IP Library › Granted Patent US 12,490,093
Granted Patent B2
US 12,490,093 · App. 18/551,861 · Granted Dec 2, 2025

Configuration method and apparatus for terminal device, and communication device

Inventors: Ye Tian (Beijing, CN); Li Su (Beijing, CN); Shen He (Beijing, CN); Haitao Du (Beijing, CN); Jie Ma (Beijing, CN); Wenshu Jiang (Beijing, CN)
Assignees: CHINA MOBILE COMMUNICATION CO., LTD RESEARCH INSTITUTE; CHINA MOBILE COMMUNICATIONS GROUP CO., LTD.
H04W12/069H04W12/03H04W12/041H04W12/106H04W12/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,490,093
App. No.
18/551,861
Granted
Dec 2, 2025
Kind
B2
Abstract

A configuration method includes: the terminal device generating a second key on the basis of a first key, and performing encryption and/or integrity protection on a certificate request message on the basis of the second key; and sending a first request message, the first request message comprising the certificate request message encrypted and/or integrity-protected via the second key.

Claims (41)

1 . A method for configuring a terminal device, comprising:

generating, by a Universal Subscriber Identity Module (USIM) of the terminal device, at least one first key, wherein the at least one first key is generated by the USIM through negotiation with a Bootstrapping Server Function (BSF);

generating, by the USIM of the terminal device, at least one second key based on at least one first key, and performing, by the USIM of the terminal device, at least encryption or integrity protection on at least one certificate request message based on the at least one second key;

transmitting, by the USIM of the terminal device to a client of the terminal device, at least one message which comprises the at least one certificate request message at least encrypted or integrity-protected by the at least one second key; and

transmitting, by the client of the terminal device to a server, at least one first request message which comprises the at least one certificate request message at least encrypted or integrity-protected by the at least one second key, and comprises a Bootstrapping-Transaction Identifier (B-TID) and a Fully Qualified Domain Name (FQDN) of the server.

2 . The method of claim 1 , further comprising:

receiving, by the terminal device, at least one first response message from a server, and performing, by the terminal device, at least integrity verification or decryption on the at least one first response message based on the at least one second key, and

obtaining, by the terminal device, at least one digital certificate carried in the at least one first response message.

3 . The method of claim 2 , wherein the terminal device comprises a modem,

receiving, by the terminal device, the at least one first response message from the server, and performing, by the terminal device, at least integrity verification or decryption on the at least one first response message based on the at least one second key, and obtaining, by the terminal device, the at least one digital certificate carried in the at least one first response message comprises:

receiving, by the client, the at least one first response message from the server, and transmitting, by the client, the at least one first response message to the USIM through the modem;

performing, by the USIM, at least integrity verification or decryption on the at least one first response message based on the at least one second key; and

obtaining, by the USIM, the at least one digital certificate carried in the at least one first response message after the verification is passed, and storing, by the USIM, the at least one digital certificate in a security component.

4 . The method of claim 1 , wherein the terminal device comprises a modem,

generating, by the USIM of the terminal device, the at least one second key based on the at least one first key, and performing, by the USIM of the terminal device, at least encryption or integrity protection on the at least one certificate request message based on the at least one second key comprises:

triggering, by the client, the USIM through the modem, to generate the at least one second key based on the at least one first key;

generating, by the client, at least one first certificate request message, and transmitting, by the client, the at least one first certificate request message to the USIM through the modem;

generating, by the USIM, a public/private key pair, and adding, by the USIM, the public key in the public/private key pair to the at least one first certificate request message, and signing, by the USIM, the at least one first certificate request message with the private key in the public/private key pair, to obtain at least one second certificate request message;

performing, by the USIM, at least encryption or integrity protection on the at least one second certificate request message based on the at least one second key, and performing, by the USIM, the at least encryption or integrity protection including: adding, by the USIM, a first verification value to the at least one second certificate request message; and

transmitting, by the USIM, the processed at least one second certificate request message to the client through the modem.

5 . The method of claim 1 , further comprising:

performing, by the terminal device, a Generic Bootstrapping Architecture (GBA) authentication process or an Authentication and Key Management for Applications (AKMA) authentication process.

6 . A terminal device, comprising a memory, a processor, and a computer program stored on the memory and executable by the processor, the processor is configured to implement steps of the method of claim 1 when the processor executes the computer program.

7 . The terminal device of claim 6 , wherein the processor, when executing the computer program, is further configured to:

receive at least one first response message from a server, and perform at least integrity verification or decryption on the at least one first response message based on the at least one second key, and obtain at least one digital certificate carried in the at least one first response message.

8 . A method for configuring a terminal device, comprising:

receiving, by a server, at least one first request message, which comprises at least one certificate request message at least encrypted or integrity-protected by at least one second key, and comprises a Bootstrapping-Transaction Identifier (B-TID) and a Fully Qualified Domain Name (FQDN) of the server, from the terminal device;

obtaining, by the server, the at least one second key from a network device, comprising: transmitting, by the server, at least one second request message to the network device, the at least one second request message being configured to request the at least one second key and comprising the B-TID and the FQDN; and receiving, by the server, at least one second response message transmitted by the network device, the at least one second response message comprising the at least one second key; and

performing, by the server, at least integrity verification or decryption on the at least one first request message based on the at least one second key, and

wherein in a case that the server receives the at least one first request message, the method further comprises:

issuing, by the server, at least one digital certificate after authorization of the at least one first request message is passed; and

transmitting, by the server, at least one first response message to the terminal device, the at least one first response message comprising the at least one digital certificate.

9 . The method of claim 8 , wherein transmitting, by the server, the at least one first response message to the terminal device comprises:

constructing, by the server, the at least one first response message containing the at least one digital certificate, and performing, by the server, at least encryption or integrity protection on the at least one first response message based on the at least one second key, and performing, by the server, the at least encryption or integrity protection including: adding, by the server, a second verification value to the at least one first response message; and

transmitting, by the server, the processed at least one first response message to the terminal device.

10 . The method of claim 8 , wherein the at least one first request message comprises B-TID,

obtaining, by the server, the at least one second key from the network device comprises:

querying, by the server, whether there is at least one second key corresponding to the B-TID; and

obtaining, by the server, the at least one second key from the network device, in response to the querying result indicating that there is no second key corresponding to the B-TID.

11 . A server, comprising a memory, a processor, and a computer program stored on the memory and executable by the processor, the processor is configured to implement steps of the method of claim 8 when the processor executes the computer program.

12 . The server of claim 11 , wherein in transmitting the at least one first response message to the terminal device, the processor, when executing the computer program, is configured to: construct the at least one first response message containing the at least one digital certificate, and performing, by the server, at least encryption or integrity protection on the at least one first response message based on the at least one second key, and adding, by the server, a second verification value to the at least one first response message; and transmit the processed at least one first response message to the terminal device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2023
From: TIAN, YE; SU, LI; HE, SHEN; DU, HAITAO; MA, JIE; JIANG, WENSHU
To: CHINA MOBILE COMMUNICATION CO., LTD RESEARCH INSTITUTE; CHINA MOBILE COMMUNICATIONS GROUP CO., LTD.
Reel/Frame 064990/0512 →
Priority Claims (2)
CN 202110304444.4 · Mar 22, 2021 · national
CN 202111217636.8 · Oct 19, 2021 · national
Continuity (1)
Related Publication 20240179523A1 · May 30, 2024
References Cited (27)
US 20150095648A1 · Nix · 2015 [cited by applicant]
US 20160094542A1 · Lee · 2016 [cited by applicant]
US 20180295125A1 · Lee · 2018 [cited by applicant]
CN 101808286A · 2010 [cited by applicant]
CN 102202306A · 2011 [cited by applicant]
CN 106797564A · 2017 [cited by applicant]
CN 106888449A · 2017 [cited by applicant]
CN 108667781A · 2018 [cited by applicant]
CN 110958229A · 2020 [cited by applicant]
CN 111050322A · 2020 [cited by applicant]
CN 111404670A · 2020 [cited by applicant]
CN 112449323A · 2021 [cited by applicant]
JP 2018093375A · 2018 [cited by applicant]
JP 2019149714A · 2019 [cited by applicant]
WO 2009053818A2 · 2009 [cited by applicant]
WO 2012031433A1 · 2012 [cited by applicant]
WO 2015144042A1 · 2015 [cited by applicant]
WO 2017091959A1 · 2017 [cited by applicant]
WO 2020199134A1 · 2020 [cited by applicant]
WO 2020249861A1 · 2020 [cited by applicant]
John A. MacDonald et al, “Overcoming Channel Bandwidth Constraints in Secure SIM Applications”, Security and Privacy in the Age of Ubiquitous Computing, Jun. 2005, pp. 539-549. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Generic Authentication Architecture (GAA); Generic Bootstrapping Architecture (GBA) (Release 18)”, 3GPP TS 33.220 V18.3.0 (… [cited by applicant]
International Search Report in the international application No. PCT/CN2022/082192, mailed on May 26, 2022. 5 pages with English translation. [cited by applicant]
Written Opinion of the International Search Authority in the international application No. PCT/CN2022/082192, mailed on May 26, 2022. 6 pages with English translation. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Radio Access Network; NR; NR and NG-RAN Overall Description; Stage 2 (Release 16)”, 3GPP Standard; Technical Specification; 3GPP TS 38.300, 3rd Generati… [cited by applicant]
“3GPP; Technical Specification Group Services and System Aspects; Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in the 5G System (5Gs) (Release 17)”, 3GPP Standard; Technical Specif… [cited by applicant]
Supplementary European Search Report in the European application No. 22774225.1, mailed on Jun. 11, 2024, 17 pages. [cited by applicant]