IP Library Granted Patent US 11,153,752
Granted Patent B2
US 11,153,752 · App. 16/565,389 · Granted Oct 19, 2021

Apparatus and method for SSP device and server to negotiate digital certificates

Inventors: Kangjin Yoon (Suwon-si, KR); Duckey Lee (Suwon-si, KR); Hyewon Lee (Suwon-si, KR); Jonghoe Koo (Suwon-si, KR)
Assignee: Samsung Electronics Co., Ltd.
H04W12/0431H04L9/0844H04L9/3265H04L9/3268H04L63/166H04W12/06H04W28/18H04W72/10H04L67/42H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,752
App. No.
16/565,389
Granted
Oct 19, 2021
Kind
B2
Abstract

A method of a local bundle assistant (LBA) negotiating a certificate with a secondary platform bundle manager (SPBM) in a wireless communication system including: transmitting a request message requesting information of certificates supported by a secondary secure platform (SSP) to a secondary platform bundle loader (SPBL) of the SSP; receiving the information of certificates supported by the SSP including information of certificate issuers corresponding to a family identifier from the SPBL; transmitting the information of certificates supported by the SSP to the SPBM; and receiving a certificate of the SPBM for key agreement, information of public key identifiers of certificate issuers to be used by the SSP, and information of the family identifier from the SPBM.

Claims (54)

1. A method of a local bundle assistant (LBA) negotiating a certificate with a secondary platform bundle manager (SPBM) in a wireless communication system, the method comprising:

transmitting a request message requesting information of certificates supported by a secondary secure platform (SSP) to a secondary platform bundle loader (SPBL) of the SSP;

receiving the information of certificates supported by the SSP including information of certificate issuers corresponding to a family identifier from the SPBL;

transmitting the information of certificates supported by the SSP to the SPBM; and

receiving a certificate of the SPBM for key agreement, information of public key identifiers of certificate issuers to be used by the SSP, and information of the family identifier from the SPBM,

wherein, the information of certificate issuers corresponding to a family identifier includes information of public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBM and are verifiable by the SPBL, information of public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBL and are verifiable by the SPBM, and the information of the family identifier.

2. The method of claim 1 , wherein the request message further includes the information of the family identifier.

3. The method of claim 1 , wherein the information of certificates supported by the SSP further includes information of a release of a specification implemented by the SPBL.

4. The method of claim 1 , further comprising:

establishing a transport layer security (TLS) connection with the SPBM in a server authentication mode.

5. The method of claim 1 , wherein the certificate of the SPBM for key agreement, that is verifiable by a public key indicated by one of the public key identifiers included in the public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBM and are verifiable by the SPBL, is determined at the SPBM based on the information of certificates supported by the SSP.

6. The method of claim 1 , wherein:

one of public key identifiers included in the public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBL and are verifiable by the SPBM is determined at the SPBM based on the information of certificates supported by the SSP; and

the information of public key identifier of certificate issuers to be used at the SSP is set at the SPBM as the determined one of public key identifiers.

7. The method of claim 1 , further comprising:

receiving sub certificates of the certificate of the SPBM for key agreement from the SPBM.

8. A method of a secondary platform bundle manager (SPBM) negotiating a certificate with a local bundle assistant (LBA) in a wireless communication system, the method comprising:

receiving information of certificates supported by a secondary secure platform (SSP) including information of certificate issuers corresponding to a family identifier from the LBA; and

transmitting a certificate of the SPBM for key agreement, information of public key identifiers of certificate issuers to be used by the SSP, and information of the family identifier to the LBA,

wherein, the information of certificate issuers corresponding to a family identifier includes information of public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBM and are verifiable by a secondary platform bundle loader (SPBL), information of public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBL and are verifiable by the SPBM, and the information of the family identifier.

9. The method of claim 8 , wherein the information of certificates supported by the SSP further includes information of a release of a specification implemented by the SPBL.

10. The method of claim 8 , further comprising:

establishing a transport layer security (TLS) connection with the LBA in server authentication mode.

11. The method of claim 8 , further comprising:

determining the certificate of the SPBM for key agreement, that is verifiable by a public key indicated by one of the public key identifiers included in the public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBM and are verifiable by the SPBL, based on the information of certificates supported by the SSP.

12. The method of claim 8 , further comprising:

determining one of public key identifiers included in the public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBL and are verifiable by the SPBM based on the information of certificates supported by the SSP, and

setting the information of public key identifier of certificate issuers to be used at the SSP as the determined one of public key identifiers.

13. The method of claim 8 , further comprising:

transmitting sub certificates of the certificate of the SPBM for key agreement to the LBA.

14. A local bundle assistant (LBA) negotiating a certificate with a secondary platform bundle manager (SPBM) in a wireless communication system, the LBA comprising:

a transceiver; and

at least one controller coupled with the transceiver, the at least one controller configured to:

transmit a request message requesting information of certificates supported by a secondary secure platform (SSP) to a secondary platform bundle loader (SPBL) of the SSP;

receive the information of certificates supported by the SSP including information of certificate issuers corresponding to a family identifier from the SPBL;

transmit the information of certificates supported by the SSP to the SPBM; and

receive a certificate of the SPBM for key agreement, information of public key identifiers of certificate issuers to be used by the SSP, and information of the family identifier from the SPBM,

wherein, the information of certificate issuers corresponding to a family identifier includes information of public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBM and are verifiable by the SPBL, information of public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBL and are verifiable by the SPBM, and the information of the family identifier.

15. The LBA of claim 14 , wherein the request message further includes the information of the family identifier.

16. The LBA of claim 14 , wherein the certificate of the SPBM for key agreement, that is verifiable by a public key indicated by one of the public key identifiers included in the public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBM and are verifiable by the SPBL, is determined at the SPBM based on the information of certificates supported by the SSP.

17. The LBA of claim 14 , wherein:

one of public key identifiers included in the public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBL and are verifiable by the SPBM is determined at the SPBM based on the information of certificates supported by the SSP; and

the information of public key identifier of certificate issuers to be used at the SSP is set at the SPBM as the determined one of public key identifiers.

18. A secondary platform bundle manager (SPBM) negotiating a certificate with a local bundle assistant (LBA) in a wireless communication system, the SPBM comprising:

a transceiver; and

at least one controller coupled with the transceiver, the at least one controller configured to:

receive information of certificates supported by a secondary secure platform (SSP) including information of certificate issuers corresponding to a family identifier from the LBA; and

transmit a certificate of the SPBM for key agreement, information of public key identifiers of certificate issuers to be used by the SSP, and information of the family identifier to the LBA,

wherein, the information of certificate issuers corresponding to a family identifier includes information of public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBM and are verifiable by a secondary platform bundle loader (SPBL), information of public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBL and are verifiable by the SPBM, and the information of the family identifier.

19. The SPBM of claim 18 , wherein the at least one controller is configured to:

determine the certificate of the SPBM for key agreement, that is verifiable by a public key indicated by one of the public key identifiers included in the public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBM and are verifiable by the SPBL, based on the information of certificates supported by the SSP.

20. The SPBM of claim 18 , wherein the at least one controller is configured to:

determine one of public key identifiers included in the public key identifiers of certificate issuers that issued certificates included in a certificate chain of the SPBL and are verifiable by the SPBM based on the information of certificates supported by the SSP, and

set the information of public key identifier of certificate issuers to be used at the SSP as the determined one of public key identifiers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2019
From: YOON, KANGJIN; LEE, DUCKEY; LEE, HYEWON; KOO, JONGHOE
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 050321/0339 →
Priority Claims (1)
KR 10-2018-0107384 · Sep 7, 2018 · national
Continuity (1)
Related Publication 20200084622A1 · Mar 12, 2020
Cited By (1)
US 12,238,515