KR101608510B1 - 글로벌 플랫폼 규격을 사용하는 발행자 보안 도메인에 대한 키 관리 시스템 및 방법 - Google Patents
글로벌 플랫폼 규격을 사용하는 발행자 보안 도메인에 대한 키 관리 시스템 및 방법 Download PDFInfo
- Publication number
- KR101608510B1 KR101608510B1 KR1020147018590A KR20147018590A KR101608510B1 KR 101608510 B1 KR101608510 B1 KR 101608510B1 KR 1020147018590 A KR1020147018590 A KR 1020147018590A KR 20147018590 A KR20147018590 A KR 20147018590A KR 101608510 B1 KR101608510 B1 KR 101608510B1
- Authority
- KR
- South Korea
- Prior art keywords
- isd
- server
- domain
- key set
- security
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/72—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/062—Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/322—Aspects of commerce using mobile devices [M-devices]
- G06Q20/3229—Use of the SIM of a M-device as secure element
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3829—Payment protocols; Details thereof insuring higher security of transaction involving key management
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0877—Generation of secret information including derivation or calculation of cryptographic keys or passwords using additional device, e.g. trusted platform module [TPM], smartcard, USB or hardware security module [HSM]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0891—Revocation or update of secret information, e.g. encryption key update or rekeying
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3234—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
- H04W12/086—Access security using security domains
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/30—Security of mobile devices; Security of mobile applications
- H04W12/35—Protecting application or service provisioning, e.g. securing SIM application provisioning
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Business, Economics & Management (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- Accounting & Taxation (AREA)
- General Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Computing Systems (AREA)
- Finance (AREA)
- Mathematical Physics (AREA)
- Software Systems (AREA)
- Telephonic Communication Services (AREA)
- Storage Device Security (AREA)
- Mobile Radio Communication Systems (AREA)
- Computer And Data Communications (AREA)
- Telephone Function (AREA)
Abstract
Description
<도 1>
도 1은 예시적인 시스템 실시예를 나타낸 도면이다.
<도 2>
도 2는 예시적인 네트워크 구성을 나타낸 도면이다.
<도 3>
도 3은 글로벌 플랫폼에 의해 정의되는 보안 요소를 나타낸 도면이다.
<도 4>
도 4는 활성화 동안의 ISD 초기화를 나타낸 도면이다.
<도 5>
도 5는 예시적인 암호 키 교환을 나타낸 도면이다.
<도 6>
도 6은 활성화 동안 서버 초기화를 위한 예시적인 방법 실시예를 나타낸 도면이다.
<도 7>
도 7은 활성화 동안 클라이언트 초기화를 위한 예시적인 방법 실시예를 나타낸 도면이다.
<도 8>
도 8은 ISD 사전 개인화를 나타낸 도면이다.
<도 9>
도 9는 서버 ISD 사전 개인화를 위한 예시적인 방법 실시예를 나타낸 도면이다.
<도 10>
도 10은 클라이언트 ISD 사전 개인화를 위한 예시적인 방법 실시예를 나타낸 도면이다.
Claims (26)
- 클라이언트 장치에서 서버로부터, 상기 서버에서의 제1 발행자 보안 도메인(ISD, Issuer Security Domain) 암호화 키 세트를 업데이트하라는 허가를 수신하는 단계;
상기 클라이언트 장치 상의 보안 요소(secure element)를 통해, 상기 서버에서의 상기 제1 ISD 암호화 키세트를 업데이트하는 데에 사용될 제2 ISD 키 세트를 생성하는 단계;
암호화된 제2 ISD 키 세트를 산출하도록, 상기 클라이언트 장치 상의 상기 보안 요소를 통해, 상기 제2 ISD 키 세트를 서버 공개 키(server public key)로 암호화하는 단계; 및
상기 서버에서의 상기 제1 ISD 암호화 키 세트를 상기 제2 ISD 키 세트로 업데이트하기 위해 상기 암호화된 제2 ISD 키 세트를 상기 서버로 송신하는 단계
를 포함하고,
상기 제2 ISD 키 세트는 상기 서버에서의 상기 제1 ISD 암호화 키 세트를 교체하고, 상기 제2 ISD 키 세트는 상기 서버 및 상기 보안 요소에게만 알려진 것인, 방법. - 제1항에 있어서, 상기 보안 요소는 적어도 하나의 보안 도메인을 포함하고, 상기 적어도 하나의 보안 도메인은 발행자 보안 도메인, 감독 기관 보안 도메인(Controlling Authority Security Domain), 및 보조 보안 도메인(Supplemental Security Domain) 중 하나인, 방법.
- 제2항에 있어서, 상기 발행자 보안 도메인은 적어도 하나의 다른 도메인을 관리하는 최상위 레벨 보안 도메인인, 방법.
- 제3항에 있어서, 상기 발행자 보안 도메인은 카드 콘텐츠, 카드 수명 주기 및 응용 프로그램 수명 주기(application life cycle) 중 적어도 하나를 관리하는 것인, 방법.
- 제1항에 있어서, 상기 보안 요소는 글로벌 플랫폼 카드 규격(Global Platform Card specifications)에 따라 구현되고, 상기 제2 ISD 키 세트는 제3자 벤더로부터 수신된 암호화 키에 기초한 것이 아닌, 방법.
- 제1항에 있어서, 상기 보안 요소는 보안 도메인에 관련된 적어도 하나의 암호 키(cryptographic key)를 저장하는, 방법.
- 제6항에 있어서, 보안 도메인에의 액세스는 상기 보안 도메인에 대한 암호 키에의 액세스를 갖는 프로세스로 제한되는 것인, 방법.
- 제1항에 있어서, 상기 보안 요소는 상기 클라이언트 장치 내의 전용 하드웨어 컴포넌트를 포함하는 것인, 방법.
- 제8항에 있어서, 상기 서버는 상기 클라이언트 장치를 통해 상기 보안 요소와 통신하는 것인, 방법.
- 제8항에 있어서, 상기 허가는 상기 클라이언트 장치 및 응용 프로그램 중 적어도 하나의 초기 활성화 동안 발행되는 것인, 방법.
- 프로세서; 및
컴퓨터 실행가능한 명령어들을 저장하도록 구성된 메모리
를 포함하고,
상기 컴퓨터 실행가능한 명령어들은, 상기 프로세서에 의해 수행될 때, 시스템이,
벤더에서, 발행자 보안 도메인(ISD) 암호화 키 세트를 생성하고;
상기 ISD 암호화 키 세트 및 서버 공개 키를 클라이언트 장치에 있는 보안 요소로 송신하고 - 상기 보안 요소는 글로벌 플랫폼 카드 규격의 적어도 일부분을 구현함 -;
암호화된 ISD 키 세트를 산출하도록, 상기 벤더에서, 상기 ISD 암호화 키 세트를 상기 서버 공개 키로 암호화하고;
상기 암호화된 ISD 키 세트를 서버로 송신하게 하고,
상기 서버에서의 기존의 ISD 암호화 키 세트는 상기 벤더의 이용없이 상기 보안 요소에 의해 생성되는 새로운 ISD 키 세트로 안전하게(securely) 업데이트되고, 상기 새로운 ISD 키 세트는 상기 보안 요소 및 상기 서버에게만 알려진 것인, 시스템. - 제11항에 있어서, 상기 보안 요소는 상기 클라이언트 장치 내의 전용 하드웨어 컴포넌트를 포함하는 것인, 시스템.
- 제12항에 있어서, 상기 서버는 보안 요소 식별 컴포넌트(secure element identification component)에 의해 식별되는 상기 클라이언트 장치 내의 적어도 하나의 보안 요소를 제공하는 것인, 시스템.
- 제13항에 있어서, 각각의 보안 요소는 상기 보안 요소 식별 컴포넌트에 의해 식별되는 상이한 ISD 암호화 키 세트를 갖는, 시스템.
- 클라이언트 장치에 의해 실행될 때, 상기 클라이언트 장치로 하여금 단계들을 수행하게 하는 명령어들을 저장하도록 구성된 비일시적 컴퓨터 판독가능 저장 매체로서, 상기 단계들은,
상기 클라이언트 장치에서, 발행자 보안 도메인(ISD) 암호화 키 세트 및 서버 공개 키를 수신하는 단계 - 상기 ISD 암호화 키 세트는 벤더에서 생성된 것이고, 상기 클라이언트 장치는 보안 요소를 포함함 - ;
상기 ISD 암호화 키 세트 및 서버 공개 키를 상기 클라이언트 장치에서 저장하는 단계; 및
상기 보안 요소를 통해, 서버에서의 기존의 ISD 키 세트를 업데이트하는 데에 사용될 새로운 ISD 키 세트를 생성하는 단계
를 포함하고,
상기 서버에서의 상기 기존의 ISD 키 세트는 상기 벤더의 이용없이 상기 새로운 ISD 키 세트로 안전하게 업데이트되고, 상기 새로운 ISD 키 세트는 상기 보안 요소 및 상기 서버에게만 알려진 것인, 비일시적 컴퓨터 판독가능 저장 매체. - 제15항에 있어서, 상기 보안 요소는 글로벌 플랫폼 카드 규격의 적어도 일부분을 구현하는 것인, 비일시적 컴퓨터 판독가능 저장 매체.
- 제15항에 있어서, 상기 보안 요소는 적어도 하나의 보안 도메인을 갖고, 상기 적어도 하나의 보안 도메인은 발행자 보안 도메인, 감독 기관 보안 도메인, 및 보조 보안 도메인 중 하나인, 비일시적 컴퓨터 판독가능 저장 매체.
- 제17항에 있어서, 상기 발행자 보안 도메인은 적어도 하나의 다른 도메인을 관리하는 최상위 레벨 보안 도메인인, 비일시적 컴퓨터 판독가능 저장 매체.
- 제18항에 있어서, 상기 발행자 보안 도메인은 카드 콘텐츠, 카드 수명 주기 및 응용 프로그램 수명 주기 중 적어도 하나를 관리하는 것인, 비일시적 컴퓨터 판독가능 저장 매체.
- 제15항에 있어서, 상기 보안 요소는 글로벌 플랫폼 규격에 따라 구현되는 것인, 비일시적 컴퓨터 판독가능 저장 매체.
- 삭제
- 삭제
- 삭제
- 삭제
- 삭제
- 삭제
Applications Claiming Priority (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US13/332,201 US9185089B2 (en) | 2011-12-20 | 2011-12-20 | System and method for key management for issuer security domain using global platform specifications |
US13/332,201 | 2011-12-20 | ||
PCT/US2012/058123 WO2013095747A1 (en) | 2011-12-20 | 2012-09-28 | System and method for key management for issuer security domain using global platform specifications |
Related Child Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
KR1020167008233A Division KR101712784B1 (ko) | 2011-12-20 | 2012-09-28 | 글로벌 플랫폼 규격을 사용하는 발행자 보안 도메인에 대한 키 관리 시스템 및 방법 |
Publications (2)
Publication Number | Publication Date |
---|---|
KR20140099325A KR20140099325A (ko) | 2014-08-11 |
KR101608510B1 true KR101608510B1 (ko) | 2016-04-01 |
Family
ID=48611465
Family Applications (2)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
KR1020147018590A Expired - Fee Related KR101608510B1 (ko) | 2011-12-20 | 2012-09-28 | 글로벌 플랫폼 규격을 사용하는 발행자 보안 도메인에 대한 키 관리 시스템 및 방법 |
KR1020167008233A Expired - Fee Related KR101712784B1 (ko) | 2011-12-20 | 2012-09-28 | 글로벌 플랫폼 규격을 사용하는 발행자 보안 도메인에 대한 키 관리 시스템 및 방법 |
Family Applications After (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
KR1020167008233A Expired - Fee Related KR101712784B1 (ko) | 2011-12-20 | 2012-09-28 | 글로벌 플랫폼 규격을 사용하는 발행자 보안 도메인에 대한 키 관리 시스템 및 방법 |
Country Status (10)
Country | Link |
---|---|
US (2) | US9185089B2 (ko) |
EP (1) | EP2795828A4 (ko) |
JP (2) | JP5969048B2 (ko) |
KR (2) | KR101608510B1 (ko) |
CN (2) | CN103988464B (ko) |
AU (1) | AU2012355943B2 (ko) |
BR (1) | BR112014012653B1 (ko) |
IN (1) | IN2014CN02668A (ko) |
MX (1) | MX2014004838A (ko) |
WO (1) | WO2013095747A1 (ko) |
Families Citing this family (82)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20120130838A1 (en) * | 2006-09-24 | 2012-05-24 | Rfcyber Corp. | Method and apparatus for personalizing secure elements in mobile devices |
US8989705B1 (en) | 2009-06-18 | 2015-03-24 | Sprint Communications Company L.P. | Secure placement of centralized media controller application in mobile access terminal |
US8412945B2 (en) | 2011-08-09 | 2013-04-02 | CloudPassage, Inc. | Systems and methods for implementing security in a cloud computing environment |
US9497224B2 (en) | 2011-08-09 | 2016-11-15 | CloudPassage, Inc. | Systems and methods for implementing computer security |
US20140031024A1 (en) * | 2012-02-05 | 2014-01-30 | Rfcyber Corporation | Method and system for providing controllable trusted service manager |
EP2632196A1 (en) * | 2012-02-24 | 2013-08-28 | Alcatel Lucent | Smart card initial personnalization |
US8712407B1 (en) | 2012-04-05 | 2014-04-29 | Sprint Communications Company L.P. | Multiple secure elements in mobile electronic device with near field communication capability |
US9027102B2 (en) | 2012-05-11 | 2015-05-05 | Sprint Communications Company L.P. | Web server bypass of backend process on near field communications and secure element chips |
US8862181B1 (en) | 2012-05-29 | 2014-10-14 | Sprint Communications Company L.P. | Electronic purchase transaction trust infrastructure |
US9282898B2 (en) | 2012-06-25 | 2016-03-15 | Sprint Communications Company L.P. | End-to-end trusted communications infrastructure |
US9066230B1 (en) | 2012-06-27 | 2015-06-23 | Sprint Communications Company L.P. | Trusted policy and charging enforcement function |
US8649770B1 (en) | 2012-07-02 | 2014-02-11 | Sprint Communications Company, L.P. | Extended trusted security zone radio modem |
US8667607B2 (en) | 2012-07-24 | 2014-03-04 | Sprint Communications Company L.P. | Trusted security zone access to peripheral devices |
US8863252B1 (en) * | 2012-07-25 | 2014-10-14 | Sprint Communications Company L.P. | Trusted access to third party applications systems and methods |
US9183412B2 (en) | 2012-08-10 | 2015-11-10 | Sprint Communications Company L.P. | Systems and methods for provisioning and using multiple trusted security zones on an electronic device |
US9215180B1 (en) | 2012-08-25 | 2015-12-15 | Sprint Communications Company L.P. | File retrieval in real-time brokering of digital content |
US9015068B1 (en) | 2012-08-25 | 2015-04-21 | Sprint Communications Company L.P. | Framework for real-time brokering of digital content delivery |
US8954588B1 (en) | 2012-08-25 | 2015-02-10 | Sprint Communications Company L.P. | Reservations in real-time brokering of digital content delivery |
US8752140B1 (en) | 2012-09-11 | 2014-06-10 | Sprint Communications Company L.P. | System and methods for trusted internet domain networking |
US8898769B2 (en) | 2012-11-16 | 2014-11-25 | At&T Intellectual Property I, Lp | Methods for provisioning universal integrated circuit cards |
FR2999319B1 (fr) * | 2012-12-10 | 2015-01-09 | Oberthur Technologies | Procede et systeme de gestion d'un element securise integre ese |
US9398448B2 (en) * | 2012-12-14 | 2016-07-19 | Intel Corporation | Enhanced wireless communication security |
US9161227B1 (en) | 2013-02-07 | 2015-10-13 | Sprint Communications Company L.P. | Trusted signaling in long term evolution (LTE) 4G wireless communication |
US9578664B1 (en) | 2013-02-07 | 2017-02-21 | Sprint Communications Company L.P. | Trusted signaling in 3GPP interfaces in a network function virtualization wireless communication system |
US9104840B1 (en) | 2013-03-05 | 2015-08-11 | Sprint Communications Company L.P. | Trusted security zone watermark |
US8881977B1 (en) | 2013-03-13 | 2014-11-11 | Sprint Communications Company L.P. | Point-of-sale and automated teller machine transactions using trusted mobile access device |
US9613208B1 (en) | 2013-03-13 | 2017-04-04 | Sprint Communications Company L.P. | Trusted security zone enhanced with trusted hardware drivers |
US9049013B2 (en) | 2013-03-14 | 2015-06-02 | Sprint Communications Company L.P. | Trusted security zone containers for the protection and confidentiality of trusted service manager data |
US9049186B1 (en) | 2013-03-14 | 2015-06-02 | Sprint Communications Company L.P. | Trusted security zone re-provisioning and re-use capability for refurbished mobile devices |
US9191388B1 (en) | 2013-03-15 | 2015-11-17 | Sprint Communications Company L.P. | Trusted security zone communication addressing on an electronic device |
US8984592B1 (en) | 2013-03-15 | 2015-03-17 | Sprint Communications Company L.P. | Enablement of a trusted security zone authentication for remote mobile device management systems and methods |
US9021585B1 (en) | 2013-03-15 | 2015-04-28 | Sprint Communications Company L.P. | JTAG fuse vulnerability determination and protection using a trusted execution environment |
US9374363B1 (en) | 2013-03-15 | 2016-06-21 | Sprint Communications Company L.P. | Restricting access of a portable communication device to confidential data or applications via a remote network based on event triggers generated by the portable communication device |
US9171243B1 (en) | 2013-04-04 | 2015-10-27 | Sprint Communications Company L.P. | System for managing a digest of biographical information stored in a radio frequency identity chip coupled to a mobile communication device |
US9454723B1 (en) | 2013-04-04 | 2016-09-27 | Sprint Communications Company L.P. | Radio frequency identity (RFID) chip electrically and communicatively coupled to motherboard of mobile communication device |
US9324016B1 (en) | 2013-04-04 | 2016-04-26 | Sprint Communications Company L.P. | Digest of biographical information for an electronic device with static and dynamic portions |
EP2984581B1 (en) | 2013-04-10 | 2018-03-07 | Illumio, Inc. | Distributed network management using a logical multi-dimensional label-based policy model |
US9838869B1 (en) | 2013-04-10 | 2017-12-05 | Sprint Communications Company L.P. | Delivering digital content to a mobile device via a digital rights clearing house |
US9882919B2 (en) | 2013-04-10 | 2018-01-30 | Illumio, Inc. | Distributed network security using a logical multi-dimensional label-based policy model |
US9443088B1 (en) | 2013-04-15 | 2016-09-13 | Sprint Communications Company L.P. | Protection for multimedia files pre-downloaded to a mobile device |
US9052891B2 (en) * | 2013-05-14 | 2015-06-09 | International Business Machines Corporation | Declarative configuration and execution of card content management operations for trusted service manager |
US9069952B1 (en) | 2013-05-20 | 2015-06-30 | Sprint Communications Company L.P. | Method for enabling hardware assisted operating system region for safe execution of untrusted code using trusted transitional memory |
US9560519B1 (en) | 2013-06-06 | 2017-01-31 | Sprint Communications Company L.P. | Mobile communication device profound identity brokering framework |
US9183606B1 (en) | 2013-07-10 | 2015-11-10 | Sprint Communications Company L.P. | Trusted processing location within a graphics processing unit |
US9208339B1 (en) | 2013-08-12 | 2015-12-08 | Sprint Communications Company L.P. | Verifying Applications in Virtual Environments Using a Trusted Security Zone |
US9036820B2 (en) | 2013-09-11 | 2015-05-19 | At&T Intellectual Property I, Lp | System and methods for UICC-based secure communication |
KR101769973B1 (ko) * | 2013-09-30 | 2017-08-21 | 구글 인코포레이티드 | 보안 요소 상의 데이터를 안전하게 관리하기 위한 시스템들, 방법들 및 비일시적 컴퓨터 판독가능 매체 |
US9124573B2 (en) | 2013-10-04 | 2015-09-01 | At&T Intellectual Property I, Lp | Apparatus and method for managing use of secure tokens |
US9208300B2 (en) | 2013-10-23 | 2015-12-08 | At&T Intellectual Property I, Lp | Apparatus and method for secure authentication of a communication device |
US9240994B2 (en) | 2013-10-28 | 2016-01-19 | At&T Intellectual Property I, Lp | Apparatus and method for securely managing the accessibility to content and applications |
US9185626B1 (en) | 2013-10-29 | 2015-11-10 | Sprint Communications Company L.P. | Secure peer-to-peer call forking facilitated by trusted 3rd party voice server provisioning |
US9313660B2 (en) | 2013-11-01 | 2016-04-12 | At&T Intellectual Property I, Lp | Apparatus and method for secure provisioning of a communication device |
US9240989B2 (en) | 2013-11-01 | 2016-01-19 | At&T Intellectual Property I, Lp | Apparatus and method for secure over the air programming of a communication device |
US9191522B1 (en) | 2013-11-08 | 2015-11-17 | Sprint Communications Company L.P. | Billing varied service based on tier |
US10700856B2 (en) * | 2013-11-19 | 2020-06-30 | Network-1 Technologies, Inc. | Key derivation for a module using an embedded universal integrated circuit card |
US9161325B1 (en) | 2013-11-20 | 2015-10-13 | Sprint Communications Company L.P. | Subscriber identity module virtualization |
US9118655B1 (en) | 2014-01-24 | 2015-08-25 | Sprint Communications Company L.P. | Trusted display and transmission of digital ticket documentation |
US9226145B1 (en) | 2014-03-28 | 2015-12-29 | Sprint Communications Company L.P. | Verification of mobile device integrity during activation |
US9713006B2 (en) * | 2014-05-01 | 2017-07-18 | At&T Intellectual Property I, Lp | Apparatus and method for managing security domains for a universal integrated circuit card |
US10929843B2 (en) * | 2014-05-06 | 2021-02-23 | Apple Inc. | Storage of credential service provider data in a security domain of a secure element |
US20150326545A1 (en) * | 2014-05-06 | 2015-11-12 | Apple Inc. | Secure key rotation for an issuer security domain of an electronic device |
US9230085B1 (en) | 2014-07-29 | 2016-01-05 | Sprint Communications Company L.P. | Network based temporary trust extension to a remote or mobile device enabled via specialized cloud services |
TW201633207A (zh) * | 2014-12-12 | 2016-09-16 | 納格維遜股份有限公司 | 裝置金鑰保護 |
US9779232B1 (en) | 2015-01-14 | 2017-10-03 | Sprint Communications Company L.P. | Trusted code generation and verification to prevent fraud from maleficent external devices that capture data |
US9838868B1 (en) | 2015-01-26 | 2017-12-05 | Sprint Communications Company L.P. | Mated universal serial bus (USB) wireless dongles configured with destination addresses |
US9473945B1 (en) | 2015-04-07 | 2016-10-18 | Sprint Communications Company L.P. | Infrastructure for secure short message transmission |
GB2538774A (en) * | 2015-05-28 | 2016-11-30 | Vodafone Ip Licensing Ltd | Setting a password on a device |
EP3110189A1 (en) * | 2015-06-25 | 2016-12-28 | Gemalto Sa | A method of replacing at least one authentication parameter for authenticating a security element and corresponding security element |
US9819679B1 (en) | 2015-09-14 | 2017-11-14 | Sprint Communications Company L.P. | Hardware assisted provenance proof of named data networking associated to device data, addresses, services, and servers |
US10282719B1 (en) | 2015-11-12 | 2019-05-07 | Sprint Communications Company L.P. | Secure and trusted device-based billing and charging process using privilege for network proxy authentication and audit |
US9817992B1 (en) | 2015-11-20 | 2017-11-14 | Sprint Communications Company Lp. | System and method for secure USIM wireless network access |
CN106888448B (zh) * | 2015-12-15 | 2020-08-04 | 中国移动通信集团公司 | 应用下载方法、安全元件及终端 |
EP3255597A1 (en) | 2016-06-12 | 2017-12-13 | Apple Inc. | Managing secure transactions between electronic devices and service providers |
KR101798059B1 (ko) * | 2016-12-21 | 2017-11-16 | 주식회사 한국스마트카드 | 동적가상카드의 생성 및 폐기 방법 |
US10693644B2 (en) * | 2017-06-23 | 2020-06-23 | International Business Machines Corporation | Single-input multifactor authentication |
US10499249B1 (en) | 2017-07-11 | 2019-12-03 | Sprint Communications Company L.P. | Data link layer trust signaling in communication network |
US11042609B2 (en) | 2017-08-03 | 2021-06-22 | Cable Television Laboratories, Inc. | Systems and methods for secure element registration and provisioning |
CN107767135B (zh) * | 2017-10-10 | 2020-10-02 | 易信(厦门)信用服务技术有限公司 | 一种基于互联网的智能工程交易征信系统 |
CN111062057B (zh) * | 2019-12-16 | 2022-06-14 | 英联(厦门)金融技术服务股份有限公司 | 一种中立的数据应用方法、装置以及系统 |
CN110969214B (zh) * | 2019-12-18 | 2023-06-23 | 天津大学 | 一种基于支持向量机综合模型的暂态安全域在线构建方法 |
EP4057659A1 (en) * | 2021-03-11 | 2022-09-14 | Thales DIS France SA | A method of replacing a current key in a security element and corresponding security element |
CN118012725B (zh) * | 2024-04-09 | 2024-07-09 | 西安热工研究院有限公司 | 一种可信管理平台告警管理方法、系统、设备及存储介质 |
Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20100088518A1 (en) | 2008-09-19 | 2010-04-08 | Oberthur Technologies | Method of exchanging data such as cryptographic keys between a data processing system and an electronic entity such as a microcircuit card |
Family Cites Families (27)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JPH11168460A (ja) * | 1997-10-01 | 1999-06-22 | Pumpkin House:Kk | 暗号ネットワーク・システムおよび方法 |
SE0104344D0 (sv) * | 2001-12-20 | 2001-12-20 | Au System Ab Publ | System och förfarande |
US20030182559A1 (en) * | 2002-03-22 | 2003-09-25 | Ian Curry | Secure communication apparatus and method for facilitating recipient and sender activity delegation |
JP2007517303A (ja) * | 2003-12-24 | 2007-06-28 | コーニンクレッカ フィリップス エレクトロニクス エヌ ヴィ | 認可証明書使用中のプライバシー保護 |
US7672460B2 (en) * | 2004-01-22 | 2010-03-02 | Nec Corporation | Mix-net system |
US7805611B1 (en) * | 2004-12-03 | 2010-09-28 | Oracle America, Inc. | Method for secure communication from chip card and system for performing the same |
US7628322B2 (en) | 2005-03-07 | 2009-12-08 | Nokia Corporation | Methods, system and mobile device capable of enabling credit card personalization using a wireless network |
US7699233B2 (en) * | 2005-11-02 | 2010-04-20 | Nokia Corporation | Method for issuer and chip specific diversification |
KR101143193B1 (ko) | 2005-11-25 | 2012-05-18 | 주식회사 엘지유플러스 | Ic 칩을 발급하는 방법 및 그 시스템 |
EP1999680A2 (en) | 2006-03-15 | 2008-12-10 | ActivIdentity, Inc. | Method and system for obtaining assurance that a content control key is securely stored in a remote security module for further secure communications between a content provider and said security module. |
CA2693371C (en) * | 2007-07-19 | 2013-12-10 | Telcordia Technologies, Inc. | Method for a public-key infrastructure providing communication integrity and anonymity while detecting malicious communication |
CN101370248B (zh) * | 2007-08-15 | 2011-12-07 | 中国移动通信集团公司 | 密钥更新方法、第三方服务器及激活第三方应用的系统 |
JP2009060528A (ja) * | 2007-09-03 | 2009-03-19 | Panasonic Corp | 鍵設定方法および鍵設定システム |
US8175276B2 (en) * | 2008-02-04 | 2012-05-08 | Freescale Semiconductor, Inc. | Encryption apparatus with diverse key retention schemes |
CN101729243B (zh) | 2008-10-21 | 2011-12-07 | 中兴通讯股份有限公司 | 密钥更新方法和系统 |
CN101729503B (zh) | 2008-10-23 | 2012-11-28 | 中兴通讯股份有限公司 | 密钥分发方法和系统 |
CN101729246B (zh) * | 2008-10-24 | 2012-02-08 | 中兴通讯股份有限公司 | 密钥分发方法和系统 |
CN101820613B (zh) * | 2009-02-27 | 2014-03-19 | 中兴通讯股份有限公司 | 一种应用下载的系统和方法 |
US8509448B2 (en) * | 2009-07-29 | 2013-08-13 | Motorola Solutions, Inc. | Methods and device for secure transfer of symmetric encryption keys |
US8630422B2 (en) * | 2009-11-10 | 2014-01-14 | International Business Machines Corporation | Fully homomorphic encryption method based on a bootstrappable encryption scheme, computer program and apparatus |
WO2011066152A1 (en) * | 2009-11-25 | 2011-06-03 | Aclara RF Systems Inc. | Cryptographically secure authentication device, system and method |
WO2011073734A1 (en) * | 2009-12-18 | 2011-06-23 | Nxp B.V. | Protected mode for global platform compliant smart cards |
EP2461613A1 (en) * | 2010-12-06 | 2012-06-06 | Gemalto SA | Methods and system for handling UICC data |
US8196131B1 (en) * | 2010-12-17 | 2012-06-05 | Google Inc. | Payment application lifecycle management in a contactless smart card |
US20120291095A1 (en) * | 2011-05-10 | 2012-11-15 | Tyfone, Inc. | Independent secure element management |
US9032497B2 (en) * | 2011-06-15 | 2015-05-12 | Cbs Interactive Inc. | System and method for securing embedded media |
US8639951B2 (en) * | 2011-12-19 | 2014-01-28 | International Business Machines Corporation | States for breakout appliance in a mobile data network |
-
2011
- 2011-12-20 US US13/332,201 patent/US9185089B2/en not_active Expired - Fee Related
-
2012
- 2012-09-28 KR KR1020147018590A patent/KR101608510B1/ko not_active Expired - Fee Related
- 2012-09-28 EP EP12859018.9A patent/EP2795828A4/en not_active Withdrawn
- 2012-09-28 KR KR1020167008233A patent/KR101712784B1/ko not_active Expired - Fee Related
- 2012-09-28 JP JP2014549034A patent/JP5969048B2/ja not_active Expired - Fee Related
- 2012-09-28 CN CN201280056904.5A patent/CN103988464B/zh active Active
- 2012-09-28 AU AU2012355943A patent/AU2012355943B2/en not_active Ceased
- 2012-09-28 MX MX2014004838A patent/MX2014004838A/es active IP Right Grant
- 2012-09-28 CN CN201710544377.7A patent/CN107220561A/zh active Pending
- 2012-09-28 BR BR112014012653-4A patent/BR112014012653B1/pt active IP Right Grant
- 2012-09-28 WO PCT/US2012/058123 patent/WO2013095747A1/en active Application Filing
-
2014
- 2014-04-08 IN IN2668CHN2014 patent/IN2014CN02668A/en unknown
-
2015
- 2015-09-30 US US14/872,024 patent/US9590963B2/en active Active
-
2016
- 2016-07-06 JP JP2016133919A patent/JP6692234B2/ja not_active Expired - Fee Related
Patent Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20100088518A1 (en) | 2008-09-19 | 2010-04-08 | Oberthur Technologies | Method of exchanging data such as cryptographic keys between a data processing system and an electronic entity such as a microcircuit card |
Also Published As
Publication number | Publication date |
---|---|
US9590963B2 (en) | 2017-03-07 |
IN2014CN02668A (ko) | 2015-07-03 |
JP2016181936A (ja) | 2016-10-13 |
US20130159710A1 (en) | 2013-06-20 |
AU2012355943B2 (en) | 2015-09-24 |
KR20160040322A (ko) | 2016-04-12 |
AU2012355943A1 (en) | 2014-05-01 |
JP2015506605A (ja) | 2015-03-02 |
BR112014012653A8 (pt) | 2017-06-20 |
JP5969048B2 (ja) | 2016-08-10 |
JP6692234B2 (ja) | 2020-05-13 |
EP2795828A1 (en) | 2014-10-29 |
CN103988464B (zh) | 2017-05-24 |
KR101712784B1 (ko) | 2017-03-06 |
CN107220561A (zh) | 2017-09-29 |
EP2795828A4 (en) | 2015-09-09 |
BR112014012653B1 (pt) | 2022-05-17 |
CN103988464A (zh) | 2014-08-13 |
WO2013095747A1 (en) | 2013-06-27 |
US9185089B2 (en) | 2015-11-10 |
KR20140099325A (ko) | 2014-08-11 |
MX2014004838A (es) | 2014-05-27 |
US20160028702A1 (en) | 2016-01-28 |
BR112014012653A2 (pt) | 2017-06-13 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
KR101608510B1 (ko) | 글로벌 플랫폼 규격을 사용하는 발행자 보안 도메인에 대한 키 관리 시스템 및 방법 | |
US9965653B2 (en) | Trusted computing | |
US11258591B2 (en) | Cryptographic key management based on identity information | |
JP5852265B2 (ja) | 計算装置、コンピュータプログラム及びアクセス許否判定方法 | |
US9760727B2 (en) | Secure host interactions | |
US9948668B2 (en) | Secure host communications | |
US9547773B2 (en) | Secure event log management | |
WO2013107362A1 (zh) | 一种保护数据的方法和系统 | |
CN110445840B (zh) | 一种基于区块链技术的文件存储和读取的方法 | |
JP6756056B2 (ja) | 身元検証による暗号チップ | |
CN114244565B (zh) | 密钥分发方法、装置、设备及存储介质 | |
CN117454361A (zh) | 一种密钥管理方法及相关设备 | |
CN116318981A (zh) | 颁发可验证声明的方法和用户设备 | |
Ju et al. | The Issue of Data Transfer for the Embedded SE on Mobile Devices |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
A201 | Request for examination | ||
PA0105 | International application |
Patent event date: 20140704 Patent event code: PA01051R01D Comment text: International Patent Application |
|
PA0201 | Request for examination |
Patent event code: PA02012R01D Patent event date: 20140704 Comment text: Request for Examination of Application |
|
PG1501 | Laying open of application | ||
E902 | Notification of reason for refusal | ||
PE0902 | Notice of grounds for rejection |
Comment text: Notification of reason for refusal Patent event date: 20150521 Patent event code: PE09021S01D |
|
E701 | Decision to grant or registration of patent right | ||
PE0701 | Decision of registration |
Patent event code: PE07011S01D Comment text: Decision to Grant Registration Patent event date: 20151224 |
|
GRNT | Written decision to grant | ||
PA0104 | Divisional application for international application |
Comment text: Divisional Application for International Patent Patent event code: PA01041R01D Patent event date: 20160328 |
|
PR0701 | Registration of establishment |
Comment text: Registration of Establishment Patent event date: 20160328 Patent event code: PR07011E01D |
|
PR1002 | Payment of registration fee |
Payment date: 20160329 End annual number: 3 Start annual number: 1 |
|
PG1601 | Publication of registration | ||
FPAY | Annual fee payment |
Payment date: 20190227 Year of fee payment: 4 |
|
PR1001 | Payment of annual fee |
Payment date: 20190227 Start annual number: 4 End annual number: 4 |
|
FPAY | Annual fee payment |
Payment date: 20200227 Year of fee payment: 5 |
|
PR1001 | Payment of annual fee |
Payment date: 20200227 Start annual number: 5 End annual number: 5 |
|
PR1001 | Payment of annual fee |
Payment date: 20210302 Start annual number: 6 End annual number: 6 |
|
PR1001 | Payment of annual fee |
Payment date: 20220216 Start annual number: 7 End annual number: 7 |
|
PC1903 | Unpaid annual fee |
Termination category: Default of registration fee Termination date: 20240108 |