IP Library › Granted Patent US 12,278,915
Granted Patent B2
US 12,278,915 · App. 17/781,840 · Granted Apr 15, 2025

Provisioning method and terminal device

Inventors: Ye Tian (Beijing, CN); Xiaoming Ren (Beijing, CN)
Assignees: CHINA MOBILE COMMUNICATIONS CO., LTD RESEARCH INSTITUTE; CHINA MOBILE COMMUNICATIONS GROUP CO., LTD.
H04L9/3273H04W12/069
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,278,915
App. No.
17/781,840
Granted
Apr 15, 2025
Kind
B2
Abstract

The present disclosure provides a provisioning method and a terminal device. The provisioning method is applied to the terminal device, including: the security module establishes a secure channel with the certificate authority CA server through one or more session keys shared by the security module and the CA server; and obtains one or more digital certificates from the CA server; wherein, the security module is to implement Universal Subscriber Identity Module (USIM) functions.

Claims (41)

1. A provisioning method, applied to a terminal device, the method comprising:

establishing, by a security module, a secure channel with a Pseudonym Certificate Authority (PCA) server through one or more session keys shared by the security module and the PCA server;

signing, by the security module, one or more Pseudonym Certificate (PC) application messages with one or more private keys of one or more Enrollment Certificates (ECs); and

obtaining, by the security module, one or more PCs from the PCA server according to the one or more PC application messages;

wherein after obtaining the one or more PCs from the PCA sever, the method further comprises:

signing, by the security module, one or more messages transmitted directly on PC5 interface with one or more private keys of the one or more PCs; and

sending the signed one or more messages to other devices; and

wherein the security module is to implement Universal Subscriber Identity Module (USIM) functions.

2. The provisioning method of claim 1 , wherein obtaining the one or more PCs from the PCA server comprises:

receiving one or more feedback messages sent by the PCA server;

verifying one or more signatures of the received one or more feedback messages with one or more public keys of the PCA server; and

obtaining the one or more PCs.

3. The provisioning method of claim 1 , wherein obtaining the one or more PCs from the PCA sever comprises:

sending, by the security module, the one or more PCs to a Hardware Security Module (HSM); and

storing, by the HSM, the one or more PCs.

4. The provisioning method of claim 3 , wherein obtaining the one or more PCs from the PCA sever further comprises:

generating, by the HSM, one or more public and private key pairs for applying for the one or more PCs;

sending, by the HSM, the one or more public keys for applying for the one or more PCs to the security module; and

obtaining, by the security module, the one or more PCs from the PCA server with the one or more public keys.

5. A terminal device, comprising a transceiver and a processor; the processor is configured to control a security module to:

establish a secure channel with a Pseudonym Certificate Authority (PCA) server through one or more session keys shared by the security module and the PCA server;

sign one or more Pseudonym Certificate (PC) application messages with one or more private keys of one or more Enrollment Certificates (ECs); and

obtain one or more PCs from the PCA server according to the one or more PC application messages;

wherein after obtaining the one or more PCs from the PCA sever, the processor is further configured to control the security module to:

sign one or more messages transmitted directly on PC5 interface with one or more private keys of the one or more PCs; and

send the signed one or more messages to other devices; and

wherein the security module is to implement Universal Subscriber Identity Module (USIM) functions.

6. The terminal device of claim 5 , wherein in order to obtain the one or more PCs from the PCA server, the processor is configured to control the security module to:

receive one or more feedback messages sent by the PCA server;

verify a signature of the received one or more feedback messages with one or more public keys of the PCA server; and

obtain the one or more PCs.

7. The terminal device of claim 5 , wherein in order to obtain the one or more PCs from the PCA sever, the processor is further configured to:

control the security module to send the one or more PCs to a Hardware Security Module (HSM); and

control the HSM to store the one or more PCs.

8. The terminal device of claim 7 , wherein in order to obtain the one or more PCs from the PCA sever, the processor is further configured to:

control the HSM to generate one or more public and private key pairs for applying for the one or more PCs;

control the HSM to send the one or more public keys for applying for the one or more PCs to the security module; and

control the security module to obtain the one or more PCs from the PCA server with the one or more public keys.

9. The terminal device of claim 7 , wherein in order to obtain the one or more PCs from the PCA sever, the processor is further configured to control the security module to:

sign one or more messages transmitted directly on PC5 interface with the one or more private keys of the one or more PCs; and

send the signed one or more messages to other devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2022
From: TIAN, YE; REN, XIAOMING
To: CHINA MOBILE COMMUNICATION CO., LTD RESEARCH INSTITUTE; CHINA MOBILE COMMUNICATIONS GROUP CO., LTD.
Reel/Frame 060613/0309 →
Priority Claims (1)
CN 201911219000.X · Dec 3, 2019 · national
Continuity (1)
Related Publication 20230007480A1 · Jan 5, 2023
References Cited (37)
US 9124573B2 · Chastain · 2015 [cited by examiner]
US 10122534B2 · Chastain · 2018 [cited by examiner]
US 12101630B2 · Yang · 2024 [cited by examiner]
US 20090044007A1 · Ferrazzini · 2009 [cited by examiner]
US 20090209232A1 · Cha · 2009 [cited by examiner]
US 20120100832A1 · Mao · 2012 [cited by applicant]
US 20150095648A1 · Nix · 2015 [cited by applicant]
US 20160021529A1 · Park · 2016 [cited by examiner]
US 20160149710A1 · Huxham et al. · 2016 [cited by applicant]
US 20160234177A1 · Bone · 2016 [cited by examiner]
US 20170142121A1 · Lee · 2017 [cited by examiner]
US 20180351945A1 · Li et al. · 2018 [cited by applicant]
US 20190156019A1 · Chen · 2019 [cited by applicant]
US 20190200228A1 · Adrangi et al. · 2019 [cited by applicant]
US 20200084622A1 · Yoon · 2020 [cited by examiner]
US 20200162247A1 · Nix · 2020 [cited by examiner]
US 20200413249A1 · Ramisetty · 2020 [cited by examiner]
CA 2986223C · 2019 [cited by examiner]
CN 101163013A · 2008 [cited by applicant]
CN 102811224A · 2012 [cited by examiner]
CN 106453196A · 2017 [cited by applicant]
CN 107645471A · 2018 [cited by examiner]
CN 108282467A · 2018 [cited by examiner]
CN 108809637A · 2018 [cited by applicant]
EP 3541106A1 · 2019 [cited by examiner]
JP 2019149714A · 2019 [cited by applicant]
WO WO2009046400A1 · 2009 [cited by examiner]
WO WO2017192161A1 · 2017 [cited by examiner]
Ning, Hong-zhou (CN 107645471 A), A Method And System For Mobile Terminal User Identity Authentication, pub: Jan. 30, 2018, (Year: 2018), All pages. [cited by examiner]
International Search Report in the international application No. PCT/CN2020/132712, mailed on Feb. 10, 2021, 2 pgs. [cited by applicant]
English translation of the Written Opinion of the International Search Authority in the international application No. PCT/CN2020/132712, mailed on Feb. 10, 2021, 3 pgs. [cited by applicant]
“Deliverable D4.2 Final Design and Evaluation of the 5G V2X System Level Architecture and Security Framework”, Nov. 2019, Jesús Alonso et al., Version v1.1, Fifth Generation Communication Automotive Research and Innovat… [cited by applicant]
“A Security Credential Management System for V2V Communications”, Dec. 2013, William Whyte, Andre Weimerskirch, Virendra Kumar and Thorsten Hehn, 2013 IEEE Vehicular Networking Conference, 8 pages. [cited by applicant]
“Secure Vehicular Communication Systems: Design and Architecture”, Nov. 2008, Panagiotis Papadimitratos, Levente Butty, Tamas Holczer, Elmar Schoch, Julien Freudiger, Maxim Raya, Zhendong Ma, Frand Kargl, Antionio Kung … [cited by applicant]
“Study on Security Aspects for LTE Support of Vehicle-to-Eveything (V2X) Services”, Sep. 2017, 3GPP TR 33.885 V14.1.0; 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 75 pa… [cited by applicant]
“Generic Bootstrapping Architecture”; Sep. 2019; 3GPP TS 33.220 V16/0/0; 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Generic Authentication Architecture(GAA); 93 pages. [cited by applicant]
Supplementary European Search Report in the European application No. 20895692.0, mailed on Nov. 8, 2023, 10 pages. [cited by applicant]
Cited By (1)
US 12,598,064