the Korean Intellectual Property Office and assigned Serial number 10-2014-0142627, the entire disclosure of which is hereby incorporated by reference.
TECHNICAL FIELD
0002The present disclosure relates to a device and a method for a secure connection. More particularly, the present disclosure relates to a device and a method for a secure connection, which securely transmits security information of a first electronic device to a second electronic device, so that services are conveniently executed using the second electronic device.
BACKGROUND
0003A Near field communication (NFC) service is currently operated in three types of modes, which are card emulation, peer to peer (P2P), and read/write. Out of the three mode types, the card emulation mode is used for NFC payment service.
0004In the card emulation mode, NFC payment services, such as, a transportation card payment service, a check card payment service, and the like, may be executed using an electronic device by transmitting security information stored in a security chip (an embedded secure element (eSE) chip, a universal integrated circuit card (UICC) chip, or a host card emulation (HCE) chip) to an NFC reader through an NFC chip.
0005In the card emulation mode, communication between the security chip (an eSE chip, a UICC chip, or an HCE chip) and the NFC chip should be directly connected. For example, the security chip (an eSE chip, a UICC chip, or an HCE chip) should be connected with the NFC chip from the perspective of hardware (H/W) in one electronic device so that the security information stored in the security chip is transmitted to the NFC reader through the NFC chip, or the security chip should be connected with the NFC chip through a processor (application processor (AP)) in one electronic device.
0006When a user possesses a plurality of electronic devices, for example, a smart phone, a watch phone, and a tablet, a security chip (an embedded secure element (eSE) chip, a universal integrated circuit card (UICC) chip, or a host card emulation (HCE) chip) and a near field communication (NFC) chip required for NFC payment service should be included in each of the plurality of electronic devices. For example, when an eSE/UICC/HCU chip and an NFC chip for NFC payment service are included in only the smart phone, a user should proceed with payment service using the smart phone although the smart phone is connected with the watch phone through Bluetooth.
0007Therefore, a need exists for a device and a method for a secure connection, which securely transmits security information of a first electronic device to a second electronic device, so that services are conveniently executed using the second electronic device.
0008The above information is presented as background information only to assist with an understanding of the present disclosure. No determination has been made, and no assertion is made, as to whether any of the above might be applicable as prior art with regard to the present disclosure.
SUMMARY
0009Aspects of the present disclosure are to address at least the above-mentioned problems and/or disadvantages and to provide at least the advantages described below. Accordingly, an aspect of the present disclosure is to provide a device and a method for a secure connection, which securely transmits security information of a first electronic device to a second electronic device, so that services are conveniently executed using the second electronic device.
0010In accordance with an aspect of the present disclosure, an electronic device is provided. The electronic device includes a first short-range communication module configured to execute short-range communication with a second electronic device, a security module configured to store security information, and a processor configured to receive, from the second electronic device, a pairing key that registers the electronic device as being linked to the second electronic device, transmit session key generation information to the second electronic device when authentication with the second electronic device is completed based on the pairing key, generate a session key based on the session key generation information, encrypt the security information based on the session key, and transmit the encrypted information to the second electronic device.
0011In accordance with another aspect of the present disclosure, an electronic device is provided. The electronic device includes a first short-range communication module configured to execute short-range communication with a first electronic device, a second short-range communication module configured to execute short-range communication with a third electronic device, and a processor configured to transmit, when a pairing key that registers the first electronic device as being linked to the electronic device is received from a server device, the pairing key to the first electronic device, transmit session key generation information received from the first electronic device to the server device, decode encrypted security information that is received from the first electronic device, based on a session key received from the server device, and transmit the decoded information to the third electronic device.
0012In accordance with another aspect of the present disclosure, a server device is provided. The server device includes a processor configured to generate and store a pairing key for registering a first electronic device as being linked to an electronic device, based on unique information of the first electronic device received from the electronic device, and transmit the pairing key to the electronic device, and generate a session key identical to a session key of the first electronic device based on session key generation information of the first electronic device received from the electronic device, and transmit the session key to the electronic device.
0013In accordance with another aspect of the present disclosure, a secure connection method of an electronic device is provided. The secure connection method includes receiving a pairing key that registers the electronic device as being linked to a second electronic device from the second electronic device that is connected over a first short-range communication, transmitting session key generation information to the second electronic device when authentication with respect to the second electronic device is completed based on the pairing key, and generating a session key based on the session key generation information, encrypting security information through the session key, and transmitting the encrypted information to the second electronic device.
0014In accordance with another aspect of the present disclosure, a secure connection method of an electronic device is provided. The secure connection method includes transmitting, when a pairing key that registers a first electronic device as being linked to the electronic device, is received from a server device, the pairing key to the first electronic device that is connected over a first short-range communication, transmitting, to the server device, session key generation information received from the first electronic device, and decoding, when a session key is received from the server device, encrypted security information that is received from the first electronic device, based on the session key, and transmitting the decoded information to a third electronic device that is connected over a second short-range communication.
0015In accordance with another aspect of the present disclosure, a secure connection method of a server device is provided. The secure connection method includes generating and storing, when unique information of a first electronic device is received from an electronic device, a pairing key for registering the first electronic device as being linked to the electronic device, based on the unique information of the first electronic device, and transmitting the pairing key to the electronic device, and generating, when session key generation information of the first electronic device is received from the electronic device, a session key identical to a session key of the first electronic device based on the session key generation information, and transmitting the session key to the electronic device.
0016A secure connection device and method, according to various embodiments of the present disclosure, securely provides security information of the first electronic device to a second electronic device, so that services are conveniently executed using the second electronic device.
0017Other aspects, advantages, and salient features of the disclosure will become apparent to those skilled in the art from the following detailed description, which, taken in conjunction with the annexed drawings, discloses various embodiments of the present disclosure.
BRIEF DESCRIPTION OF THE DRAWINGS
0018The above and other aspects, features, and advantages of certain embodiments of the present disclosure will be more apparent from the following description taken in conjunction with the accompanying drawings, in which:
0019<figref idref="DRAWINGS">FIG. 1</figref> illustrates a network environment according to various embodiments of the present disclosure;
0020<figref idref="DRAWINGS">FIG. 2</figref> is a block diagram of an electronic device according to various embodiments of the present disclosure;
0021<figref idref="DRAWINGS">FIG. 3</figref> is a block diagram of a programming module according to various embodiments of the present disclosure;
0022<figref idref="DRAWINGS">FIG. 4</figref> is a diagram illustrating a secure connection system according to various embodiments of the present disclosure;
0023<figref idref="DRAWINGS">FIG. 5</figref> is a block diagram of a secure connection device according to various embodiments of the present disclosure;
0024<figref idref="DRAWINGS">FIGS. 6A and 6B</figref> are flowcharts illustrating a registration method for a secure connection according to various embodiments of the present disclosure; and
0025<figref idref="DRAWINGS">FIGS. 7A and 7B</figref> are flowcharts illustrating a secure connection method according to various embodiments of the present disclosure.
0026Throughout the drawings, like reference numerals will be understood to refer to like parts, components, and structures.
DETAILED DESCRIPTION
0027The following description with reference to the accompanying drawings is provided to assist in a comprehensive understanding of various embodiments of the present disclosure as defined by the claims and their equivalents. It includes various specific details to assist in that understanding but these are to be regarded as merely exemplary. Accordingly, those of ordinary skill in the art will recognize that various changes and modifications of the various embodiments described herein can be made without departing from the scope and spirit of the present disclosure. In addition, descriptions of well-known functions and constructions may be omitted for clarity and conciseness.
0028The terms and words used in the following description and claims are not limited to the bibliographical meanings, but, are merely used by the inventor to enable a clear and consistent understanding of the present disclosure. Accordingly, it should be apparent to those skilled in the art that the following description of various embodiments of the present disclosure is provided for illustration purpose only and not for the purpose of limiting the present disclosure as defined by the appended claims and their equivalents.
0029It is to be understood that the singular forms “a,” “an,” and “the” include plural referents unless the context clearly dictates otherwise. Thus, for example, reference to “a component surface” includes reference to one or more of such surfaces.
0030By the term “substantially” it is meant that the recited characteristic, parameter, or value need not be achieved exactly, but that deviations or variations, including for example, tolerances, measurement error, measurement accuracy limitations and other factors known to those of skill in the art, may occur in amounts that do not preclude the effect the characteristic was intended to provide.
0031In embodiments of the present disclosure, the expression “have”, “may have”, “include” or “may include” refers to existence of a corresponding feature (for example, a numerical value, a function, an operation, or components, such as elements), and does not exclude existence of additional features.
0032In embodiments of the present disclosure, the expression “A or B”, “at least one of A or/and B”, or “one or more of A or/and B” may include all possible combinations of the items listed. For example, the expression “A or B”, “at least one of A and B”, or “at least one of A or B” refers to all of (1) including at least one A, (2) including at least one B, or (3) including all of at least one A and at least one B.
0033The expression “a first”, “a second”, “the first”, or “the second” used in various embodiments of the present disclosure may modify various components regardless of the order and/or the importance but does not limit the corresponding components. The above expressions are used merely for the purpose of distinguishing an element from the other elements. For example, a first user device and a second user device indicate different user devices although both of them are user devices. For example, a first element may be termed a second element, and similarly, a second element may be termed a first element without departing from the scope of the present disclosure.
0034When it is mentioned that one element (for example, a first element) is “(operatively or communicatively) coupled with/to or connected to” another element (for example, a second element), it should be construed that the one element is directly connected to the another element or the one element is indirectly connected to the another element via yet another element (for example, a third element). In contrast, it may be understood that when an element (for example, the first element) is referred to as being “directly connected,” or “directly coupled” to another element (second element), there are no element (for example, the third element) interposed between them.
0035The expression “configured to” used in embodiments of the present disclosure may be exchanged with, for example, “suitable for”, “having the capacity to”, “designed to”, “adapted to”, “made to”, or “capable of” according to the situation. The term “configured to” may not necessarily imply “specifically designed to” in hardware (H/W). Alternatively, in some situations, the expression “device configured to” may mean that the device, together with other devices or components, “is able to”. For example, the phrase “processor adapted (or configured) to perform A, B, and C” may mean a dedicated processor (for example, an embedded processor) only for performing the corresponding operations or a generic-purpose processor (for example, a central processing unit (CPU) or an application processor (AP)) that can perform the corresponding operations by executing one or more software (S/W) programs stored in a memory device.
0036The terms used herein are merely for the purpose of describing particular embodiments of the present disclosure and are not intended to limit the scope of other embodiments. Unless defined otherwise, all terms used herein, including technical and scientific terms, have the same meaning as those commonly understood by a person skilled in the art to which the present disclosure pertains. Such terms as those defined in a generally used dictionary are to be interpreted to have the meanings equal to the contextual meanings in the relevant field of the art, and are not to be interpreted to have ideal or excessively formal meanings unless clearly defined in embodiments of the present disclosure. In some cases, even the term defined in embodiments of the present disclosure should not be interpreted to exclude embodiments of the present disclosure.
0037For example, the electronic device may include at least one of a smartphone, a tablet personal computer (PC), a mobile phone, a video phone, an electronic book (e-book) reader, a desktop PC, a laptop PC, a netbook computer, a personal digital assistant (PDA), a portable multimedia player (PMP), a Moving Picture Experts Group phase 1 or phase 2 (MPEG-1 or MPEG-2) audio layer 3 (MP3) player, a mobile medical appliance, a camera, and a wearable device (for example, a head-mounted-device (HMD), such as electronic glasses, electronic clothes, an electronic bracelet, an electronic necklace, an electronic appcessory, electronic tattoos, a smart watch, and the like).
0038According to various embodiments of the present disclosure, the electronic device may be a smart home appliance. The home appliance may include at least one of, for example, a television (TV), a digital versatile disc (DVD) player, an audio, a refrigerator, an air conditioner, a vacuum cleaner, an oven, a microwave oven, a washing machine, an air cleaner, a set-top box, a home automation control panel, a security control panel, a TV box (for example, Samsung HomeSync™, Apple TV™, or Google TV™), a game console (for example, Xbox™ and PlayStation™), an electronic dictionary, an electronic key, a camcorder, and an electronic photo frame.
0039According to an embodiment of the present disclosure, the electronic device may include at least one of various medical devices (for example, various portable medical measuring devices (a blood glucose monitoring device, a heart rate monitoring device, a blood pressure measuring device, a body temperature measuring device, and the like), a magnetic resonance angiography (MRA), a magnetic resonance imaging (MRI), a computed tomography (CT) machine, and an ultrasonic machine), a navigation device, a global positioning system (GPS) receiver, an event data recorder (EDR), a flight data recorder (FDR), a vehicle infotainment devices, an electronic devices for a ship (for example, a navigation device for a ship, and a gyro-compass), avionics, security devices, an automotive head unit, a robot for home or industry, an automatic teller's machine (ATM) in banks, point of sales (POS) in a shop, or internet device of things (for example, a light bulb, various sensors, electric or gas meter, a sprinkler device, a fire alarm, a thermostat, a streetlamp, a toaster, a sporting goods, a hot water tank, a heater, a boiler, and the like).
0040According to various embodiments of the present disclosure, the electronic device may include at least one of a part of furniture or a building/structure, an electronic board, an electronic signature receiving device, a projector, and various kinds of measuring instruments (for example, a water meter, an electric meter, a gas meter, and a radio wave meter). The electronic device according to various embodiments of the present disclosure may be a combination of one or more of the aforementioned various devices. Further, the electronic device according to an embodiment of the present disclosure is not limited to the aforementioned devices, and may include a new electronic device according to the development of technology.
0041Hereinafter, an electronic device according to various embodiments of the present disclosure will be described with reference to the accompanying drawings. As used herein, the term “user” may indicate a person who uses an electronic device or a device (for example, an artificial intelligence electronic device) that uses an electronic device.
0042<figref idref="DRAWINGS">FIG. 1</figref> illustrates a network environment according to various embodiments of the present disclosure.
0043Referring to <figref idref="DRAWINGS">FIG. 1</figref>, an electronic device <b>101</b> in a network environment <b>100</b>, according to various embodiments of the present disclosure, will be described.
0044Referring to <figref idref="DRAWINGS">FIG. 1</figref>, the electronic device <b>101</b> may include a bus <b>110</b>, a processor <b>120</b>, a memory <b>130</b>, an input/output interface <b>150</b>, a display <b>160</b>, and a communication interface <b>170</b>. In an embodiment of the present disclosure, the electronic device <b>101</b> may omit at least some of the above elements or may further include other elements.
0045The bus <b>110</b> may include, for example, a circuit for connecting the elements <b>110</b> to <b>170</b> each other, and transferring communication (for example, a control message and/or data) between the elements.
0046The processor <b>120</b> may include one or more of a CPU, an AP, and a communication processor (CP). The processor <b>120</b> may control, for example, at least one other element of the electronic device <b>101</b> and/or process calculation or data processing associated with communication.
0047The memory <b>130</b> may include a volatile memory and/or a non-volatile memory. The memory <b>130</b> may store, for example, instructions or data related to at least one other element of the electronic device <b>101</b>. According to an embodiment of the present disclosure, the memory <b>130</b> may store S/W and/or a program <b>140</b>. The program <b>140</b> may include, for example, a kernel <b>141</b>, middleware <b>143</b>, an application programming interface (API) <b>145</b>, and/or an application program (or application) <b>147</b>. At least some of the kernel <b>141</b>, the middleware <b>143</b>, and the API <b>145</b> may be referred to as an operating system (OS).
0048The kernel <b>141</b> may control or manage system resources (for example, the bus <b>110</b>, the processor <b>120</b>, or the memory <b>130</b>) used for executing an operation or function implemented by other programs (for example, the middleware <b>143</b>, the API <b>145</b>, or the application program <b>147</b>). Furthermore, the kernel <b>141</b> may provide an interface through which the middleware <b>143</b>, the API <b>145</b>, or the application program <b>147</b> may access individual elements of the electronic device <b>101</b> to control or manage system resources.
0049The middleware <b>143</b> may serve as an intermediary such that, for example, the API <b>145</b> or the application program <b>147</b> communicate with the kernel <b>141</b> to transmit/receive data. Furthermore, in regard to task requests received from the application program <b>147</b>, the middleware <b>143</b> may perform a control (for example, scheduling or load balancing) for the task requests using, for example, a method of assigning, to at least one application, a priority for using the system resources (for example, the bus <b>110</b>, the processor <b>120</b>, or the memory <b>130</b>) of the electronic device <b>101</b>.
0050The API <b>145</b> is an interface by which the applications <b>147</b> control functions provided from the kernel <b>141</b> or the middleware <b>143</b>, and may include, for example, at least one interface or function (for example, instructions) for file control, window control, image processing, or text control.
0051The input/output interface <b>150</b> may serve as an interface which may transmit instructions or data input from a user or another external device to other element(s) of the electronic device <b>101</b>. Further, the input/output interface <b>150</b> may output instructions or data received from other element(s) of the electronic device <b>101</b> to a user or another external device.
0052The display <b>160</b> may include, for example, a liquid crystal display (LCD), a light emitting diode (LED) display, an organic LED (OLED) display, a micro electro mechanical system (MEMS) display, or an electronic paper display. The display <b>160</b> may display various types of contents (for example, text, images, videos, icons, or symbols) for users. The display <b>160</b> may include a touch screen, and may receive, for example, a touch, gesture, proximity, or hovering input using an electronic pen or a user's body part.
0053The communication interface <b>170</b> may establish communication between, for example, the electronic device <b>101</b> and an external device (for example, a first external electronic device <b>102</b>, a second external electronic device <b>104</b>, or a server <b>106</b>). For example, the communication interface <b>170</b> may be connected to a network <b>162</b> through wireless or wired communication so as to communicate with the external device (for example, the second external electronic device <b>104</b> or the server <b>106</b>). In another example, the communication interface <b>170</b> may be connected to the first external electronic device <b>102</b> through a wireless communication <b>164</b>.
0054The wireless communication may use, for example, at least one of long term evolution (LTE), LTE-advanced (LTE-A), code division multiple access (CDMA), wideband CDMA (WCDMA), universal mobile telecommunications system (UMTS), wireless broadband (WiBro), and global system for mobile communications (GSM), as a cellular communication protocol. The wired communication may include, for example, at least one of a universal serial bus (USB), a high definition multimedia interface (HDMI), recommended standard 232 (RS-232), and a plain old telephone service (POTS). The network <b>162</b> may include at least one of communication networks, such as a computer network (for example, a local area network (LAN) or a wide area network (WAN)), the Internet, and a telephone network.
0055Each of the first external electronic device <b>102</b> and the second external electronic device <b>104</b> may be a device that is the same as or different from the electronic device <b>101</b>. According to an embodiment of the present disclosure, the server <b>106</b> may include a group of one or more servers. According to various embodiments of the present disclosure, some or all of the operations executed in the electronic device <b>101</b> may be executed by another electronic device or by a plurality of electronic devices (for example, the first external electronic device <b>102</b> or the second external electronic device <b>104</b>, or the server <b>106</b>). According to an embodiment of the present disclosure, when the electronic device <b>101</b> should perform a function or service automatically or by request, the electronic device <b>101</b> may request another device (for example, the first external electronic device <b>102</b> or the second external electronic device <b>104</b>, or the server <b>106</b>) to perform at least some function related to the function or service, instead of or in addition to performing the function or service by itself. The other electronic device (for example, the first external electronic device <b>102</b> or the second external electronic device <b>104</b> or the server <b>106</b>) may execute the requested function or additional function, and may transmit a result thereof to the electronic device <b>101</b>. The electronic device <b>101</b> may provide the requested function or service based on the received result as it is or after additionally processing the received result. To this end, for example, cloud computing, distributed computing, or client-server computing technology may be used.
0056<figref idref="DRAWINGS">FIG. 2</figref> is a block diagram of an electronic apparatus according to various embodiments of the present disclosure.
0057Referring to <figref idref="DRAWINGS">FIG. 2</figref>, an electronic device <b>201</b> may include, for example, a part or the entirety of the electronic device <b>101</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref>. The electronic device <b>201</b> may include at least one AP <b>210</b>, a communication module <b>220</b>, a subscriber identification module (SIM) card <b>224</b>, a memory <b>230</b>, a sensor module <b>240</b>, an input device <b>250</b>, a display <b>260</b>, an interface <b>270</b>, an audio module <b>280</b>, a camera module <b>291</b>, a power management module <b>295</b>, a battery <b>296</b>, an indicator <b>297</b>, and a motor <b>298</b>.
0058The AP <b>210</b> may control a plurality of H/W or S/W elements connected thereto by driving an operating system or an application program, and may perform a variety of data processing and calculations. The AP <b>210</b> may be embodied as, for example, a system on chip (SoC). According to an embodiment of the present disclosure, the AP <b>210</b> may further include a graphics processing unit (GPU) and/or an image signal processor. The AP <b>210</b> may include at least some of the elements (for example, a cellular module <b>221</b>) illustrated in <figref idref="DRAWINGS">FIG. 2</figref>. The AP <b>210</b> may load instructions or data, received from at least one other element (for example, a non-volatile memory), in a volatile memory to process the loaded instructions or data, and may store various types of data in a non-volatile memory.
0059The communication module <b>220</b> may have a configuration equal or similar to the communication interface <b>170</b> of <figref idref="DRAWINGS">FIG. 1</figref>. The communication module <b>220</b> may include, for example, a cellular module <b>221</b>, a Wi-Fi module <b>223</b>, a Bluetooth (BT) module <b>225</b>, a GPS module <b>227</b>, a near field communication (NFC) module <b>228</b>, and a radio frequency (RF) module <b>229</b>.
0060The cellular module <b>221</b> may provide a voice call, a video call, text message services, or Internet services through, for example, a communication network. According to an embodiment of the present disclosure, the cellular module <b>221</b> may distinguish and authenticate electronic devices <b>201</b> in a communication network using a subscriber identification module (for example, the SIM card <b>224</b>). According to an embodiment of the present disclosure, the cellular module <b>221</b> may perform at least some of the functions which may be provided by the AP <b>210</b>. According to an embodiment of the present disclosure, the cellular module <b>221</b> may include a CP.
0061The Wi-Fi module <b>223</b>, the BT module <b>225</b>, the GPS module <b>227</b>, and the NFC module <b>228</b> may include, for example, a processor for processing data transmitted/received through a corresponding module. According to any embodiment of the present disclosure, at least some (two or more) of the cellular module <b>221</b>, the Wi-Fi module <b>223</b>, the BT module <b>225</b>, the GPS module <b>227</b>, and the NFC module <b>228</b> may be included in one integrated chip (IC) or IC package.
0062The RF module <b>229</b> may transmit/receive, for example, a communication signal (for example, an RF signal). The RF module <b>229</b> may include, for example, a transceiver, a power amp module (PAM), a frequency filter, a low noise amplifier (LNA) or an antenna. According to an embodiment of the present disclosure, at least one of the cellular module <b>221</b>, the Wi-Fi module <b>223</b>, the BT module <b>225</b>, the global navigation satellite system (GNSS) module <b>227</b>, and the NFC module <b>228</b> may transmit and receive RF signals through a separate RF module.
0063The SIM card <b>224</b> may include a card that contains a SIM and/or an embedded SIM, and may contain unique identification information (for example, an IC card identifier (ICCID)) or subscriber information (for example, an international mobile subscriber identity (IMSI)).
0064The memory <b>230</b> may include, for example, an embedded memory <b>232</b> or an external memory. The embedded memory <b>232</b> may include at least one of, for example, a volatile memory (for example, a dynamic random access memory (DRAM), a static RAM (SRAM), a synchronous DRAM (SDRAM), and the like) and a non-volatile memory (for example, a one time programmable read only memory (OTPROM), a PROM, an erasable and programmable ROM (EPROM), an electrically erasable and programmable ROM (EEPROM), a flash memory (for example, a NAND flash memory or a NOR flash memory), a hard drive, or a solid state drive (SSD).
0065The external memory <b>234</b> may further include a flash drive, for example, a compact flash (CF), a secure digital (SD), a micro-SD, a mini-SD, an extreme digital (xD), a memory stick, and the like. The external memory <b>234</b> may be functionally and/or physically connected to the electronic device <b>201</b> through various interfaces.
0066The sensor module <b>240</b> may measure a physical quantity or detect an operation state of the electronic device <b>201</b>, and may convert the measured or detected information into an electrical signal. The sensor module <b>240</b> may include, for example, at least one of a gesture sensor <b>240</b>A, a gyro sensor <b>240</b>B, an atmospheric pressure sensor <b>240</b>C, a magnetic sensor <b>240</b>D, an acceleration sensor <b>240</b>E, a grip sensor <b>240</b>F, a proximity sensor <b>240</b>G, a color sensor <b>240</b>H (for example, red, green, and blue (RGB) sensor), a biometric sensor <b>240</b>I, a temperature/humidity sensor <b>240</b>J, an illumination sensor <b>240</b>K, and an ultra violet (UV) sensor <b>240</b>M. Additionally or alternatively, the sensor module <b>240</b> may include, for example, an E-nose sensor, an electromyography (EMG) sensor, an electroencephalogram (EEG) sensor, an electrocardiogram (ECG) sensor, an infrared (IR) sensor, an iris scanner, and/or a fingerprint sensor. The sensor module <b>240</b> may further include a control circuit for controlling at least one sensor included therein. In an embodiment of the present disclosure, the electronic device <b>201</b> may further include a processor configured to control the sensor module <b>240</b> as a part of or separately from the AP <b>210</b>, and may control the sensor module <b>240</b> while the AP <b>210</b> is in a sleep mode.
0067The input device <b>250</b> may include, for example, a touch panel <b>252</b>, a (digital) pen sensor <b>254</b>, a key <b>256</b>, or an ultrasonic input device <b>258</b>. The touch panel <b>252</b> may use at least one of, for example, a capacitive type, a resistive type, an infrared type, and an ultrasonic type. The touch panel <b>252</b> may further include a control circuit. The touch panel <b>252</b> may further include a tactile layer, and may provide a tactile reaction to a user.
0068The (digital) pen sensor <b>254</b> may include, for example, a recognition sheet which is a part of the touch panel or a separate recognition sheet. The key <b>256</b> may include, for example, a physical button, an optical key or a keypad. The ultrasonic input device <b>258</b> may determine data by detecting an ultrasonic wave generated by an input unit, using a microphone (for example, a microphone <b>288</b>) of the electronic device <b>201</b>.
0069The display <b>260</b> (for example, the display <b>160</b>) may include a panel <b>262</b>, a hologram device <b>264</b> or a projector <b>266</b>. The panel <b>262</b> may include an element equal or similar to the display <b>160</b> of <figref idref="DRAWINGS">FIG. 1</figref>. The panel <b>262</b> may be embodied to be, for example, flexible, transparent, or wearable. The panel <b>262</b> may also be configured to be integrated with the touch panel <b>252</b> as a single module. The hologram device <b>264</b> may show a stereoscopic image in the air by using interference of light. The projector <b>266</b> may project light onto a screen to display an image. The screen may be located, for example, inside or outside the electronic device <b>201</b>. According to an embodiment of the present disclosure, the display <b>260</b> may further include a control circuit for controlling the panel <b>262</b>, the hologram device <b>264</b>, or the projector <b>266</b>.
0070The interface <b>270</b> may include, for example, an HDMI <b>272</b>, a USB <b>274</b>, an optical interface <b>276</b>, or a D-subminiature (D-sub) <b>278</b>. The interface <b>270</b> may be included in, for example, the communication interface <b>170</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref>. Additionally or alternatively, the interface <b>270</b> may include, for example, a mobile high-definition link (MHL) interface, an SD card/multi-media card (MMC) interface, or an Infrared Data Association (IrDA) standard interface.
0071The audio module <b>280</b> may bilaterally convert, for example, a sound and an electrical signal. At least some elements of the audio module <b>280</b> may be included in, for example, the input/output interface <b>150</b> illustrated in <figref idref="DRAWINGS">FIG. 1</figref>. The audio module <b>280</b> may process sound information input or output through, for example, a speaker <b>282</b>, a receiver <b>284</b>, earphones <b>286</b>, the microphone <b>288</b>, and the like.
0072The camera module <b>291</b> is a device which is capable of photographing a still image and a video image. According to an embodiment of the present disclosure, the camera module <b>291</b> may include one or more image sensors (for example, a front sensor or a back sensor), a lens, an image signal processor (ISP) or a flash (for example, LED or xenon lamp).
0073The power management module <b>295</b> may manage, for example, power of the electronic device <b>201</b>. According to an embodiment of the present disclosure, the power management module <b>295</b> may include a power management IC (PMIC), a charger IC, or a battery or fuel gauge. The PMIC may have a wired and/or wireless charging scheme. Examples of the wireless charging method may include, for example, a magnetic resonance method, a magnetic induction method, an electromagnetic method, and the like. Additional circuits (for example, a coil loop, a resonance circuit, a rectifier, and the like) for wireless charging may be further included. The battery gauge may measure, for example, the residual quantity of battery <b>296</b>, a charging voltage, current, or temperature. The battery <b>296</b> may include, for example, a rechargeable battery and/or a solar battery.
0074The indicator <b>297</b> may show particular statuses of the electronic device <b>201</b> or a part (for example, AP <b>210</b>) of the electronic device <b>201</b>, for example, a boot-up status, a message status, a charging status, and the like. The motor <b>298</b> may convert an electrical signal into mechanical vibrations, and may generate a vibration or haptic effect. Although not illustrated, the electronic device <b>201</b> may include a processing unit (for example, a GPU) for supporting mobile TV. The processing device for supporting mobile TV may process media data according to a standard of digital multimedia broadcasting (DMB), digital video broadcasting (DVB), media flow, and the like.
0075Each of the components of the electronic device according to the present disclosure may be implemented by one or more components and the name of the corresponding component may vary depending on a type of the electronic device. In various embodiments of the present disclosure, the electronic device may include at least one of the above-described elements. Some of the above-described elements may be omitted from the electronic device, or the electronic device may further include additional elements. Further, some of the components of the electronic device according to the various embodiments of the present disclosure may be combined to form a single entity, and thus, may equivalently execute functions of the corresponding elements prior to the combination.
0076<figref idref="DRAWINGS">FIG. 3</figref> is a block diagram of a program module according to various embodiments of the present disclosure.
0077Referring to <figref idref="DRAWINGS">FIG. 3</figref>, according to an embodiment of the present disclosure, a program module <b>310</b> (for example, the program <b>140</b>) may include an OS for controlling resources related to an electronic device (for example, the electronic device <b>101</b>) and/or various applications (for example, the application programs <b>147</b>) executed in the operating system. The operating system may be, for example, Android, iOS, Windows, Symbian, Tizen, Bada, and the like.
0078The programming module <b>310</b> may include a kernel <b>320</b>, middleware <b>330</b>, an API <b>360</b>, and/or an application <b>370</b>. At least some of the program module <b>310</b> may be preloaded in an electronic device or downloaded from a server (for example, the server <b>106</b>).
0079The kernel <b>320</b> (for example, the kernel <b>141</b>) may include, for example, a system resource manager <b>321</b> or a device driver <b>323</b>. The system resource manager <b>321</b> may control, allocate, or collect the system resources. According to an embodiment of the present disclosure, the system resource manager <b>321</b> may include a process manager, a memory manager, a file system manager, and the like. The device driver <b>323</b> may include, for example, a display driver, a camera driver, a BT driver, a shared-memory driver, a USB driver, a keypad driver, a Wi-Fi driver, an audio driver, or an inter-process communication (IPC) driver.
0080The middleware <b>330</b> may provide a function required by the applications <b>370</b> in common or may provide various functions to the applications <b>370</b> through the API <b>360</b> so that the applications <b>370</b> may efficiently use the electronic device's limited system resources. According to an embodiment of the present disclosure, the middleware <b>330</b> (for example, the middleware <b>143</b>) may include at least one of a runtime library <b>335</b>, an application manager <b>341</b>, a window manager <b>342</b>, a multimedia manager <b>343</b>, a resource manager <b>344</b>, a power manager <b>345</b>, a database manager <b>346</b>, a package manager <b>347</b>, a connectivity manager <b>348</b>, a notification manager <b>349</b>, a location manager <b>350</b>, a graphic manager <b>351</b>, and a security manager <b>352</b>.
0081The run time library <b>335</b> may include, for example, a library module that a compiler uses in order to add new functions through a programming language while the application <b>370</b> is executed. The run time library <b>335</b> may perform input/output management, memory management, a function for an arithmetic function, and the like.
0082The application manager <b>341</b> may manage, for example, a life cycle of at least one application among the applications <b>370</b>. The window manager <b>342</b> may manage a graphical user interface (GUI) resource used in a screen. The multimedia manager <b>343</b> may recognize a format required for reproducing various media files, and may encode or decode a media file using a codec appropriate for the corresponding format. The resource manager <b>344</b> may manage resources, such as a source code, a memory, or a storage space of at least one application among the applications <b>370</b>.
0083The power manager <b>345</b> may operate together with a basic input/output system (BIOS) to manage a battery or power, and may provide power information required for the operation of the electronic device. The database manager <b>346</b> may generate, search for, or change a database to be used by at least one of the applications <b>370</b>. The package manager <b>347</b> may manage installing or updating applications distributed in the form of a package file.
0084For example, the connectivity manager <b>348</b> may manage wireless connections, such as Wi-Fi, BT, and the like. The notification manager <b>349</b> may display or report an event, such as the reception of a message, an appointment, a proximity notification, and the like, to a user without disturbance. The location manager <b>350</b> may manage location information of an electronic device. The graphic manager <b>351</b> may manage graphic effects to be provided to a user and user interfaces related to the graphic effects. The security manager <b>352</b> may provide various security functions required for system security, user authentication, and the like. According to an embodiment of the present disclosure, when an electronic device (for example, electronic device <b>101</b>) has a call function, the middleware <b>330</b> may further include a telephony manager for managing a voice call function or a video call function of the electronic device.
0085The middleware <b>330</b> may include a middleware module for forming a combination of various functions of the aforementioned elements. The middleware <b>330</b> may provide a module specialized for each type of operating system in order to provide a differentiated function. In addition, a few existing elements may be dynamically removed from the middleware <b>330</b>, or a new element may be added to the middleware <b>330</b>.
0086The API <b>360</b> (for example, the API <b>145</b>) is a set of API programming functions, and may be provided in a different configuration for each operating system. For example, in the case of Android or iOS, one API set may be provided for each platform. In the case of Tizen, two or more API sets may be provided for each platform.
0087The applications <b>370</b> (for example, the application programs <b>147</b>) may include, for example, one or more applications that are capable of providing functions, such as a home <b>371</b>, a dialer <b>372</b>, a short message service (SMS)/multimedia message service (MMS) <b>373</b>, an instant message (IM) <b>374</b>, a browser <b>375</b>, a camera <b>376</b>, an alarm <b>377</b>, contacts <b>378</b>, a voice dialer <b>379</b>, an email <b>380</b>, a calendar <b>381</b>, a media player <b>382</b>, an album <b>383</b>, a clock <b>384</b>, health care (for example, measuring exercise quantity or blood sugar), environment information (for example, atmospheric pressure, humidity, or temperature information), and the like.
0088According to an embodiment of the present disclosure, the applications <b>370</b> may include an application (hereinafter, referred to as an “information exchange application” for ease of the description) supporting exchanging information between the electronic device (for example, the electronic device <b>101</b>) and an external electronic device (for example, the first external electronic device <b>102</b> or the second external electronic device <b>104</b>). The information exchange application may include, for example, a notification relay application for transmitting predetermined information to the external electronic device, or a device management application for managing the external electronic device.
0089For example, the notification relay application may include a function of delivering, to an external electronic apparatus (for example, the first external electronic device <b>102</b> or the second external electronic device <b>104</b>), notification information generated by other applications (for example, an SMS/MMS application, an email application, a health care application, an environmental information application, and the like) of the electronic device. Further, the notification relay application may receive notification information from, for example, an external electronic device, and may provide the received notification information to a user. For example, the device management application may manage (for example, install, delete, or update) at least one function of an external electronic device (for example, the second external electronic device <b>104</b>) communicating with the electronic device (for example, a function of turning on/off the external electronic device itself (or some components) or a function of adjusting luminance (or a resolution) of the display), applications operating in the external electronic device, or services provided by the external electronic device (for example, a call service and a message service).
0090According to an embodiment of the present disclosure, the applications <b>370</b> may include an application (for example, a health management application) designated according to attributes (for example, attributes of the electronic device, such as the type of electronic device which corresponds to a mobile medical device) of the external electronic device (for example, the first external electronic device <b>102</b> or the second external electronic device <b>104</b>). According to an embodiment of the present disclosure, the applications <b>370</b> may include an application received from the external electronic device (for example, the server <b>106</b>, or the first external electronic device <b>102</b> or the second external electronic device <b>104</b>). According to an embodiment of the present disclosure, the applications <b>370</b> may include a preloaded application or a third party application, which can be downloaded from a server. Names of the elements of the program module <b>310</b>, according to the above-described embodiments of the present disclosure, may change depending on the type of operating system.
0091According to various embodiments of the present disclosure, at least some of the program module <b>310</b> may be implemented in S/W, firmware, H/W, or a combination of two or more thereof. At least some of the programming module <b>310</b> may be implemented (for example, executed) by, for example, the processor (for example, the AP <b>210</b>). At least some of the programming module <b>310</b> may include, for example, a module, a program, a routine, sets of instructions, a process, and the like, for performing one or more functions. The term “module” used in embodiments of the present disclosure may refer to, for example, a unit including one or more combinations of H/W, S/W, and firmware. The “module” may be interchangeable with a term, such as a unit, a logic, a logical block, a component, or a circuit. The “module” may be the smallest unit of an integrated component or a part thereof. The “module” may be a minimum unit for performing one or more functions or a part thereof. The “module” may be mechanically or electronically implemented. For example, the “module” according to the present disclosure may include at least one of an application-specific IC (ASIC) chip, a field-programmable gate arrays (FPGA), and a programmable-logic device for performing operations which has been known or are to be developed hereinafter.
0092According to various embodiments of the present disclosure, at least some of the devices (for example, modules or functions thereof) or the method (for example, operations) according to the present disclosure may be implemented by a command stored in a non-transitory computer-readable storage medium in a programming module form. The instruction, when executed by a processor (for example, the processor <b>120</b>), may cause the one or more processors to execute the function corresponding to the instruction. The non-transitory computer-readable storage medium may be, for example, the memory <b>130</b>.
0093Certain aspects of the present disclosure can also be embodied as computer readable code on a non-transitory computer readable recording medium. A non-transitory computer readable recording medium is any data storage device that can store data which can be thereafter read by a computer system. Examples of the non-transitory computer readable recording medium include a Read-Only Memory (ROM), a Random-Access Memory (RAM), Compact Disc-ROMs (CD-ROMs), magnetic tapes, floppy disks, and optical data storage devices. The non-transitory computer readable recording medium can also be distributed over network coupled computer systems so that the computer readable code is stored and executed in a distributed fashion. In addition, functional programs, code, and code segments for accomplishing the present disclosure can be easily construed by programmers skilled in the art to which the present disclosure pertains.
0094At this point it should be noted that the various embodiments of the present disclosure as described above typically involve the processing of input data and the generation of output data to some extent. This input data processing and output data generation may be implemented in hardware or software in combination with hardware. For example, specific electronic components may be employed in a mobile device or similar or related circuitry for implementing the functions associated with the various embodiments of the present disclosure as described above. Alternatively, one or more processors operating in accordance with stored instructions may implement the functions associated with the various embodiments of the present disclosure as described above. If such is the case, it is within the scope of the present disclosure that such instructions may be stored on one or more non-transitory processor readable mediums. Examples of the processor readable mediums include a ROM, a RAM, CD-ROMs, magnetic tapes, floppy disks, and optical data storage devices. The processor readable mediums can also be distributed over network coupled computer systems so that the instructions are stored and executed in a distributed fashion. In addition, functional computer programs, instructions, and instruction segments for accomplishing the present disclosure can be easily construed by programmers skilled in the art to which the present disclosure pertains.
0095The programming module according to the present disclosure may include one or more of the aforementioned components or may further include other additional components, or some of the aforementioned components may be omitted. Operations executed by a module, a programming module, or other component elements according to various embodiments of the present disclosure may be executed sequentially, in parallel, repeatedly, or in a heuristic manner. Further, some operations may be executed according to another order or may be omitted, or other operations may be added.
0096Various embodiments disclosed herein are provided merely to easily describe technical details of the present disclosure and to help the understanding of the present disclosure, and are not intended to limit the scope of the present disclosure. Therefore, it should be construed that all modifications and changes or modified and changed forms based on the technical idea of the present disclosure fall within the scope of the present disclosure.
0097<figref idref="DRAWINGS">FIG. 4</figref> is a diagram illustrating a secure connection system according to various embodiments of the present disclosure. <figref idref="DRAWINGS">FIG. 5</figref> is a block diagram of a secure connection device according to various embodiments of the present disclosure. <figref idref="DRAWINGS">FIG. 5</figref> is a block diagram illustrating a first electronic device <b>400</b><i>a </i>and a second electronic device <b>400</b><i>b </i>of <figref idref="DRAWINGS">FIG. 4</figref>.
0098Referring to <figref idref="DRAWINGS">FIGS. 4 and 5</figref>, a secure connection system according to various embodiments may include a first electronic device <b>400</b><i>a </i>(for example, the electronic device <b>101</b>, the first external electronic device <b>102</b>, or the second external electronic device <b>104</b> of <figref idref="DRAWINGS">FIG. 1</figref> and the electronic device <b>201</b> of <figref idref="DRAWINGS">FIG. 2</figref>), a second electronic device <b>400</b><i>b </i>(for example, the electronic device <b>101</b>, the first external electronic device <b>102</b>, or the second external electronic device <b>104</b> of <figref idref="DRAWINGS">FIG. 1</figref>, or the electronic device <b>201</b> of <figref idref="DRAWINGS">FIG. 2</figref>), and a server device <b>500</b> (for example, the server <b>106</b> of <figref idref="DRAWINGS">FIG. 1</figref>).
0099According to various embodiments of the present disclosure, the first electronic device <b>400</b><i>a </i>may include a first processor <b>410</b>, a first short-range communication module <b>411</b> (for example, the BT module <b>225</b> of <figref idref="DRAWINGS">FIG. 2</figref>), a security module <b>412</b>, and a memory <b>413</b>.
0100According to various embodiments of the present disclosure, the first processor <b>410</b> (for example, the processor <b>120</b> of <figref idref="DRAWINGS">FIG. 1</figref> or the AP <b>201</b> of <figref idref="DRAWINGS">FIG. 2</figref>) may encrypt security information stored in the security module <b>412</b> using a session key identical to a session key of the second electronic device <b>400</b><i>b</i>, and transmits the encrypted security information to the second electronic device <b>400</b><i>b </i>that is connected through the first short-range communication module <b>411</b>.
0101According to an embodiment of the present disclosure, in the state in which the second electronic device <b>400</b><i>b </i>is connected through the first short-range communication module <b>411</b> over a first short-range communication (for example, BT), when a first pairing request message is received from the second electronic device <b>400</b><i>b</i>, the first processor <b>410</b> may transmit, to the second electronic device <b>400</b><i>b</i>, a first pairing response message together with unique information (identification (ID)) of the first electronic device <b>400</b><i>a</i>. After transmitting the first pairing response message, the first processor <b>410</b> may receive, from the second electronic device <b>400</b><i>b</i>, a pairing key that registers, on the server device <b>500</b>, the first electronic device <b>400</b><i>a </i>as an electronic device linked to the second electronic device <b>400</b><i>b</i>. The first processor <b>410</b> may store, in the memory <b>413</b>, the pairing key to be linked to the unique information (ID) of the electronic device. In addition, the pairing key may be stored in a separate security memory, such as TrustZone, which is prepared in the first processor <b>410</b> from the perspective of S/W. In addition, the pairing key may be stored in the security module <b>412</b>, which is separately configured from the perspective of H/W.
0102According to an embodiment of the present disclosure, the unique information (ID) of the electronic device <b>400</b><i>a </i>may be at least one of unique information (ID) of the security module <b>412</b>, and unique information (ID) of the security information stored in the security module <b>412</b>.
0103According to an embodiment of the present disclosure, after transmitting the first pairing response message to the second electronic device <b>400</b><i>b</i>, the first processor <b>410</b> may detect a master key that is stored to be linked to the unique information (ID) of the electronic device, from the memory <b>413</b>, may generate a pairing key using the master key, and may store the pairing key to be linked to the unique information of the electronic device. After transmitting the first pairing response message, the first processor <b>410</b> may receive, from the second electronic device <b>400</b><i>b</i>, a pairing key that registers, on the server device <b>500</b>, the first electronic device <b>400</b><i>a </i>as an electronic device linked to the second electronic device <b>400</b><i>b</i>. When the pairing key stored in the memory <b>413</b> and the pairing key received from the second electronic device <b>400</b><i>b </i>are identical, the first processor <b>410</b> may maintain storing the pairing key. When the pairing key stored in the memory <b>413</b> and the pairing key received from the second electronic device <b>400</b><i>b </i>are not identical, the first processor <b>410</b> may transmit, to the second electronic device <b>400</b><i>b</i>, a message indicating that the pairing keys are different, and may delete the pairing key stored in the memory <b>413</b>.
0104According to an embodiment of the present disclosure, when a second pairing request message is transmitted from the second electronic device <b>400</b><i>b </i>that is connected over a first short-range communication, the first processor <b>410</b> generates a first random number and transmits the first random number to the second electronic device <b>400</b><i>b</i>. After transmitting the first random number to the second electronic device <b>400</b><i>b</i>, when a second random number and a first authentication key are received from the second electronic device <b>400</b><i>b</i>, the first processor <b>410</b> may generate a second authentication key using the first random number, the second random number, and the pairing key. The first processor <b>410</b> may compare the first authentication key received from the second electronic device <b>400</b><i>b </i>and the second authentication key, and when the first authentication key and the second authentication key are identical, the first processor <b>410</b> may transmit, to the second electronic device <b>400</b><i>b</i>, a second pairing response message together with session key generation information.
0105According to an embodiment of the present disclosure, when the first authentication key and the second authentication key are identical, the first processor <b>410</b> may generate a session key using the session key generation information, may encrypt security information stored in the security module <b>412</b> using the session key, and may transmit the encrypted security information to the second electronic device <b>400</b><i>b. </i>
0106According to an embodiment of the present disclosure, the first processor <b>410</b> may generate the session key generation information including at least one of stamp (Timestamp) information and count information of the first electronic device <b>400</b><i>a. </i>
0107According to an embodiment of the present disclosure, the first processor <b>410</b> may designate an expiration date of the session key using the stamp (Timestamp) information out of the session key generation information.
0108According to various embodiments of the present disclosure, the security module <b>412</b> may store security information required for executing a service through a second short-range communication module (for example, the NFC module <b>228</b> of <figref idref="DRAWINGS">FIG. 2</figref>).
0109According to an embodiment of the present disclosure, the security module <b>412</b> may include at least one of an embedded secure element (eSE) chip, a universal integrated circuit card (UICC) chip, an embedded UICC (eUICC) chip, and a host card emulation (HCE) chip.
0110According to an embodiment of the present disclosure, the security module <b>412</b> may store a pairing key that registers, on the server device <b>500</b>, the first electronic device <b>400</b><i>a </i>as an electronic device linked to the second electronic device <b>400</b><i>b</i>, which is received from the second electronic device <b>400</b><i>b. </i>
0111According to an embodiment of the present disclosure, the security module <b>412</b> may be configured to be fixed to the first electronic device <b>400</b><i>a </i>or to be detachable from the first electronic device <b>400</b><i>a</i>. For example, when the security module <b>412</b> is an eSE chip, it may be configured to be fixed to the first electronic device <b>400</b><i>a</i>, or when the security module <b>412</b> is a UICC chip, it may be configured to be detachable from the first electronic device <b>400</b><i>a. </i>
0112According to various embodiments of the present disclosure, the memory <b>413</b> may store the unique information (ID) of the first electronic device <b>400</b><i>a </i>and a pairing key to be linked to each other, or may store the unique information (ID) of the first electronic device <b>400</b><i>a</i>, a master key, and a pairing key to be linked to one another.
0113According to an embodiment of the present disclosure, the memory <b>413</b> may store a session key identical to that of the second electronic device <b>400</b><i>b</i>, and may store an application (for example, a pairing managing application) that is capable of transmitting encrypted security information to the second electronic device <b>400</b><i>b </i>using the session key.
0114According to various embodiments of the present disclosure, the second electronic device <b>400</b><i>b </i>may include a second processor <b>420</b>, a first short-range communication module <b>421</b> (for example, the BT module <b>225</b> of <figref idref="DRAWINGS">FIG. 2</figref>), a second short-range communication module <b>422</b> (for example, the NFC module <b>228</b> of <figref idref="DRAWINGS">FIG. 2</figref>), and a memory <b>423</b>.
0115According to various embodiments of the present disclosure, the second processor <b>420</b> (for example, the processor <b>120</b> of <figref idref="DRAWINGS">FIG. 1</figref> or the AP <b>201</b> of <figref idref="DRAWINGS">FIG. 2</figref>) may receive security information, which has been encrypted using a session key, from the first electronic device <b>400</b><i>a </i>that is connected through the first short-range communication module <b>421</b>, and may transmit, to a third electronic device <b>400</b><i>c </i>that is connected through the second short-range communication module <b>422</b>, the security information decoded through a session key identical to the session key of the first electronic device <b>400</b><i>a. </i>
0116According to an embodiment of the present disclosure, the second processor <b>420</b> may transmit a first pairing request message as a general pairing request, to the first electronic device <b>400</b><i>a </i>that is connected over a first short-range communication. When the unique information (ID) of the first electronic device is received together with a first pairing response message from the first electronic device <b>400</b><i>a</i>, the second processor <b>420</b> may transmit the unique information (ID) of the first electronic device to a server device <b>500</b> together with user information of the second electronic device (for example, an ID and a password registered on a first server <b>510</b>). When a pairing key that registers the first electronic device <b>400</b><i>a </i>as an electronic device linked to the second electronic device <b>400</b><i>b</i>, is received from the server device <b>500</b>, the second processor <b>420</b> may transmit the pairing key to the first electronic device <b>400</b><i>a. </i>
0117According to an embodiment of the present disclosure, the second processor <b>420</b> may transmit a second pairing request message to the first electronic device <b>400</b><i>a </i>as a security pairing request after transmitting the pairing key to the first electronic device <b>400</b><i>a</i>. The second processor <b>420</b> may transmit, to the server device <b>500</b>, a first random number that is received from the first electronic device after the transmission of the second pairing request message. The second processor <b>420</b> may transmit, to the first electronic device <b>400</b><i>a</i>, a second random number and a first authentication key, which are received from the server device <b>500</b>. When session key generation information (for example, time stamp information or count information) is received together with a second pairing response message from the first electronic device <b>400</b><i>a</i>, after the transmission of the second random number and the first authentication key, the second processor <b>420</b> may transmit the session key generation information to the server device <b>500</b>. When a session key is received from the server device <b>500</b> after the transmission of the session key generation information, the second processor <b>420</b> may decode, using the session key, encrypted security information that is received from the first electronic device <b>400</b><i>a</i>. The second processor <b>210</b> transmits the security information, which is received from the first electronic device <b>400</b><i>a</i>, to the third electronic device <b>400</b><i>c </i>(for example, an NFC reader) that is connected over a second short-range communication, and completes authentication, and executes a service using the third electronic device <b>400</b><i>c. </i>
0118According to various embodiments of the present disclosure, a memory <b>423</b> may store user information (for example, an ID and a password) of the second electronic device, which is registered on the server device <b>500</b>.
0119According to an embodiment of the present disclosure, the memory <b>423</b> may store a session key identical to that of the first electronic device <b>400</b><i>a</i>, and may store an application (for example, a pairing managing application) that is capable of decoding, using the session key, encrypted security information that is received from the first electronic device <b>400</b><i>a. </i>
0120According to various embodiments of the present disclosure, the server device <b>500</b> may include the first server <b>510</b> and a second server <b>520</b>. According to an embodiment of the present disclosure, the server device <b>500</b> may be separated into the first server <b>510</b> and the second server <b>520</b>, or the first server <b>510</b> and the second server <b>520</b> may be integrated.
0121According to various embodiments of the present disclosure, the first server <b>510</b> may register the first electronic device <b>400</b><i>a </i>as an electronic device linked to the second electronic device <b>400</b><i>b </i>using the pairing key, may generate a session key that allows the reception of security information of the first electronic device, and may transmit the session key to the second electronic device <b>400</b><i>b. </i>
0122According to an embodiment of the present disclosure, the first server <b>510</b> may include a processor (not illustrated), and may execute a function of a paging managing server.
0123According to an embodiment of the present disclosure, the first server <b>510</b> may receive, from the second electronic device <b>400</b><i>b</i>, the user information (for example, an ID and a password) of the second electronic device <b>400</b><i>b </i>and the unique information (ID) of the first electronic device <b>400</b><i>a</i>. When it is determined that the user information of the second electronic device <b>400</b><i>b </i>is information registered on the first server <b>510</b>, the first server <b>510</b> determines that the authentication with respect to the second electronic device <b>400</b><i>b </i>is successful, and may store the unique information (ID) of the first electronic device <b>400</b><i>a </i>to be linked to the user information of the second electronic device <b>400</b><i>b</i>. When the authentication with respect to the second electronic device <b>400</b><i>b </i>is successful, the first server <b>510</b> may transmit the unique information (ID) of the first electronic device <b>400</b><i>a </i>to the second server <b>520</b>. After the transmission of the unique information (ID) of the first electronic device <b>400</b><i>a</i>, when a pairing key is received from the second server <b>520</b>, the first server <b>510</b> may store the pairing key to be linked to the user information of the second electronic device <b>400</b><i>b </i>and the unique information (ID) of the first electronic device <b>400</b><i>a</i>, and may transmit the pairing key to the second electronic device <b>400</b><i>b. </i>
0124According to an embodiment of the present disclosure, after the transmission of the pairing key, when a first random number is received from the second electronic device <b>400</b><i>b</i>, the first server <b>510</b> may generate a second random number, may generate a first authentication key using the first random number, the second random number, and the pairing key, and may transmit the second random number and the first authentication key to the second electronic device <b>400</b><i>b</i>. After the transmission of the second random number and the first authentication key, when session key generation information is received from the second electronic device <b>400</b><i>b</i>, the first server <b>510</b> may generate a session key using the session key generation information, and may transmit the session key to the second electronic device <b>400</b><i>b. </i>
0125According to various embodiments of the present disclosure, the second server <b>520</b> may generate a pairing key using a master key that corresponds to the unique information of the first electronic device.
0126According to an embodiment of the present disclosure, the second server <b>520</b> may include a processor (not illustrated), and may execute a function of a key managing server.
0127According to an embodiment of the present disclosure, when the unique information (ID) of the first electronic device <b>400</b><i>a </i>is received from the first server <b>510</b>, the second server <b>520</b> may detect, from a database (DB), a master key that is stored to be linked to the first electronic device <b>400</b><i>a</i>, and may transmit the pairing key generated using the master key to the first server <b>510</b>.
0128According to an embodiment of the present disclosure, the first short-range communication module <b>411</b> may execute short-range communication with the second electronic device, the security module <b>412</b> may store security information, and the first processor <b>410</b> may be configured to receive, from the second electronic device, a pairing key that registers the electronic device as an electronic device linked to the second electronic device, transmit session key generation information to the second electronic device when authentication with respect to the second electronic device is completed using the pairing key, generate a session key using the session key generation information, and encrypt the security information and transmit the encrypted security information to the second electronic device.
0129According to various embodiments of the present disclosure, the first processor <b>410</b> may be configured to transmit, to the second electronic device, when a first pairing request message is received from the second electronic device, a first pairing response message together with unique information of the electronic device, and store, when the pairing key is received from the second electronic device, the pairing key to be linked to the unique information of the electronic device.
0130According to various embodiments of the present disclosure, the first processor <b>410</b> may be configured to generate a first random number and transmit the generated first random number to the second electronic device, when a second pairing request message is received from the second electronic device, generate, when a second random number and a first authentication key are received from the second electronic device, a second authentication key using the first random number, the second random number, and the pairing key, and transmit, to the second electronic device, when the first authentication key and the second authentication key are identical, a second pairing response message together with session key generation information.
0131According to various embodiments of the present disclosure, the first processor <b>410</b> may be configured to generate, when the first authentication key and the second authentication key are identical, the session key using the session key generation information.
0132According to various embodiments of the present disclosure, the session key generation information includes at least one of time stamp (Timestamp) information and count information. According to various embodiments of the present disclosure, the first short-range communication module <b>421</b> may execute short-range communication with a first electronic device, the second short-range communication module <b>422</b> may execute short-range communication with a third electronic device, and the processor may <b>420</b> be configured to transmit, when a pairing key, which registers the first electronic device as an electronic device linked to the electronic device, is received from a server device, the pairing key to the first electronic device, and transmit, to the server device, session key generation information received from the first electronic device, decode encrypted security information that is received from the first electronic device, using a session key received from the server device, and transmit the decoded information to the third electronic device.
0133Timestamp refers to a time stamp when the first electronic device authenticates the first server, and is a factor used when the first server generates a session key. Timestamp varies for each session and thus, a session key generated using Timestamp is generated to be different for each time. In addition, Timestamp is a reference used when the first server maintains a session during a predetermined period of time, and indicates a period of time for using a session key.
0134Count indicates the number of sessions that are connected to the first server up to date in the first electronic device, and is a factor used when the first server generates a session key. Count in association with a connection between the first electronic device and the first server varies over time and thus, a session key is generated to be different for each time. In addition, the first server and the first electronic device have an identical count value and thus, when the first server receives a different count value, there is a high probability of an abnormal connection. Accordingly, Count may detect an abnormal connection.
0135According to various embodiments of the present disclosure, the second processor <b>420</b> may be configured to transmit, when a first pairing response message is received together with unique information of the first electronic device, from the first electronic device, in response to a first pairing request message, the unique information of the first electronic device together with user information of the electronic device to the server device, and receive the pairing key from the server device.
0136According to various embodiments of the present disclosure, the second processor <b>420</b> may be configured to transmit, when a first random number is received from the first electronic device in response to the transmission of a second pairing request message, the first random number to the server device, and transmit a second random number and a first authentication key received from the server device, to the first electronic device, and receive session key generation information from the first electronic device.
0137According to various embodiments of the present disclosure, the session key generation information includes at least one of time stamp (Timestamp) information and count information. According to various embodiments of the present disclosure, a processor of the server device <b>500</b> may be configured to generate and store a pairing key for registering a first electronic device as being linked to an electronic device, using unique information of the first electronic device received from the electronic device, and transmitting the pairing key to the electronic device, and generating a session key identical to a session key of the first electronic device using session key generation information of the first electronic device received from the electronic device, and transmitting the session key to the electronic device.
0138According to various embodiments of the present disclosure, the processor of the server device <b>500</b> may be configured to perform, when user information of the electronic device and unique information of the first electronic device are received from the electronic device, authentication with respect to the electronic device using the user information of the electronic device, and generate and store the pairing key using a master key that corresponds to the unique information of the first electronic device, when the authentication with respect to the electronic device is completed.
0139According to various embodiments of the present disclosure, the processor of the server device <b>500</b> may be configured to generate, when a first random number is received from the electronic device, a second random number, generate a first authentication key using the first random number, the second random number, and the pairing key, and transmit the second random number and the first authentication key to the electronic device, and receive session key generation information of the first electronic device from the electronic device.
0140According to various embodiments of the present disclosure, the session key generation information may include at least one of time stamp (Timestamp) information and count information.
0141<figref idref="DRAWINGS">FIGS. 6A and 6B</figref> are flowcharts illustrating a registration method for a secure connection according to various embodiments of the present disclosure.
0142Referring to <figref idref="DRAWINGS">FIGS. 6A and 6B</figref>, a registration method for a secure connection according to various embodiments of the present disclosure is described through an example executed by the first electronic device <b>400</b><i>a</i>, the second electronic device <b>400</b><i>b</i>, and the server device <b>500</b> of <figref idref="DRAWINGS">FIGS. 4 and 5</figref>. With reference to <figref idref="DRAWINGS">FIGS. 6A and 6B</figref>, in operation <b>611</b>, the first electronic device <b>400</b><i>a </i>(for example, the first processor <b>410</b>) and the second electronic device <b>400</b><i>b </i>(for example, the second processor <b>420</b>) are connected through a first short-range communication (for example, BT communication).
0143In operation <b>612</b>, the second electronic device <b>400</b><i>b </i>transmits a first pairing request message, which is a general pairing request, to the first electronic device <b>400</b><i>a. </i>
0144In operation <b>613</b>, the first electronic device <b>400</b><i>a </i>transmits, to the second electronic device <b>400</b><i>b</i>, a first pairing response message together with the unique information (for example, the unique information of security information) of the first electronic device.
0145In operation <b>614</b>, when the unique information of the first electronic device is received from the first electronic device <b>400</b><i>a</i>, the second electronic device <b>400</b><i>b </i>transmits, to the first server <b>510</b>, the user information (for example, an ID and a password) of the second electronic device and the unique information of the first electronic device.
0146In operation <b>615</b>, the first server <b>510</b> (for example, a processor) executes authentication with respect to the second electronic device based on whether the user information of the second electronic device <b>400</b><i>b </i>exists from among a plurality of pieces of user information stored in the DB of the first server <b>510</b>.
0147In operation <b>616</b>, the first server <b>510</b> determines that the authentication fails when the user information of the second electronic device <b>400</b><i>b </i>does not exist among the plurality of pieces of user information stored in the DB of the first server <b>510</b>, and in operation <b>617</b>, transmits an error information message to the second electronic device <b>400</b><i>b </i>in response to the failure of the authentication.
0148In operation <b>616</b>, the first server <b>510</b> determines that the authentication is successful when the user information of the second electronic device <b>400</b><i>b </i>exists among the plurality of pieces of user information stored in the DB of the first server <b>510</b>, and in operation <b>618</b>, stores the unique information of the first electronic device to be linked to the user information of the second electronic device in the DB of the first server.
0149In operation <b>619</b>, the first server <b>510</b> transmits the unique information of the first electronic device to the second server <b>520</b>.
0150In operation <b>620</b>, the second server <b>520</b> detects, from the DB of the second server <b>520</b>, a master key stored to correspond to the unique information of the first electronic device when the unique information of the first electronic device is received from the first server <b>510</b>. The second server <b>520</b> generates a pairing key (K_P) using the detected master key in operation <b>621</b>, and transmits the pairing key (K_P) to the first server <b>510</b> in operation <b>622</b>.
0151In operation <b>623</b>, when the pairing key (K_P) is received from the second server <b>520</b>, the first server <b>510</b> stores, in the DB of the first server, the pairing key (K_P) to be linked to the user information of the second electronic device and the unique information of the first electronic device, thereby registering the first electronic device <b>400</b><i>a </i>as an electronic device linked to the second electronic device <b>400</b><i>b </i>using the pairing key (K_P).
0152In operation <b>624</b>, the first server <b>510</b> transmits the pairing key (K_P) to the second electronic device <b>400</b><i>b. </i>
0153In operation <b>625</b>, when the pairing key (K_P) that registers the first electronic device <b>400</b><i>a </i>as an electronic device linked to the second electronic device <b>400</b><i>b </i>is received from the first server <b>510</b>, the second electronic device <b>400</b><i>b </i>transmits the pairing key (K_P) to the first electronic device <b>400</b><i>a. </i>
0154In operation <b>626</b>, when the pairing key (K_P) that registers the first electronic device <b>400</b><i>a </i>as an electronic device associated the second electronic device <b>400</b><i>b </i>is received from the second electronic device <b>400</b><i>b</i>, the first electronic device <b>400</b><i>a </i>stores the pairing key (K_P) to be linked to the unique information of the first electronic device.
0155<figref idref="DRAWINGS">FIGS. 7A and 7B</figref> are flowcharts illustrating a secure connection method according to various embodiments of the present disclosure.
0156Referring to <figref idref="DRAWINGS">FIGS. 7A and 7B</figref>, a secure connection method, according to various embodiments of the present disclosure, is described through an example executed by the first electronic device <b>400</b><i>a</i>, the second electronic device <b>400</b><i>b</i>, and the server device <b>500</b> of <figref idref="DRAWINGS">FIGS. 4 and 5</figref>. A secure connection method of <figref idref="DRAWINGS">FIGS. 7A and 7B</figref>, according to various embodiments of the present disclosure, may be executed after executing a registration method for secure connection of <figref idref="DRAWINGS">FIGS. 6A and 6B</figref> according to various embodiments of the present disclosure. With reference to <figref idref="DRAWINGS">FIGS. 7A and 7B</figref>, in operation <b>711</b>, the first electronic device <b>400</b><i>a </i>(for example, the first processor <b>410</b>) and the second electronic device <b>400</b><i>b </i>(for example, the second processor <b>420</b>) may be connected through a first short-range communication (for example, BT communication).
0157In operation <b>712</b>, as the second electronic device <b>400</b><i>b </i>transmits the user information of the second electronic device to the first server <b>510</b> through the web and determines that the authentication is successful, the second electronic device <b>400</b><i>b </i>may be connected to the first server <b>510</b>.
0158In operation <b>713</b>, after the registration of <figref idref="DRAWINGS">FIGS. 6A and 6B</figref>, the second electronic device <b>400</b><i>b </i>may transmit a second pairing request message, which is a security pairing request, to the first electronic device <b>400</b><i>a. </i>
0159In operation <b>714</b>, when the second pairing request message is received from the second electronic device <b>400</b><i>b</i>, the first electronic device <b>400</b><i>a </i>generates a first random number in operation <b>714</b>, and transmits the first random number to the second electronic device <b>400</b><i>b </i>in operation <b>715</b>.
0160In operation <b>716</b>, when the first random number is received from the first electronic device <b>400</b><i>a</i>, the second electronic device <b>400</b><i>b </i>transmits the first random number to the first server <b>510</b> (for example, the processor).
0161In operation <b>717</b>, when the first random number is received from the second electronic device <b>400</b><i>b</i>, the first server <b>510</b> generates a second random number.
0162In operation <b>718</b>, the first server <b>510</b> generates a first authentication key (Res_Key) using at least one of the first random number, the second random number, and the pairing key (K_P).
0163In operation <b>719</b>, the first server <b>510</b> transmits the second random number and the first authentication key (Res_Key) to the second electronic device <b>400</b><i>b. </i>
0164In operation <b>720</b>, when the second random number and the first authentication key (Res_key) are received from the first server <b>510</b>, the second electronic device <b>400</b><i>b </i>transmits the second random number and the first authentication key (Res_Key) to the first electronic device <b>400</b><i>a. </i>
0165In operation <b>721</b>, when the second random number and the first authentication key (Res_Key) are received from the second electronic device <b>400</b><i>b</i>, the first electronic device <b>400</b><i>a </i>generates a second authentication key (Res_Key) using at least one of the first random number, the second random number, and the pairing key (K_P).
0166In operation <b>722</b>, the first electronic device <b>400</b><i>a </i>compares the first authentication key received from the second electronic device <b>400</b><i>b </i>and the generated second authentication key. When the first authentication key and the second authentication key are different in operation <b>722</b>, the first electronic device <b>400</b><i>a </i>transmits, to the second electronic device <b>400</b><i>b</i>, an error message indicating that the authentication keys are different in operation <b>723</b>. When the first authentication key and the second authentication key are identical in operation <b>722</b>, the first electronic device <b>400</b><i>a </i>transmits a second pairing response message together with the session key generation information (for example, time stamp (Timestamp) information and count information) to the second electronic device <b>400</b><i>b </i>in operation <b>724</b>.
0167In operation <b>725</b>, the first electronic device <b>400</b><i>a </i>generates a session key (K_S) using the session key generation information (for example, time stamp (Timestamp) information and count information).
0168In operation <b>726</b>, when the session key generation information and the second pairing response message are received from the first electronic device <b>400</b><i>a</i>, the second electronic device <b>400</b><i>b </i>transmits the session key generation information to the first server <b>510</b>.
0169In operation <b>727</b>, when the session key generation information is received from the second electronic device <b>400</b><i>b</i>, the first server <b>510</b> generates a session key (K_S) using the session key generation information.
0170In operation <b>728</b>, the first server <b>510</b> transmits the session key (K_S) to the second electronic device <b>400</b><i>b. </i>
0171In operation <b>729</b>, the first electronic device <b>400</b><i>a </i>encrypts security information stored in the security module <b>412</b> of the first electronic device <b>400</b><i>a </i>using the session key (K_S) that is identical to that of the second electronic device <b>400</b><i>b</i>, and transmits the encrypted security information to the second electronic device <b>400</b><i>b</i>. When the encrypted security information is received from the first electronic device <b>400</b><i>a </i>in operation <b>729</b>, the second electronic device <b>400</b><i>b </i>decodes the security information using the session key.
0172In operation <b>730</b>, when the second electronic device <b>400</b><i>b </i>transmits the security information received from the first electronic device <b>400</b><i>a </i>to the third electronic device <b>400</b><i>c </i>(for example, an NFC reader) and determines that the authentication is completed, the second electronic device <b>400</b><i>b </i>may proceed with a service (for example, NFC payment service) with the third electronic device <b>400</b><i>c. </i>
0173According to various embodiments of the present disclosure, a secure connection method of an electronic device is provided. The method includes receiving a pairing key that registers the electronic device as an electronic device that is linked to a second electronic device from the second electronic device that is connected over a first short-range communication, transmitting session key generation information to the second electronic device when authentication with respect to the second electronic device is completed using the pairing key, and generating a session key using the session key generation information, encrypting security information through the session key, and transmitting the encrypted information to the second electronic device.
0174According to various embodiments of the present disclosure, the operation of receiving the pairing key includes transmitting, to the second electronic device, when a first pairing request message is received from the second electronic device, a first pairing response message together with unique information of the electronic device, and storing, when the pairing key is received from the second electronic device, the pairing key to be linked to the unique information of the electronic device.
0175According to various embodiments of the present disclosure, the operation of transmitting the session key generation information includes generating, when a second pairing request message is received from the second electronic device, a first random number and transmitting the first random number to the second electronic device, generating, when a second random number and a first authentication key are received from the second electronic device, a second authentication key using the first random number, the second random number, and the pairing key, and transmitting, to the second electronic device, when the first authentication key and the second authentication key are identical, a second pairing response message together with the session key generation information.
0176According to various embodiments of the present disclosure, when the first authentication key and the second authentication key are identical, the method further includes generating the session key using the session key generation information.
0177According to various embodiments of the present disclosure, the session key generation information includes at least one of time stamp (Timestamp) information and count information.
0178According to various embodiments of the present disclosure, a secure connection method of an electronic device is provided. The method includes transmitting, when a pairing key that registers a first electronic device as an electronic device linked to the electronic device is received from a server device, the pairing key to the first electronic device that is connected over a first short-range communication, transmitting, to the server device, session key generation information received from the first electronic device, and decoding, when a session key is received from the server device, encrypted security information that is received from the first electronic device, using the session key, and transmitting the decoded information to a third electronic device that is connected over a second short-range communication.
0179According to various embodiments of the present disclosure, the operation of transmitting to the first electronic device includes transmitting a first pairing request message, transmitting, to the server device, the unique information of the first electronic device together with the user information of the electronic device when a first pairing response message is received together with the unique information of the first electronic device, from the first electronic device, in response to the first pairing request message, and receiving the pairing key from the server device.
0180According to various embodiments of the present disclosure, the operation of transmitting to the server device, includes transmitting a second pairing request message, transmitting, when a first random number is received from the first electronic device in response to transmission of the second pairing request message, the first random number to the server device, transmitting, when a second random number and a first authentication key are received from the server device, the second random number and the first authentication key to the first electronic device, and receiving the session key generation information from the first electronic device.
0181According to various embodiments of the present disclosure, the session key generation information includes at least one of time stamp (Timestamp) information and count information.
0182According to various embodiments of the present disclosure, a secure connection method of a server device is provided. The method includes generating and storing, when unique information of a first electronic device is received from an electronic device, a pairing key for registering the first electronic device as an electronic device linked to the electronic device, using the unique information of the first electronic device, and transmitting the pairing key to the electronic device, and generating, when session key generation information of the first electronic device is received from the electronic device, a session key identical to a session key of the first electronic device using the session key generation information, and transmitting the session key to the electronic device.
0183According to various embodiments of the present disclosure, the operation of transmitting the pairing key to the electronic device includes executing, when user information of the electronic device and unique information of the first electronic device are received from the electronic device, authentication with respect to the electronic device using the user information of the electronic device, and generating and storing, when the authentication with respect to the electronic device is completed, the pairing key using a master key that corresponds to the unique information of the first electronic device.
0184According to various embodiments of the present disclosure, the operation of transmitting the session key to the electronic device includes generating, when a first random number is received from the electronic device, a second random number, generating a first authentication key using the first random number, the second random number, and the pairing key, transmitting the second random number and the first authentication key to the electronic device, and receiving session key generation information of the first electronic device from the electronic device.
0185According to various embodiments of the present disclosure, the session key generation information includes at least one of Timestamp information and count information.
0186While the present disclosure has been shown and described with reference to various embodiments thereof, it will be understood by those skilled in the art that various changes in form and details may be made therein without departing from the spirit and scope of the present disclosure as defined by the appended claims and their equivalents.
Contents6
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10289571B2 | Cited by | United States of America | Search report |
| US11871372B2 | Cited by | United States of America | Applicant |
| US11197150B2 | Cited by | United States of America | Search report |
| US11354048B2 | Cited by | United States of America | Search report |
| US2017270059A1 | Cited by | United States of America | Pre-grant |
| US10757676B1 | Cited by | United States of America | Search report |
| US10223633B2 | Cited by | United States of America | Search report |
| US11496900B2 | Cited by | United States of America | Search report |
| CN119766271A | Cited by | China | Search report |
| US10908806B2 | Cited by | United States of America | Applicant |
| US2019034909A1 | Cited by | United States of America | Search report |
| US12470913B2 | Cited by | United States of America | Applicant |
| JP2018013882A | Cited by | Japan | Search report |
| US10993203B2 | Cited by | United States of America | Applicant |
| US11122045B2 | Cited by | United States of America | Search report |
| US2017270059A1 | Cited by | United States of America | Search report |
| EP3633913A1 | Cited by | European Patent Office (EPO) | Search report |
| US10810140B2 | Cited by | United States of America | Applicant |
| US12022571B2 | Cited by | United States of America | Applicant |
| JP2018013881A | Cited by | Japan | Search report |
| US2003061477A1 | Cites | United States of America | Pre-grant |
| US2006153386A1 | Cites | United States of America | Pre-grant |
| US2007251997A1 | Cites | United States of America | Pre-grant |
| US2008016368A1 | Cites | United States of America | Pre-grant |
| US2008016537A1 | Cites | United States of America | Pre-grant |
| US2008065892A1 | Cites | United States of America | Pre-grant |
| US2010023747A1 | Cites | United States of America | Pre-grant |
| US2010220856A1 | Cites | United States of America | Pre-grant |
| US2013132286A1 | Cites | United States of America | Pre-grant |
| US2014079217A1 | Cites | United States of America | Pre-grant |
| US2014141721A1 | Cites | United States of America | Pre-grant |
| US2014208384A1 | Cites | United States of America | Pre-grant |
| US9032501B1 | Cites | United States of America | Pre-grant |
14 members in 7 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 1020140142627 | Republic of Korea | – | |
| 20140142627 | Republic of Korea | A |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| US2016112386A1 | United States of America | A1 | |
| CN105530596A | China | A | |
| EP3013018A1 | European Patent Office (EPO) | A1 | |
| WO2016064184A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20160046559A | Republic of Korea | A | |
| AU2015337278A1 | Australia | A1 | |
| US10164775B2 | United States of America | B2 | |
| US2019074964A1 | United States of America | A1 | |
| EP3013018B1 | European Patent Office (EPO) | B1 | |
| AU2015337278B2 | Australia | B2 | |
| CN105530596B | China | B | |
| US10965455B2 | United States of America | B2 | |
| KR102294118B1 | Republic of Korea | B1 | |
| MY190913A | Malaysia | A |
62 transactions on the USPTO file
Allowed after 1 non-final rejection, 1 final rejection and 1 RCE.
- Non-final rejections
- 1
- Final rejections
- 1
- RCEs
- 1
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response to Election / Restriction FiledELC. | ELC. | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Restriction RequirementMCTRS | MCTRS | |
| Restriction/Election RequirementCTRS | CTRS | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Email NotificationEML_NTR | EML_NTR | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Reference capture on IDSRCAP | RCAP | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Priority document has successfully retrieved via PDX/DASPD.RECVD | PD.RECVD | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Email NotificationEML_NTR | EML_NTR | |
| Application Is Now CompleteCOMP | COMP | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Sent to Classification ContractorPGPC | PGPC | |
| FITF set to YES - revise initial settingFTFS | FTFS | |
| Cleared by OIPE CSRL194 | L194 | |
| Patent Term Adjustment - Ready for ExaminationPTA.RFE | PTA.RFE | |
| Request from applicant for the USPTO to retrieve the Priority DocumentPDREQUST | PDREQUST | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication
- 20160112386
- Application
- 14887690
Titles
- English
- Device and Method for Secure Connection
Patent term adjustment
- A delay
- +163 daysthe office missed an examination deadline
- B delay
- +29 dayspendency past three years
- Net adjustment
- 192 days
Classification
- CPC, 20
- H04L63/0492
- H04W12/04
- H04L63/0853
- H04L9/0869
- G06Q20/3278
- H04W76/14
- H04W4/80
- H04W4/008
- H04W12/02
- H04W12/06
- H04L9/0838
- H04L63/068
- H04L2463/061
- H04W12/61
- H04W12/033
- H04W12/0431
- G06Q20/3829
- G06Q20/321
- H04L9/32
- G06F21/445
- IPC, 7
- H04L29 06
- H04L9 08
- H04W4 80
- H04W12 04
- H04W12 06
- H04W76 14
- H04W4 00