Method and apparatus for remote management and verification of remote management rights
By implementing remote management and permission verification methods and equipment in the terminal of the wireless communication system, the problem of difficult to achieve efficient and secure remote management and permission verification in the prior art is solved, and effective verification and management of remote management commands and security service modules are realized.
Patent Information
- Application Number
- CN202510380096.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2020-07-14
- Filing Date
- 2021-02-24
- Publication Date
- 2025-05-30
AI Technical Summary
It is difficult to implement efficient and secure solutions for remote management and remote management permission verification, especially in wireless communication systems.
By implementing a method and device in the terminal, it is possible to remotely manage the security service module installed in the terminal and verify the validity of the selected certificate and remote management commands. The method includes including a first entity and a second entity in the terminal, the first entity receives a remote bundling management command and verifys a bundling policy, and the second entity executes a remote bundling management command and verifys its validity.
It realizes efficient and secure management of remote management and permission verification in wireless communication systems, ensuring the effectiveness of remote management commands and the legality of security service modules.
Smart Images

Figure CN120075794A_ABST
Abstract
Description
[0001] This application is a divisional application of the patent application for invention with the application date of February 24, 2021, the application number of 202180017152.0, and the invention title of "Method and device for remote management and verification of remote management permissions". Technical Field
[0002] The present disclosure relates to a method and device for remote management and verification of remote management permissions, and more particularly, to a method and device for a terminal to select certificate issuer information and a valid certificate or identifier of a server capable of remotely managing a security service installed in the terminal, and verify the validity of the selected certificate and the validity of a remote management command. Background Art
[0003] In order to meet the increasing demand for wireless data traffic since the deployment of 4G communication systems, efforts have been made to develop improved 5G or pre-5G communication systems. Therefore, 5G or pre-5G communication systems are also referred to as "ultra 4G networks" or "post-LTE systems". Consider implementing 5G communication systems in higher frequency (mmWave) bands (e.g., 60 GHz band) in order to achieve higher data rates. In order to reduce the propagation loss of radio waves and increase the transmission distance, beamforming, massive multiple-input multiple-output (MIMO), full-dimensional MIMO (FD-MIMO), array antennas, analog beamforming, and massive antenna technology are discussed in 5G communication systems. In addition, in 5G communication systems, system network improvement development is being carried out based on advanced small cells, cloud radio access network (RAN), ultra-dense networks, device-to-device (D2D) communication, wireless backhaul, mobile networks, cooperative communication, coordinated multi-points (CoMP), receiver interference cancellation, etc. In 5G systems, hybrid FSK and QAM modulation (FQAM) and sliding window superposition coding (SWSC) as advanced coding modulation (ACM), and filter bank multi-carrier (FBMC), non-orthogonal multiple access (NOMA), and sparse code multiple access (SCMA) as advanced access technologies have also been developed.
[0004] The Internet, as a human - centered connection network in which humans generate and consume information, is now evolving into the Internet of Things (IoT), where distributed entities such as things exchange and process information without human intervention. The Internet of Everything (IoE), which is a combination of IoT technology and big data processing technology through connection with cloud servers, has emerged. Since IoT implementation requires technical elements such as "sensing technology", "wired / wireless communication and network infrastructure", "service interface technology", and "security technology", sensor networks, Machine - to - Machine (M2M) communication, Machine Type Communication (MTC), etc. have been studied recently. Such an IoT environment can provide intelligent Internet technology services that create new value for human life by collecting and analyzing data generated among connected things. IoT can be applied to various fields through the integration and combination of existing Information Technology (IT) and various industrial applications, including smart homes, smart buildings, smart cities, smart cars or connected vehicles, smart grids, healthcare, smart appliances, and advanced medical services.
[0005] In line with this, various attempts have been made to apply 5G communication systems to IoT networks. For example, technologies such as sensor networks, Machine Type Communication (MTC), and Machine - to - Machine (M2M) communication can be implemented through beamforming, MIMO, and array antennas. The application of cloud Radio Access Network (RAN) as the above - mentioned big data processing technology can also be considered an example of the integration of 5G technology and IoT technology.
[0006] Various services can be provided according to the above - mentioned development of mobile communication systems, so a method for efficiently providing these services is needed. More specifically, a method and device are needed in which a terminal selects an identifier of a server that can remotely manage security services installed in the terminal, or valid certificates and certificate issuer information that can be used when downloading and installing a bundle between the terminal and the server, and verifies the validity of the selected certificate.
[0007] The above information is presented only as background information to help understand the present disclosure. As to whether any of the above content can be used as prior art with respect to the present disclosure, no determination has been made and no assertion is made. Summary of the Invention
[0008] Technical Problem
[0009] The disclosed embodiments may provide an apparatus and method in which a security service module can be remotely installed in a security module installed in an electronic device, a security service can be provided via the security service module and security information stored in the security module, and the installed security service module is remotely controlled.
[0010] In addition, the disclosed embodiments may provide an apparatus and method for selecting and verifying a certificate between a terminal and a bundling management server, the certificate being used for remote management of a bundle classified as a different bundling family identifier, a bundling family identifier and a bundling family manager identifier, or a bundling family identifier, a bundling family manager identifier, and a bundling owner identifier.
[0011] Solution to the problem
[0012] According to an aspect of the present disclosure, a method performed by a first entity included in a terminal in a wireless communication system, the method comprising: receiving a remote bundling management command from a server; verifying a first bundling policy based on information included in the remote bundling management command and a bundling policy stored in the terminal; sending the remote bundling management command to a second entity included in the terminal; and receiving an execution result of the remote bundling management command from the second entity, wherein a second bundling policy is verified by the second entity based on information included in the remote bundling management command and a bundling policy stored in the terminal, and wherein the remote bundling management command is executed by the terminal based on verification results of the first bundling policy and the second bundling policy.
[0013] In some examples, the information included in the remote bundling management command includes at least one of a bundling identifier, a bundling family identifier of the bundle, a bundling family manager identifier of the bundle, a bundling owner identifier of the bundle, and a remote management command type.
[0014] In some examples, the bundling policy stored in the terminal includes at least one of end user consent and bundling management server verification.
[0015] In some examples, verifying the first bundling policy includes verifying user consent.
[0016] In some examples, verification of the second bundling policy includes verifying the bundling management server.
[0017] According to another aspect of the present disclosure, a method performed by a second entity included in a terminal in a wireless communication system, the method comprising:
[0018] Receive a remote bundling management command from a first entity included in a terminal; verify a second bundling strategy based on information included in the remote bundling management command and a bundling strategy stored in the terminal; and send an execution result of the remote bundling management command to the first entity, where the remote bundling management command is sent from a server to the first entity, where a first bundling strategy is verified by the first entity based on information included in the remote bundling management command and a bundling strategy stored in the terminal, and where the remote bundling management command is executed by the terminal based on verification results of the first bundling strategy and the second bundling strategy.
[0019] According to another aspect of the present disclosure, a first entity included in a terminal, the first entity comprising: a transceiver capable of sending or receiving at least one signal; and a controller coupled to the transceiver, where the controller is configured to: receive a remote bundling management command from a server, verify a first bundling strategy based on information included in the remote bundling management command and a bundling strategy stored in the terminal, send the remote bundling management command to a second entity included in the terminal, and receive an execution result of the remote bundling management command from the second entity, where a second bundling strategy is verified by the second entity based on information included in the remote bundling management command and a bundling strategy stored in the terminal, and where the remote bundling management command is executed by the terminal based on verification results of the first bundling strategy and the second bundling strategy.
[0020] According to another aspect of the present disclosure, a second entity included in a terminal, the second entity comprising: a transceiver capable of sending or receiving at least one signal; and a controller coupled to the transceiver, where the controller is configured to: receive a remote bundling management command from a first entity included in the terminal, verify a second bundling strategy based on information included in the remote bundling management command and a bundling strategy stored in the terminal, and send an execution result of the remote bundling management command to the first entity, where the remote bundling management command is sent from a server to the first entity, where a first bundling strategy is verified by the first entity based on information included in the remote bundling management command and a bundling strategy stored in the terminal, and where the remote bundling management command is executed by the terminal based on verification results of the first bundling strategy and the second bundling strategy.
[0021] According to some embodiments of the present disclosure, a method for a terminal to manage and verify a remote management certificate may include: receiving, from a security service module management server, a remote management instruction packet for remotely controlling a specific security service module and a remote security service module management certificate of the security service module management server; obtaining certificate information configured for the security module, where the certificate information may be used when remotely managing a security service module corresponding to at least one identifier among a security service module owner identifier, a security service module family manager identifier, and a security service module family identifier of the specific security service module; and verifying the remote security service module management certificate of the bundling management server and the remote management instruction packet by using the obtained certificate information.
[0022] A terminal according to some embodiments of the present disclosure may include a transceiver and at least one processor, where the at least one processor is configured to perform control to: obtain remote security service module management certificate information, where the remote security service module management certificate information may be used when remotely managing a specific security service module corresponding to at least one identifier among a security service module family identifier and a security service module family manager identifier; and receive, from a bundling management server, a remote management instruction packet for remotely controlling the security service module and a remote security service module management certificate of the security service module management server.
[0023] According to some embodiments of the present disclosure, one or more processors may perform control to: verify, based on the certificate information configured for the security module, a remote management instruction packet for remotely controlling the security service module and a remote security service module management certificate of the security service module management server, where the certificate information may be used when remotely managing a security service module corresponding to at least one identifier among a security service module owner identifier, a security service module family manager identifier, and a security service module family identifier of the security service module pre-configured for the security module; and remotely manage the security service module.
[0024] According to another aspect of the present disclosure, a method performed by a local bundling assistant (LBA) included in a terminal in a wireless communication system includes: receiving a remote bundling management command from a server; verifying a first bundling policy based on the remote bundling management command; sending the remote bundling management command to a secondary platform bundling loader (SPBL) included in the terminal; and receiving an execution result of the remote bundling management command from the SPBL, where a second bundling policy is verified by the SPBL based on the remote bundling management command, and where, after the first bundling policy and the second bundling policy are verified, the remote bundling management command is executed by the terminal.
[0025] According to another aspect of the present disclosure, a method executed by a Secondary Platform Boot Loader (SPBL) included in a terminal in a wireless communication system, the method comprising: receiving a remote bundling management command from a Local Bundling Assistant (LBA) included in the terminal; verifying a second bundling policy based on the remote bundling management command; and sending an execution result of the remote bundling management command to the LBA, wherein the remote bundling management command is sent from a server to the LBA, wherein a first bundling policy is verified by the LBA based on the remote bundling management command, and wherein after the first bundling policy and the second bundling policy are verified, the remote bundling management command is executed by the terminal.
[0026] According to another aspect of the present disclosure, a Local Bundling Assistant (LBA) included in a terminal, the LBA comprising: a transceiver capable of sending or receiving at least one signal, and a controller coupled to the transceiver, wherein the controller is configured to: receive a remote bundling management command from a server, verify a first bundling policy based on the remote bundling management command, send the remote bundling management command to a Secondary Platform Boot Loader (SPBL) included in the terminal, and receive an execution result of the remote bundling management command from the SPBL, wherein a second bundling policy is verified by the SPBL based on the remote bundling management command, and wherein after the first bundling policy and the second bundling policy are verified, the remote bundling management command is executed by the terminal.
[0027] According to another aspect of the present disclosure, a Secondary Platform Boot Loader (SPBL) included in a terminal, the SPBL comprising: a transceiver capable of sending or receiving at least one signal, and a controller coupled to the transceiver, wherein the controller is configured to: receive a remote bundling management command from a Local Bundling Assistant (LBA) included in the terminal, verify a second bundling policy based on the remote bundling management command, and send an execution result of the remote bundling management command to the LBA, wherein the remote bundling management command is sent from a server to the LBA, wherein a first bundling policy is verified by the LBA based on the remote bundling management command, and wherein after the first bundling policy and the second bundling policy are verified, the remote bundling management command is executed by the terminal.
[0028] The technical subject matter pursued by the present disclosure may not be limited to the above technical subject matter, and through the following description, those skilled in the art to which the present disclosure pertains can clearly understand other technical subject matters not mentioned.
[0029] Before proceeding with the following detailed description, it may be advantageous to set forth definitions of certain words and phrases used throughout this patent document: The terms "include" and "comprise," and derivatives thereof, mean inclusion without limitation; the term "or" is inclusive, meaning and / or; the phrases "associated with" and "associated therewith," and derivatives thereof, may mean to include, be included within, interconnect with, contain, be contained within, connect or be connected to, couple or be coupled to, be communicable with, cooperate with, interleave, juxtapose, be proximate to, be bound to or bound with, have, be characterized by, etc.; and the term "controller" means any device, system, or part thereof that controls at least one operation, such a device may be implemented in hardware, firmware, software, or some combination of at least two of them. It should be noted that the functions associated with any particular controller may be centralized or distributed, whether locally or remotely.
[0030] In addition, the various functions described below may be implemented or supported by one or more computer programs, each of which is formed of computer-readable program code and embodied in a computer-readable medium. The terms "application" and "program" refer to one or more computer programs, software components, sets of instructions, procedures, functions, objects, classes, instances, related data, or a portion thereof that are adapted to be implemented in appropriate computer-readable program code. The phrase "computer-readable program code" includes any type of computer code, including source code, object code, and executable code. The phrase "computer-readable medium" includes any type of medium that can be accessed by a computer, such as read-only memory (ROM), random access memory (RAM), hard disk drive, compact disc (CD), digital video disc (DVD), or any other type of memory. A "non-transitory" computer-readable medium does not include wired, wireless, optical, or other communication links that transmit transitory electrical or other signals. Non-transitory computer-readable media include media in which data can be permanently stored and media in which data can be stored and then overwritten, such as rewritable compact discs or erasable memory devices.
[0031] Definitions of certain words and phrases are provided throughout this patent document, and those of ordinary skill in the art should understand that, in many if not most instances, such definitions apply to both the prior and future use of such defined words and phrases.
[0032] Advantages of the Invention
[0033] According to various embodiments, the terminal can verify and execute remote bundle management commands. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] To more fully understand the present disclosure and its advantages, reference is now made to the following description taken in conjunction with the accompanying drawings, in which like reference numerals represent like parts:
[0035] Figure 1 A diagram showing a method for a terminal to perform mobile communication network connection using an intelligent security platform (SSP) equipped with a telecommunications bundle including a profile according to some embodiments;
[0036] Figure 2 A conceptual diagram showing the internal structure of an SSP according to some embodiments;
[0037] Figure 3 A diagram showing an example of a hierarchy of certificates (certificate hierarchy or certificate chain) issued by a certificate issuer (CI), public keys included in each certificate, and a digital signature configuration of the certificate issuer (CI) according to some embodiments;
[0038] Figure 4 A diagram showing an example of a hierarchy of certificates (certificate hierarchy or certificate chain) issued by a certificate issuer (CI), public keys included in each certificate, and a digital signature configuration of the certificate issuer (CI) according to some embodiments;
[0039] Figure 5 A diagram showing examples of internal and external elements of a terminal for allowing the terminal to download and install a bundle via an SSP according to some embodiments;
[0040] Figure 6 A diagram showing an example of a process in which a subscriber subscribes to a service via a service provider and the service provider and the bundle management server prepare to download the bundle according to some embodiments;
[0041] Figure 7 A diagram showing an example of the configuration of a terminal and a method for the service provider, the bundle management server, and the device manager to interoperate according to some embodiments;
[0042] Figure 8 A diagram showing an example of a general process for a terminal to perform remote bundle management according to some embodiments;
[0043] Figure 9 A diagram showing an example of a general process for a terminal to perform remote bundle management according to some embodiments;
[0044] Figure 10 A diagram showing an example of configuring a bundle policy according to some embodiments;
[0045] Figure 11 A diagram showing an example of configuring SSP remote management for remote bundle management according to some embodiments;
[0046] Figure 12 A diagram showing an example of a process for configuring SSP remote management permissions among a device manager, a service provider, and a bundle management server, and between the device manager and an SSP;
[0047] Figure 13 A diagram showing an example of a process for generating a remote bundle management command by a bundle management server according to some embodiments;
[0048] Figure 14 A diagram showing an example of a process for a terminal to verify and execute a remote bundle management command received from a bundle management server according to some embodiments;
[0049] Figure 15 A diagram showing the configuration of a terminal according to some embodiments; and
[0050] Figure 16 A diagram showing the configuration of a bundle management server according to some embodiments. Detailed Description of Embodiments
[0051] The following discussion Figures 1 to 16 and the various embodiments for describing the principles of the present disclosure in this patent document are for illustration only and should not be construed as limiting the scope of the present disclosure in any way. Those skilled in the art will understand that the principles of the present disclosure can be implemented in any appropriately arranged system or device.
[0052] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings.
[0053] When describing the embodiments of the present disclosure, descriptions related to well-known technical content in the art and not directly related to the present disclosure will be omitted. Omitting such unnecessary descriptions is intended to prevent obscuring the main idea of the present disclosure and to more clearly convey the main idea.
[0054] For the same reason, in the drawings, some elements may be exaggerated, omitted, or shown schematically. In addition, the size of each element does not fully reflect the actual size. In the drawings, the same or corresponding elements are provided with the same reference numerals.
[0055] Advantages and features of the present disclosure and ways to implement them will be apparent by referring to the embodiments described in detail below in conjunction with the accompanying drawings. However, the present disclosure is not limited to the embodiments set forth below and can be implemented in various different forms. The following embodiments are provided only to completely disclose the present disclosure and to inform those skilled in the art of the scope of the present disclosure, and the present disclosure is only defined by the scope of the appended claims. Throughout the specification, the same or similar reference numerals designate the same or similar elements.
[0056] Here, it will be understood that each block of the flowchart illustration and combinations of blocks in the flowchart illustration can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, a special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions executed via the processor of the computer or other programmable data processing apparatus create means for implementing the functions specified in the flowchart block or blocks. These computer program instructions can also be stored in a computer-usable or computer-readable memory, which can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-usable or computer-readable memory produce an article of manufacture including instruction means that implement the functions specified in the flowchart block or blocks. The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.
[0057] In addition, each block of the flowchart illustration can represent a module, a segment, or a portion of code, which includes one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks may occur out of order. For example, depending on the functionality involved, two blocks shown in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order.
[0058] As used herein, a "unit" refers to a software element or a hardware element that performs a predetermined function, such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). However, the meaning of a "unit" is not always limited to software or hardware. A "unit" can be constructed to be stored in an addressable storage medium or to execute on one or more processors. Thus, a "unit" includes, for example, software elements, object-oriented software elements, class elements or task elements, processes, functions, attributes, procedures, subroutines, program code segments, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and parameters. The elements and functions provided by a "unit" can be combined into a smaller number of elements or "units" or divided into a larger number of elements or "units". In addition, the elements and "units" can be implemented to reproduce one or more CPUs within a device or a secure multimedia card. In addition, a "unit" in an embodiment can include one or more processors.
[0059] Specific terms used in the following description are provided to assist in understanding the present disclosure, and the use of these specific terms may be changed in other forms without departing from the technical spirit of the present disclosure.
[0060] The secure element (SE) refers to a security module including a single chip, which is capable of storing security information (e.g., mobile communication network access keys, user identification information (such as ID card / passport, credit card information, encryption keys, etc.)), and using the stored security information to deploy and operate control modules (e.g., network access control modules, such as USIM, encryption modules, key generation modules, etc.). The SE can be used in various electronic devices (e.g., smart phones, tablets, wearable devices, motor vehicles, IoT devices, etc.), and can provide security services (e.g., mobile communication network access, payment, user authentication, etc.) via the security information and control modules.
[0061] The SE can be classified into a universal integrated circuit card (UICC), an embedded secure element (eSE), a smart security platform (SSP) (which is an integrated form of the UICC and eSE), etc., and can be further divided into removable type, embedded type, and integrated type, where the SE is integrated into a specific device or a system-on-chip (SoC) in the integrated type, depending on the type of connection of the electronic device or the installation on the electronic device.
[0062] A Universal Integrated Circuit Card (UICC) is a smart card inserted into a mobile communication terminal or the like for use, and is also referred to as a UICC card. The UICC may include an access control module for accessing the network of a mobile communication service provider. Examples of the access control module include a Universal Subscriber Identity Module (USIM), a Subscriber Identity Module (SIM), an IP Multimedia Service Identity Module (ISIM), etc. A UICC having a USIM is generally also referred to as a USIM card. Similarly, a UICC including a SIM module is generally referred to as a SIM card. The SIM module may be placed during the manufacture of the UICC, or the SIM module for the mobile communication service to be used may be downloaded to the UICC card when the user desires. In addition, for a UICC card, multiple SIM modules may be downloaded and installed, and at least one of the SIM modules may be selected for use. The UICC card may or may not be embedded in the terminal. The UICC embedded in the terminal for use is referred to as an embedded UICC (eUICC). Specifically, the UICC embedded in a system-on-chip (SoC) having a single-processor structure in which a communication processor of the terminal, an application processor of the terminal, or both processors are integrated is also referred to as an integrated UICC (iUICC). Generally, the eUICC and iUICC are embedded in the terminal for use, and may refer to a UICC card capable of remotely downloading and selecting a SIM module. In the present disclosure, a UICC card capable of remotely downloading and selecting a SIM module is collectively referred to as an eUICC or an iUICC. That is, among the UICC cards capable of remotely downloading and selecting a SIM module, the UICC cards embedded or not embedded in the terminal are collectively referred to and used as an eUICC or an iUICC. The SIM module information to be downloaded is collectively referred to by the terms eUICC profile, iUICC profile, or more simply, as a profile.
[0063] An embedded secure element (eSE) refers to an embedded SE fixed to an electronic device for use. The eSE is generally manufactured specifically for a manufacturer at the request of the terminal manufacturer, and may be manufactured to include an operating system and a framework. The eSE remotely downloads and installs a service control module of the applet type, and may be used for various security service purposes, such as an electronic wallet, ticketing, an electronic passport, and a digital key. In the present disclosure, an SE in the form of a single chip attached to an electronic device capable of remotely downloading and installing a service control module is collectively referred to as an eSE.
[0064] The Smart Security Platform (SSP) can integrate support for UICC and eSE functions on a single chip, and the SSP can be classified into a removable SSP (rSSP), an embedded SSP (eSSP), and an integrated SSP (iSSP) embedded in a SoC. The SSP can include a primary platform (PP) and at least one secondary platform bundle (SPB) operating on the PP. The primary platform can include at least one of a hardware platform and a low-level operating system (LLOS), and the secondary platform bundle can include at least one of a high-level operating system (HLOS) and an application executed on the HLOS. The secondary platform bundle is also referred to as the SPB or the bundle. The bundle can access resources such as the central processing unit and memory of the PP via the primary platform interface (PPI) provided by the PP, and thus can be executed on the PP. The bundle can be equipped with communication applications such as a subscriber identity module (SIM), a universal SIM (USIM), and an IP multimedia SIM (ISIM), and can also be equipped with various applications such as an electronic wallet, ticketing, an electronic passport, and a digital key.
[0065] Depending on the remotely downloaded and installed bundle, the SSP can be used for the above UICC or eSE purposes, and multiple bundles can be installed on a single SSP and operated simultaneously to allow the UICC and eSE to be used interchangeably. That is, if a bundle including a profile operates on the SSP, the SSP can be used for UICC purposes to access the network of a mobile communication service provider. Similar to in an eUICC or iUICC, the corresponding UICC bundle can remotely download at least one profile into the bundle and select the at least one profile to perform operations. If a bundle including a service control module operates on the SSP, the SSP can be used for eSE purposes, where the service control module is equipped with an application capable of providing services (such as an electronic wallet, ticketing, an electronic passport, or a digital key) on the SSP. Multiple service control modules can be installed and operated by being integrated into one bundle, or can be installed and operated as corresponding independent bundles.
[0066] Hereinafter, the terms used in the present disclosure will be described in more detail.
[0067] In the present disclosure, the SSP is a security module in the form of a chip that can integrate support for UICC and eSE functions on a single chip, and the SSP can be classified into a removable SSP (rSSP), an embedded SSP (eSSP), and an integrated SSP (iSSP) embedded in a SoC. The SSP can download and install bundles from an external bundle management server (secondary platform bundle manager, SPB manager) by using over-the-air (OTA) technology.
[0068] In the present disclosure, the method of downloading and installing a bundle in an SSP by using OTA technology can be applied in the same way to a removable SSP (rSSP) that can be inserted into and removed from a terminal, an embedded SSP (eSSP) installed in the terminal, and an integrated SSP (iSSP) included inside the SoC installed in the terminal.
[0069] In the present disclosure, the term UICC can be used interchangeably with SIM, and the term eUICC can be used interchangeably with eSIM. In the present disclosure, the term SSP can be used interchangeably with eUICC and eSIM.
[0070] In the present disclosure, the resources of the PP using the SSP on the primary platform (PP) are used to operate the secondary platform bundle (SPB), where the UICC bundle can refer to, for example, a software package of applications, a file system, authentication key values, etc. stored in an existing UICC, and an operating system (HLOS) in which the applications, file system, authentication key values, etc. operate. In the present disclosure, the secondary platform bundle can be used interchangeably with bundle, profile, and applet. In the present disclosure, the security service module can be used interchangeably with SSP and bundle.
[0071] In the present disclosure, the USIM profile can refer to the same thing as that referred to by the profile, or can refer to a software package of information included in the USIM application in the profile.
[0072] In the present disclosure, the operation of enabling a bundle by the terminal or an external server can refer to an operation of performing a configuration to change the state of the corresponding profile to an enabled state so that the terminal can receive services provided by the bundle (e.g., communication services via a communication service provider, credit card payment services, user authentication services, etc.). A bundle in an enabled state can be expressed as an "enabled bundle". The enabled bundle can be stored in a storage space inside or outside the SSP while being encrypted.
[0073] In the present disclosure, the enabled bundle can be changed to an active state according to an external input of the bundle (e.g., user input, push, request from an application in the terminal, authentication request from a communication service provider, PP management message, etc.) or an operation inside the bundle (e.g., timer and polling). A bundle in an active state can refer to an operation of being loaded from a storage space inside or outside the SSP into the operation memory inside the SSP by using a security control device (secure CPU) inside the SSP, processing security information, and providing security services to the terminal.
[0074] In the present disclosure, the operation of disabling a bundle by a terminal or an external server may refer to an operation of performing a configuration to change the state of the bundle to a disabled state so as to prevent the terminal from receiving services provided by the bundle. A profile in a disabled state may be expressed as "disabled bundle". A bundle in an enabled state may be stored in a storage space inside or outside the SSP while being encrypted.
[0075] In the present disclosure, the operation of deleting a bundle by a terminal or an external server may refer to an operation of performing a configuration to change the state of the bundle to a deleted state so as to prevent the terminal or the external server from enabling or disabling the bundle. A bundle in a deleted state may be expressed as "deleted bundle".
[0076] In the present disclosure, a bundle management server may provide functions of generating a bundle upon a request from a service provider or another bundle management server, encrypting the generated bundle, generating bundle remote management instructions, or encrypting the generated bundle remote management instructions. A bundle management server providing the above functions may be expressed as at least one of a secondary platform bundle manager (SPB manager), a remote bundle manager (RBM), an image delivery server (IDS), a subscription manager data preparation (SM-DP), a subscription manager data preparation plus (SM-DP+), a manager bundle server, a managed subscription manager data preparation plus (managed SM-DP+), a bundle encryption server, a bundle generation server, a bundle provider (BP), a bundle provider, a bundle provisioning credential holder (BPC holder).
[0077] In the present disclosure, a bundle management server may download, install, or update a bundle in the SSP, and may be used to manage key and certificate configurations for remotely managing the state of the bundle. A bundle management server providing the above functions may be expressed as at least one of a secondary platform bundle manager (SPBM), a remote bundle manager (RBM), an image delivery server (IDS), a subscription manager security routing (SM-SR), a subscription manager security routing plus (SM-SR+), an entity outside the card of an eUICC profile manager or a profile management credential holder (PMC holder), and an eUICC manager (EM).
[0078] In the present disclosure, a subscription relay server may be expressed as at least one of a secondary platform bundling manager (SPBM), a remote bundling manager (RBM), a secondary platform bundling discovery server (SPBDS), a bundling discovery server (BDS), a subscription manager discovery service (SM-DS), a discovery service (DS), a root subscription relay server (root SM-DS), and an alternative subscription relay server (alternative SM-DS). The subscription relay server may receive an event registration request (registration event request or event registration request) from one or more bundling management servers or subscription relay servers. One or more subscription relay servers may be used in combination, and in this case, the first subscription relay server may receive an event registration request not only from a bundling management server but also from a second subscription relay server. In the present disclosure, the functions of the subscription relay server may be integrated into the bundling management server.
[0079] In the present disclosure, the bundling management server may be collectively referred to as a combination of the functions of generating, encrypting, and transmitting a bundle or a bundle remote management instruction and the functions of configuring the SSP and managing the installed bundle. In addition, the bundling management server may be collectively referred to as a combination of the functions of the subscription relay server. Thus, in various embodiments, the operations of the bundling management server and the subscription relay server may be performed in one bundling management server. Each function may be separately performed by a plurality of bundling management servers separated from each other. In the specification, the bundling management server or the subscription relay server may be expressed as a bundling server. The bundling server may be one of the bundling management server and the subscription relay server, or may be a device including the bundling management server and the subscription relay server.
[0080] In the present disclosure, the bundling management server and the subscription relay server may be collectively referred to as the terms SPBM or RBM. The bundling server may be referred to as a bundling management server. The bundling server may be referred to as a security service module management server.
[0081] The term "terminal" as used in this disclosure may refer to a mobile station (MS), user equipment (UE), user terminal (UT), wireless terminal, access terminal (AT), terminal, subscriber unit, subscriber station (SS), wireless device, wireless communication device, wireless transmit / receive unit (WTRU), mobile node, mobile device, or other terms. Various embodiments of the terminal may include a cellular phone, a smart phone having a wireless communication function, a personal portable assistant (PDA) having a wireless communication function, a wireless modem, a portable computer having a wireless communication function, a photographing device having a wireless communication function (such as a digital camera), a game device having a wireless communication function, a music storage and playback appliance having a wireless communication function, an Internet appliance that enables wireless Internet access and browsing, and a portable unit or terminal that combines the functions of an Internet appliance. The terminal may include a machine-to-machine (M2M) terminal and a machine type communication (MTC) terminal / device, but is not limited thereto. In this disclosure, the terminal may also be referred to as an electronic device.
[0082] In this disclosure, an SSP that can be downloaded and installed in a bundled manner may be embedded in an electronic device. If the SSP is not embedded in the electronic device, an SSP physically separated from the electronic device may be inserted into the electronic device to be connected to the electronic device. For example, the SSP may be inserted into the electronic device in the form of a card. The electronic device may include a terminal, and in this case, the terminal may be a terminal including an SSP that can be downloaded and installed in a bundled manner. The SSP may not only be embedded in the terminal, but also be inserted into the terminal to be connected to the terminal in the case where the terminal and the SSP are separated.
[0083] In this disclosure, the terminal or the electronic device may include software or an application installed in the terminal or the electronic device to control the SSP. The software or the application may be referred to as, for example, a local bundling assistant (LBA) or a local bundling manager (LBM). In this disclosure, the terms LBA or LBM may be used interchangeably with the local profile assistant (LPA).
[0084] In the present disclosure, the bundling identifier is a factor called the matching bundling identifier (SPB ID), the bundling family identifier (SPB family ID), the bundling family manager identifier (SPB family custodian object ID), the bundling matching ID, and the event identifier (event ID). The bundling identifier (SPB ID) may indicate a unique identifier for each bundling. The bundling family identifier may indicate an identifier that differentiates the type of bundling (e.g., a telecommunications bundling for accessing a mobile communication service network). In the present disclosure, the bundling family identifier may be referred to as the spbFamilyId. The bundling family manager identifier may indicate an identifier that identifies the entity (e.g., a communication service provider, a terminal manufacturer, a specific group, etc.) that manages the bundling family identifier. In the present disclosure, the bundling family manager identifier may be referred to as the Oid. The bundling identifier may be used as a value that can index the bundling in the bundling management server. In the present disclosure, the SSP identifier (SSPID) may be a unique identifier of the SSP embedded in the terminal and may be referred to as the sspID. As in an embodiment of the present disclosure, if the terminal and the SSP chip are not separated, the SSP identifier may be the terminal ID. The SSP identifier may refer to a specific bundling identifier (SPB ID) in the SSP. More specifically, the SSP identifier may refer to the bundling identifier of the loader (secondary platform bundling loader, SPBL) or the management bundling that performs management to install, enable, disable, and delete another bundling in the SSP. The SSP may have multiple SSP identifiers, and the multiple SSP identifiers may be values derived from a single unique SSP identifier.
[0085] In the present disclosure, the loader (secondary platform bundling loader, SPBL) may refer to the management bundling that performs management to install, enable, disable, and delete another bundling in the SSP. The LBA of the terminal or the remote server may install, enable, disable, and delete a specific bundling via the loader. In the present disclosure, the loader may also be referred to as the SSP.
[0086] In the present disclosure, the bundling provisioning credential (BPC) may be a means for mutual authentication, bundling encryption, and signature between the bundling management server and the SSP. The BPC may include one or more of a symmetric key, a RIVEST SHAMIR ADLEMAN (RSA) certificate and private key, an elliptic curve cryptography (ECC) certificate and private key, a root certification authority (CA), and a certificate chain. If there are multiple bundling management servers, different BPCs of the corresponding multiple bundling management servers may be stored or used in the SSP.
[0087] In the present disclosure, a Profile Management Credential (PMC) can be a means for mutual authentication, transmission data encryption, and signature between a profile management server and an eUICC. The PMC can include one or more of a symmetric key, an RSA certificate and private key, an ECC certificate and private key, a root CA, and a certificate chain. If there are multiple profile management servers, different PMCs of the corresponding multiple profile management servers can be stored or used in the eUICC.
[0088] In the present disclosure, an event can be a term that collectively refers to bundling downloads, remote bundling management, or management / processing instructions for other bundling or SSPs. An event can be named a Remote Bundling Provisioning Operation (Remote Bundling Supply Operation or RBP Operation) or an event record, and each event can be said to include data such as the bundling management server in which the event is stored, the address of a subscription relay server or each server identifier, and at least one of a matching identifier (matching ID or matchingID) corresponding to the event or an event identifier (event ID or eventID). Bundling download can be used interchangeably with bundling installation. An event type can be a term used to indicate whether a specific event is a bundling download, remote bundling management (e.g., delete, enable, disable, replace, update, etc.), or other bundling or SSP management / processing command, and can be called an operation type (or OperationType), an operation class (or OperationClass), an event request type, an event class, an event request class, etc.
[0089] In the present disclosure, a bundling image (or image) can be used interchangeably with a bundle, or can be a term used to indicate a data object of a specific bundle, and can be called a bundling TLV or a bundling image TLV. If encryption parameters are used to encrypt the bundling image, the bundling image can be called a Protected Bundling Image (PBI) or a Protected Bundling Image TLV (PBI TLV). If encryption parameters that can only be decrypted by a specific SSP are used to encrypt the bundling image, the bundling image can be called a Bound Bundling Image (BBI) or a Bound Bundling Image TLV (BBI TLV). The bundling image TLV can be a data set representing information constituting a profile in TLV (tag, length, and value) format.
[0090] In the present disclosure, Local Bundle Management (LBM) may be referred to as Bundle Local Management, Local Management, Local Management Command, Local Command, LBM Package, Bundle Local Management Package, Local Management Package, Local Management Command Package, and Local Command Package. LBM may be used to change the state (enable, disable, or delete) of a specific bundle or modify (update) the content of a specific bundle (e.g., bundle nickname or bundle metadata) via software installed in a terminal. LBM may include one or more local management commands, and in this case, for the local management commands, the bundles subject to the local management commands may be the same as or different from each other respectively.
[0091] In the present disclosure, Remote Bundle Management (RBM) may be referred to as Bundle Remote Management, Remote Management, Remote Management Command, Remote Command, Remote Bundle Management Package (RBM Package), Bundle Remote Management Package, Remote Management Package, Remote Management Command Package, and Remote Command Package. RBM may be used to change the state (enable, disable, or delete) of a specific bundle or modify (update) the content of a specific bundle (e.g., bundle nickname, bundle profile information (bundle metadata), etc.). RBM may include one or more remote management commands, and for the remote management commands, the bundles subject to the remote management commands may be the same as or different from each other respectively.
[0092] In the present disclosure, a target bundle may be used as a term to refer to a bundle subject to a local management command or a remote management command.
[0093] In the present disclosure, a certificate or digital certificate may represent a digital certificate for mutual authentication based on an asymmetric key including a pair of a public key (PK) and a private key (SK). Each certificate may include one or more public keys (PKs), a public key identifier (PKID) corresponding to the respective public key, and an identifier (certificate issuer ID) of a certificate issuer (CI) that has issued the corresponding certificate and a digital signature. The certificate issuer may be referred to as an authentication issuer, a certificate authority (CA), an authentication authority, etc. In the present disclosure, the public key (PK) and the public key identifier (public key ID, PKID) may be used interchangeably with a storage space that stores: a specific public key or a certificate including a public key; a part of a specific public key or a part of a certificate including a public key; a calculation result of a specific public key or a calculation result of a certificate including a public key (e.g., a hash) value; a calculation result (e.g., a hash) value of a part of a specific public key or a calculation result (e.g., a hash) value of a part of a certificate including a public key; or data.
[0094] In the present disclosure, if a certificate (primary certificate) issued by a single certificate issuer is used to issue other certificates (secondary certificates), or if a secondary certificate is used to connectivity-issue a third or more certificates, the correlation of the corresponding certificates may be referred to as a certificate chain or certificate hierarchy, where the CI certificate used to issue the initial certificate may be referred to as a certificate root, top certificate, root CI, root CI certificate, root CA, root CA certificate, etc.
[0095] In the present disclosure, a service provider may indicate an enterprise that requests a bundle generation by issuing a request to a bundle management server, and provide services to a terminal via the generated bundle. For example, the service provider may represent a communication service provider (mobile carrier or carrier) that provides communication network access services via a bundle equipped with a communication application, and may be collectively referred to as all of a business support system (BSS), an operation support system (OSS), a point-of-sale terminal, and other IT systems of the communication service provider. In the present disclosure, the service provider is not limited to representing only a specific enterprise, and may be used to refer to a group or association (or consortium) of one or more enterprises, or represent an agent (representative) of the group or association. In the present disclosure, the service provider may be referred to as a business operator (operator or OP or Op.), a bundle owner (BO), an image owner (IO), etc., and each service provider may be configured or assigned at least one name and / or unique identifier (object identifier (OID)). If the service provider refers to a group, association, or representative of one or more enterprises, the name or unique identifier of the group, association, or representative may be a name or unique identifier shared by all enterprises belonging to the group or association or all enterprises cooperating with the representative.
[0096] In the present disclosure, a terminal manager (device manager) may issue requests to a bundling management server or a service provider to request generation of a bundle, may subscribe to services of the service provider, and may indicate to an SSP of a terminal managed by the device manager an enterprise that provides services via the bundle. The device manager may be a service subscriber that has entered into a contract with the service provider and subscribed to services provided by the service provider. For example, the device manager may represent a business operator or an M2M service provider that provides and uses a remote measurement service by using IoT terminals, and may refer to an enterprise that manufactures and sells terminals or a terminal manufacturer. In the present disclosure, the device manager is not limited to representing only one specific enterprise, and may be used to refer to a group or association (or consortium) of one or more enterprises, or represent an agent (representative) of the group or association. In the present disclosure, the device manager may be referred to as a bundle owner (BO), a bundle manager, an image owner (IO), a service subscriber, etc., and each device manager may be configured or assigned at least one name and / or a unique identifier (object identifier (OID)). If the device manager refers to a group, association, or representative of one or more enterprises, the name or unique identifier of the group, association, or representative may be a name or unique identifier shared by all enterprises belonging to the group or association or all enterprises cooperating with the representative.
[0097] In the present disclosure, AKA may indicate authentication and key agreement, and may indicate an authentication algorithm for accessing 3GPP and 3GPP2 networks.
[0098] In the present disclosure, K (or the K value) may be an encryption key value stored in the eUICC and used in the AKA authentication algorithm.
[0099] In the present disclosure, OPc may be a parameter value that can be stored in the eUICC and used in the AKA authentication algorithm.
[0100] In the present disclosure, NAA is a network access application, and may be an application program stored in the UICC for accessing a network, such as a USIM or an ISIM. The NAA may be a network access module.
[0101] In the present disclosure, a telecommunications bundle may be a bundle equipped with at least one NAA or equipped with a function of remotely downloading and installing at least one NAA. In the present disclosure, the telecommunications bundle may include a telecommunications bundle identifier indicating the telecommunications bundle.
[0102] Furthermore, when describing the present disclosure, when it is determined that a detailed description of a related known function or configuration may unnecessarily obscure the subject matter of the present disclosure, its detailed description will be omitted.
[0103] In the following, various embodiments of a method and apparatus for online installation and management of bundles via a remote server will be described.
[0104] Figure 1 A diagram showing a method for a terminal to perform mobile communication network connection using an intelligent security platform (SSP) equipped with a telecommunications bundle including a profile according to some embodiments is shown.
[0105] As Figure 1 shown, the SSP 120 may be embedded in the SoC 130 of the terminal 110. The SoC 130 may be a communication processor, an application processor, or a processor in which two processors are integrated. The SSP 120 may be a removable type 122 in the form of an independent chip not integrated into the SoC, or may be an embedded type 124 previously embedded in the terminal 110.
[0106] The bundle having a profile may indicate "access information" including that which can be used to access a specific communication service provider. For example, the access information may be an international mobile subscriber identity (IMSI) as a subscriber identifier, and a K or Ki value that is required for authentication to the network in addition to the subscriber identity.
[0107] The terminal 110 may perform authentication with an authentication processing system (e.g., a home location register (HLR) or an authentication center (AuC)) of a mobile communication service provider by using at least one of the telecommunications bundles 140 and 150 installed inside the SSP 120. For example, the authentication processing may be an authentication and key agreement (AKA) process. If the authentication is successful, the terminal 110 may use mobile communication services such as using mobile data or making a phone call through the mobile communication network 160 of the mobile communication system. Each of the two telecommunications bundles 140 and 150 may store different authentication information, and the terminal 110 may operate the two telecommunications bundles 140 and 150 simultaneously or in a time-division manner according to the configuration to use the mobile communication network.
[0108] By using the payment bundle 170 installed in the SSP 120, the terminal 110 may use online payment via a terminal application, or may use offline payment via an external credit card point of sale (PoS) device, and the identity of the terminal owner may be authenticated using an electronic identity card (eID) bundle 180.
[0109] Figure 2 A conceptual diagram showing the internal structure of an SSP according to some embodiments is shown.
[0110] In Figure 2In [the context], the SSP 210 may include a main platform (PP) 220, and one or more secondary platform bundles (SPBs) 230 and 240 operating thereon. The main platform 220 may include hardware (not shown) and at least one low-level operating system (LLOS) 222. The secondary platform bundle 230 may include a high-level operating system (HLOS) 232 and at least one application 234 operating thereon. Each of the secondary platform bundles 230 and 240 may access resources such as the central processing device, memory, etc. of the main platform 220 to operate on the SSP 210 by using the main platform interface (PPI) 250.
[0111] Figure 3 A diagram is shown that illustrates an example of the hierarchy (certificate hierarchy or certificate chain) of certificates issued by a certificate issuer (CI), the public keys included in each certificate, and the digital signature configuration of the certificate issuer (CI) according to some embodiments. In the present disclosure, the certificate issuer (CI) may be used interchangeably with the certificate authority (CA).
[0112] Referring Figure 3 , the certificate issuer (CI) may generate a public key 313 and a private key for its own use by the certificate issuer, may generate a CI certificate (certificate issuer certificate) 311 that includes the public key 313 of the two generated keys in its own certificate, and may attach a digital signature 315 generated using its private key to the certificate issuer's certificate itself.
[0113] Referring Figure 3 , the CI certificate 311 may be used to issue 391 an object 1 certificate 331. The object 1 may be, for example, a bundle management server (SPBM). The object 1 may generate a public key 333 and a private key for its own use, and may generate an object 1 certificate 331 that includes the public key 333 of the two generated keys in its own certificate. The object 1 may send a request to the certificate issuer (CI) to receive a digital signature (CI digital signature) 335 of the certificate issuer by using the private key (CI private key) of the certificate issuer. The object 1 certificate 331 may include an identifier 337 of the certificate issuer, which corresponds to the public key (CI public key) 313 of the certificate issuer that should be used when verifying the digital signature 335 of the certificate issuer included in the object 1 certificate 331. The identifier 337 of the certificate issuer may include at least one of a public key identifier (CI public key ID) of the certificate issuer and a CI identifier (CI ID, CI object ID, object universal unique identifier, or object UUID).
[0114] Referring Figure 3, the CI certificate 311 can be used to issue the object 2 certificate 351. The object 2 can be, for example, an SSP manufacturer (SSP maker). The object 2 can generate a public key 353 and a private key to be used by it, and can generate the object 2 certificate 351 by including the public key 353 of the two generated keys in its own certificate. The object 2 can send a request to the certificate issuer to receive the digital signature (CI digital signature) 355 of the certificate issuer by using the private key (CI private key) of the certificate issuer. The object 2 certificate 351 can include an identifier 357 of the certificate issuer, which corresponds to the public key (CI public key) 313 of the certificate issuer that should be used when verifying the digital signature 355 of the certificate issuer included in the object 2 certificate 351. The identifier 357 of the certificate issuer can include at least one of a public key identifier (CI public key ID) and a CI identifier (CI ID, CI object ID, object universal unique identifier, or object UUID) of the certificate issuer. The certificate issuer signatures 335 and 355 included in the object 1 certificate 331 and the object 2 certificate 351 can have different values, but the public key identifier 357 of the certificate issuer can have the same value.
[0115] Reference Figure 3 , the object 2 certificate 351 can be used to issue the object 3 certificate 357. The object 3 can be, for example, an SSP manufactured by an SSP manufacturer (SSP maker) or a secondary platform loader (SPBL) placed inside the SSP. The object 3 can generate a public key 373 and a private key to be used by it, and can generate the object 3 certificate 371 that includes the public key 373 of the two generated keys in its own certificate. The object 3 can send a request to the object 2 to receive the digital signature 375 of the object 2 by using the private key of the object 2. The object 3 certificate 371 can include an identifier 377 corresponding to the public key 353 of the object 2, which should be used when verifying the digital signature 375 of the object 2 included in the object 3 certificate 371. The identifier 377 can include at least one of a publisher identifier (object ID or object universal unique identifier (object UUID)) of the publisher and a public key identifier (public key ID).
[0116] Although not shown in Figure 3 , there can be at least one sub-certificate issuer (sub-CI or sub-certificate authority (sub-CA)) between the certificate issuer (CI), the object 1, and the object 2. The sub-certificate issuer certificate can be issued by the certificate issuer (CI) through the CI certificate 311, or can be issued by another sub-certificate issuer through its own sub-certificate issuer certificate. The sub-certificate issuer can issue the object 1 certificate or the object 2 certificate by using the certificate of the sub-certificate issuer.
[0117] Although inFigure 3 is not shown, but there may be at least one sub-certificate issuer (sub-CI or sub-certificate authority (sub-CA)) between Object 2 and Object 3. The sub-certificate issuer certificate may be issued by Object 2 via the Object 2 certificate 351, or may be issued by another sub-certificate issuer via its own sub-certificate issuer certificate. The sub-certificate issuer may issue the Object 3 certificate and the Object 2 certificate by using its own sub-certificate issuer certificate.
[0118] Reference Figure 3 , the extended configuration values 317, 339, 359, and 379 of the corresponding certificates 311, 331, 351, and 371 may include a bundle family identifier (SPB family ID) of a bundle that can be downloaded and installed in the corresponding certificate, or a bundle family identifier (SPB family ID) and a bundle family manager identifier (SPB family custodian object ID).
[0119] Figure 3 The Object 1 certificate 331, the Object 2 certificate 351, and the Object 3 certificate 371 shown in the example of may all have the same CI certificate 311 as the highest certificate or the certificate root. Therefore, in order for Object 1, Object 2, and Object 3 to authenticate each other, the CI certificate 311 or the CI public key 313 included therein may be required. More specifically, in Figure 3 's example, in order for Object 1 and Object 2 to authenticate each other by using digital certificates and signatures, Object 1 may require the signature of Object 2, the Object 2 certificate 351, and the CI public key 313, and Object 2 may require the signature of Object 1, the Object 1 certificate 331, and the CI public key 313. More specifically, in Figure 3 's example, in order for Object 1 and Object 3 to authenticate each other by using digital certificates and signatures, Object 1 may require the signature of Object 3, the Object 3 certificate 371, the Object 2 certificate 351, and the CI public key 313, and Object 3 may require the signature of Object 1, the Object 1 certificate 331, and the CI public key 313. In this case, for the Object 3 certificate 371, the Object 2 certificate 351 may be referred to as a sub-certificate issuer (sub-CI or sub-certificate authority (sub-CA)) certificate.
[0120] Figure 4 shows a diagram of an example of a hierarchy of certificates (certificate hierarchy or certificate chain) issued by a certificate issuer (CI), the public keys included in each certificate, and the digital signature configuration of the certificate issuer (CI).
[0121] Reference Figure 4, the CI certificate 421 can be used to issue the connection certificate 441, or the object 2 certificate 451 can be used to issue the connection certificate 441. Sub-certificate issuer certificates (not shown) that can exist between the CI certificate 421 and the object 2 certificate 451 and between the object 2 certificate 451 and the object 3 certificate 471 can be used to issue the connection certificate 441. The connection certificate 441 can receive a digital signature 445 by using the private key of the issuer. The connection certificate 441 can include an identifier 447 corresponding to the public key of the issuer, which should be used when verifying the signature 445 included in the connection certificate 441. The identifier 447 can include at least one of the issuer identifier (object ID or object universal unique identifier (object UUID)) of the issuer and the public key identifier (public key ID). The public key 443 of the connection certificate 441 can be the value of the issuer identifier 447 corresponding to the object 1 certificate 431, or the value of the issuer identifier corresponding to a sub-issuer certificate (not shown) that can exist between the CI certificate 411 and the object 1 certificate 431. The extended configuration value 449 of the connection certificate 441 can include the bundle family identifier (SPB family ID) of the bundle that the issuer has allowed the object 1 to download to the object 3 to the corresponding certificate bundle, or the bundle family identifier (SPB family ID) and the bundle family manager identifier (SPB family custodian object ID).
[0122] Reference Figure 4 , the extended configuration values 417, 427, 439, 449, 459, and 479 of the corresponding certificates 411, 421, 431, 441, 451, and 471 can include the bundle family identifier (SPB family ID) of the bundle that can be downloaded and installed in the corresponding certificate, or the bundle family identifier (SPB family ID) and the bundle family manager identifier (SPB family custodian object ID).
[0123] Although not shown in Figure 4 , there can be at least one sub-certificate issuer (sub-CI or sub-certificate authority (sub-CA)) between the certificate issuer (CI), the object 1, and the object 2. The sub-certificate issuer certificate can be issued by the certificate issuer (CI) through the CI certificate 411, or can be issued by another sub-certificate issuer through its own sub-certificate issuer certificate. The sub-certificate issuer can issue the object 1 certificate or the object 2 certificate by using the sub-certificate issuer's certificate. The extended configuration value of the sub-certificate issuer certificate can include the bundle family identifier (SPB family ID) of the bundle that can be downloaded and installed in the corresponding certificate, or the bundle family identifier (SPB family ID) and the bundle family manager identifier (SPB family custodian object ID).
[0124] Although in Figure 4Although not shown in [the figure], there may be at least one sub-certificate issuer (sub-CI or sub-certificate authority (sub-CA)) between Object 2 and Object 3. The sub-certificate issuer certificate may be issued by Object 2 through the Object 2 certificate 451, or may be issued by another sub-certificate issuer through its own sub-certificate issuer certificate. The sub-certificate issuer may issue the Object 3 certificate and the Object 2 certificate by using its own sub-certificate issuer certificate.
[0125] Reference Figure 4 , the shown Object 1 certificate 431 and Object 2 certificate 451 may respectively have different CI certificates 411 and CI certificates 421 as the highest certificates or certificate roots. Therefore, in order for Object 2 and Object 3 to authenticate Object 1, the included CI certificate 411 and / or CI public key 413 may be required. In order for Object 1 to authenticate Object 2 and Object 3, the included CI certificate 421 and / or CI public key 423 may be required. More specifically, in Figure 4 's example, in order for Object 1 and Object 2 to authenticate each other by using digital certificates and signatures, Object 1 may require the signature of Object 2, the Object 2 certificate 451, and the CI public key 423, and Object 2 may require the signature of Object 1, the Object 1 certificate 431, and the CI public key 413. In Figure 4 's example, in order for Object 1 and Object 3 to authenticate each other by using digital certificates and signatures, Object 1 may require the signature of Object 3, the Object 3 certificate 471, the Object 2 certificate 451, and the CI public key 423, and Object 3 may require the signature of Object 1, the Object 1 certificate 431, and the CI public key 413.
[0126] Reference Figure 4 , in order for Object 3 to authenticate Object 1, the included connection certificate 441, CI certificate 421, and / or public key 423 may be required. More specifically, in Figure 4 's example, in order for Object 3 to authenticate Object 1 by using the digital certificate and signature of Object 1, Object 3 may require the signature of Object 1, the Object 1 certificate 431, the connection certificate 441, and the CI public key 423. In order for Object 3 to authenticate Object 1, the included connection certificate 441, Object 2 certificate 451, CI certificate 421, and / or public key 423 may be required. More specifically, in Figure 4 's example, in order for Object 3 to authenticate Object 1 by using the digital certificate and signature of Object 1, Object 3 may require the signature of Object 1, the Object 1 certificate 431, the connection certificate 441, the Object 2 certificate 451, and the CI public key 423.
[0127] Figure 5 FIG. shows an example diagram for allowing a terminal to download and install internal and external components of a bundled terminal via an SSP according to some embodiments.
[0128] In Figure 5 , the terminal 510 can be a terminal in which the SSP 530 is placed and the LBA 512 for controlling the SSP 530 is installed. The SSP 530 can be embedded in the terminal 510 or can be removable. The SSP 530 can include a main platform 531, a secondary platform bootloader (SPBL) 533, and one or more secondary platform bundles 535, 537, or 539. The secondary platform bundles 535, 537, or 539 may not be installed in the SSP 530 when the terminal is shipped, but can be remotely downloaded and installed after shipment.
[0129] Referring Figure 5 to, the corresponding bundle can have different bundle family identifiers, or different bundle family identifiers and bundle family manager identifiers 541 or 542. The SSP 530 or SPBL 533 can store and manage a certificate configuration 551 that is allowed for downloading and installing bundles with different bundle family identifiers, or bundle family identifiers and bundle family manager identifiers. The LBA 512 can request the certificate configuration 551 from the SSP 530 or SPBL 533, and the certificate configuration can be copied and stored in the LBA 512.
[0130] Referring Figure 5 to, the SSP 530 or SPBL 533 can store and manage certificate information 552, 553, or 554, and different family identifiers and different bundle family manager identifiers are assigned to the certificate information 552, 553, or 554. The certificate information 552, 553, or 554 to which a family identifier and a bundle family manager identifier are assigned can be used to download a bundle including the assigned family identifier and bundle family identifier. The SSP 530 or SPBL 533 can reject downloading and installing a bundle that does not include the family identifier and bundle family identifier assigned to the corresponding certificate information 552, 553, or 554.
[0131] Referring Figure 5 to, different bundle family identifiers are assigned to the SSP 530 or SPBL 533, and the SSP 530 or SPBL 533 can store and manage certificate information 555 or 556 to which no bundle family manager identifier is assigned. The certificate information 555 or 556 to which a family identifier is assigned can be used to download a bundle including the assigned family identifier.
[0132] Referring Figure 5 to, the SSP 530 or SPBL 533 can store and manage certificate information 557 to which no bundle family identifier and bundle family manager identifier are assigned.
[0133] Figure 5The certificate information 552, 553, 554, 555, 556, and 557 stored and managed by SSP 530 or SPBL 533 can be Figure 3 or Figure 4 the CI certificate in, the public key identifier of the CI certificate, the certificate issued by the certificate issuer (CI) existing in the certificate hierarchy, or the public key identifier of the corresponding certificate. When downloading and installing a bundle from the bundle management server 551 or 553, SSP 430 or SPBL 433 can select the certificate information configured for the bundle family identifier assigned to the bundle, or the certificate information configured for the bundle family identifier and the bundle family manager identifier assigned to the bundle, and can transmit this information to the bundle management server 551 or 553. The certificate information can be the certificate or public key of the certificate issuer (CI) of the certificate hierarchy, and can be the identifier corresponding to the certificate and the public key (for example, CI ID, CI ID, CI object ID, object universal unique identifier (object UUID), or CI public key ID).
[0134] Figure 6 FIG. shows an example of a process in which a subscriber subscribes to a service via a service provider and the service provider and the bundle management server prepare to download a bundle according to some embodiments.
[0135] In Figure 6 the terminal 600 can be a terminal in which the SSP 610 is placed and the LBA 620 for controlling the SSP 610 is installed. Although not shown in the figure, in the bundle management server 650, the bundle requested by the service provider 640 can be generated and waiting, and the service provider 640 can have at least one of the bundle identifier (SPB ID), bundle family identifier (SPB family ID), bundle family manager identifier (SPB family custodian object ID), and the address of the bundle management server 650 (SPBM Addr) of the generated bundle.
[0136] Referring to Figure 6 , in operation 6001, the subscriber 630 can select and subscribe to a service provided by the service provider 640 (for example, data service via a mobile communication network, etc.). The subscriber 630 can selectively transmit the identifier (SSPID) of the SSP 610 installed in the terminal 600 in which the bundle is to be installed to the service provider 640 in order to use the service provided by the service provider 640.
[0137] In operation 6003, service provider 640 and bundle provisioning server 650 may perform a bundle download preparation process. In operation 6003, service provider 640 may selectively transmit to bundle management server 650 the identifier (SSPID) of the SSP 610 in which the bundle is to be installed, and may transmit to bundle management server 650 at least one of a specific bundle identifier (SPB ID), a bundle family identifier (SPB family ID), and a bundle family manager identifier (SPB family custodian object ID), which enables the provision of services selected by the subscriber from among the bundles prepared by the server. In operation 6003, bundle management server 650 may select one of the bundle with the transmitted specific bundle identifier, the bundle with the bundle family identifier, and the bundle with the bundle family identifier and the bundle family manager identifier, and may transmit to service provider 640 the identifier of the selected bundle. Service provider 640 or bundle provisioning server 650 may newly generate a bundle match ID that enables the identification of the selected bundle. Bundle provisioning server 650 may connect and manage the transmitted SSP identifier (SSPID) and the selected bundle. In operation 6003, bundle management server 650 may transmit the bundle management server address (SPBM Addr) via which the selected bundle may be downloaded. The bundle management server address may be its own address in which the prepared bundle is stored or the address of another bundle management server, and may be the address of another bundle management server via which the download information (server address, etc.) of the prepared bundle may be stored and obtained.
[0138] Reference Figure 6 , in operation 6005, service provider 640 may transmit the prepared bundle download information to subscriber 630. For the bundle download information, at least one of the bundle management server address (SPBMAddr) for which the bundle is prepared, the bundle match ID of the prepared bundle, the bundle family identifier (SPB family ID) of the prepared bundle, and the bundle family custodian ID may be selectively transmitted.
[0139] Reference Figure 6In operation 6006, the bundled download information can be transmitted to the LBA 620 of the terminal 600. The bundled download information can be at least one of the address of the bundling management server (SPBM Addr) that the LBA 620 is to access, the bundling identifier of the bundle prepared in operation 6003, the bundling family identifier (SPBM family ID) of the prepared bundle, and the bundling family manager identifier (SPB family custodian object ID). The bundling identifier can include at least one of the bundling event ID or the bundling match ID generated in operation 6003. The bundling identifier can include at least one of the bundling family identifier and the bundling family manager identifier (SPB family custodian object ID) of the prepared bundle. The bundling event ID can include at least one of the address of the bundling management server and the bundling match ID of the bundle prepared in operation 6003. The bundled download information can be input (e.g., QR code scanning, direct text input, etc.) by the subscriber 630 to the LBA 620, or can be input to the LBA 620 by using push input via an information providing server (not shown). The LBA 620 can access an information providing server (not shown) pre-configured for the terminal 600 to receive the bundled download information.
[0140] Figure 7 FIG. shows an example of the configuration of a terminal 700 and a method of interoperating between a service provider 730, a bundling management server 740, and a device manager (device subscription manager) 750 according to some embodiments.
[0141] Reference Figure 7 , the terminal 700 can include at least one bundling management software (or LBA) 710 and at least one SSP 720. The SSP 720 can include at least one SPBL 760, and a bundle 770.
[0142] In operation 7001, the service provider 730 can request remote bundling management from at least one bundling management server 740. The bundling management server 740 can be owned by the service provider 730, or can be operated by a third party via a contract. The remote management request can include at least one of new bundle installation, enabling, disabling, deleting an installed bundle, and obtaining and modifying bundle information.
[0143] In operation 7002, the device manager 750 can request remote bundling management from at least one bundling management server 740. The bundling management server 740 can be owned by the service provider 730 or the device manager 750, or can be operated by a third party via a contract.
[0144] The device manager 750 may request remote bundle management from the service provider 730 via operation 7003. In response to this request, in operation 7001, the service provider 730 may request remote bundle management from at least one bundle management server 70.
[0145] In operation 7004, the bundle management server 740 may transmit a remote management command to the bundle management software 710. The remote management command may be a remote management command generated by the bundle management server 740 for at least one of the remote management requests for a specific bundle made in operations 7001, 7002, and 7003.
[0146] In operation 7005, the bundle management software 710 may identify at least one of the bundle configuration, bundle management software configuration, SPBL configuration, and terminal configuration indicated by the remote management command. If confirmation from the user 760 is required to execute the remote management command according to the confirmed configuration, then confirmation from the user 760 may be requested and received.
[0147] In operation 7006, the remote management command may be transmitted to the SSP 720 via the bundle management software 710. In the present disclosure, the bundle management operation of the service provider may be referred to as remote bundle management (remote SPB management).
[0148] In operation 7006, the SSP 720 or SPBL 760 may check the bundle policy for processing the received remote bundle management command. The bundle policy may be stored in the bundle 770, SPBL 760, or the bundle management software 710, and checking the bundle policy may also include checking the bundle management software 710 or the bundle management server 740. For a more detailed method of checking the bundle policy, reference will be made to the drawings described later.
[0149] Figure 8 A diagram showing an example of the general process of performing remote bundle management by the terminal 800 according to some embodiments is shown.
[0150] In Figure 8 order to describe the configurations of the terminal 800, LBA 810, SSP 820, service provider 830, bundle management server 840, and user 850, reference will be made respectively to Figure 7 the description of
[0151] Reference Figure 8, in operation 8001, the LBA 810 can discover that the remote management commands of the SSP 820 exist in the bundled management server 840. Operation 8001 can use a common user interface for user-terminal interaction. For example, the user 850 can input a specific operation (such as QR code scanning) to the LBA 810, or can select a specific menu of the LBA 810. Operation 8001 can be input from the bundled management server 840, a third bundled management server (not shown), or a specific server (not shown).
[0152] Reference Figure 8 , in operation 8002, the LBA 801 can request and download remote bundled management commands from the bundled management server 840. The LBA 810 can request information for requesting remote bundled management commands from the SSP 820, and can transmit the information to the bundled management server 840. In operation 8003, the bundled management server 840 can verify the information, and after successfully performing the verification, the bundled management server 840 can transmit remote bundled management commands to the LBA 810 in response to the request. The remote bundled management commands can include at least one of an identifier of a bundle targeted for bundled management, a bundle family identifier of the target bundle, a bundle family manager identifier of the target bundle, a bundle owner identifier of the target bundle, and a remote management command type.
[0153] In operation 8004, the LBA 810 can check the policy of the bundle targeted for remote bundle management or the policy of the SSP 820. The LBA 810 can check the bundle policy of the target bundle stored in the terminal 800 by using the target bundle identifier configured for the remote bundle management command. The bundle policy can be stored in the metadata of the bundle, and the metadata of the bundle can be stored in the LBA 810 or the SSP 820. If remote management that requires end-user consent is to be performed according to the bundle policy, the LBA 810 can request user consent for the remote management command from the user. A bundle policy for remote bundle management can be configured for the LBA 810, and when remote management that requires end-user consent is performed according to the bundle policy configured for the LBA 810, the LBA 810 can request user consent for the remote management command from the user. If at least one of the bundle policy stored in the metadata of the bundle and the bundle policy configured for the LBA 810 for the remote management command requires user consent, the LBA 810 can request user consent for the remote management command from the user. Operation 8004 can use a general user interface for the user to interact with the terminal. When remote management that requires end-user consent is performed according to the bundle policy, the LBA 810 can perform operation 8005 after successful execution of the user consent. When performing remote management that does not require user consent (end-user consent) due to the bundle policy, the LBA 810 can perform operation 8005 without user consent.
[0154] In operation 8004, when end-user consent is configured to be mandatory for at least one of the metadata of the bundle, the terminal 800, the LBA 810, and the SSP 820, the LBA 810 can perform operation 8005 after successful execution of the user consent. For example, this configuration can be performed in the case of a user terminal (such as a smart phone) that requires user consent to be executed. If user consent is impossible, the LBA 810 can reject the remote management command.
[0155] If, in operation 8004, it is necessary to verify the remote bundle management server that has transmitted the remote bundle management command according to the bundle policy, the LBA 810 can selectively verify whether the bundle management server 840 corresponds to the bundle management server that allows the transmission of the remote management command according to the bundle policy. If the LBA 810 selectively performs this verification, the LBA 810 can perform operation 8005 after successful execution of the verification of the remote bundle management server.
[0156] In operation 8005, the LBA 810 may request remote bundle management from the SSP 820. In operation 8006, the SSP 820 may check the bundle policy of the target bundle or the remote bundle management policy configured for the SSP 820 to perform remote bundle management. For example, in the case of remote bundle management for installing a bundle, the SSP 820 may receive, via the LBA 810, summary information (bundle metadata) of the bundle to be installed in the SSP 820 and / or a part of the bundle policy from the bundle management server 840. As another example, in addition to the bundle policy stored by itself, the SSP 820 may also receive all or a part of the bundle policy from the LBA 810. The SSP 820 may check the bundle policy of the target bundle stored in the SSP 820 by using the target bundle identifier configured for the remote bundle management command. The detailed operation of the SSP 820 for checking the bundle policy will be described with reference to the description of the accompanying drawings described later.
[0157] If it is necessary to verify the remote bundle management server that has transmitted the remote bundle management command according to the bundle policy, the SSP 820 may verify whether the bundle management server 840 corresponds to the bundle management server that allows the transmission of the remote management command according to the bundle policy. If the remote bundle management command is transmitted from a bundle management server that does not allow the transmission of the remote management command according to the bundle policy, the SSP 820 may terminate the remote bundle management. Even if remote bundle management is performed on a bundle for which remote management is not allowed according to the bundle policy, the SSP 820 may terminate the remote bundle management.
[0158] If the bundle policy requires verification of the remote bundle management server, the SSP 820 may use the verification key (credential) or verification method stored in the bundle policy of the bundle specified by the transmitted remote management command to verify the bundle management server 840 that has transmitted the remote management command. For example, the bundle policy may store a public key that can be used to verify a digital signature, a digital certificate, a public key identifier (PKI) corresponding to the digital certificate or the public key of the digital certificate, a public key of a higher certificate that can verify the digital certificate, or a public key identifier corresponding to the public key of the higher certificate. The stored information may be information associated with the digital certificate for the remote bundle management corresponding to the bundle, which is issued by the service provider 830 or the bundle owner to the bundle management server 840, where the bundle belongs to the service provider 830 or the bundle owner itself. In addition to the information, the bundle policy may selectively include whether bundle management server verification is required. The SSP 820 may verify the digital signature included in the received remote bundle management command according to the configuration. If the remote bundle management command is transmitted from a bundle management server for which unauthorized verification is impossible, the SSP 820 may terminate the remote bundle management.
[0159] In operation 8007, the SSP 820 may transmit the result of the remote management command to the LBA 810. In operation 8008, the LBA 810 may notify the user of the result of executing the remote management command via the user interface. The LBA 810 may notify the bundling management server 840 of the result of executing the remote management command, and in operation 8010, the bundling management server 840 may notify the service provider 830 of the result of executing the remote bundling management. The result notified in operation 8010 may include a part or all of the result of executing the remote bundling management transmitted from the LBA 810 in operation 8009.
[0160] Figure 9 A diagram showing an example of the general process of performing remote bundling management by the terminal 900 according to some embodiments.
[0161] In Figure 9 order to describe the configurations of the terminal 900, the LBA 910, the SSP 920, the service provider 930, the bundling management server 940, and the user 950, reference will be made to the descriptions of Figure 7 respectively.
[0162] Referring to Figure 9 , in operation 9001, the LBA 910 may discover that a remote management command for the SSP 920 exists in the bundling management server 940. Operation 9001 may use a general user interface for the user to interact with the terminal. For example, the user 950 may input a specific operation (such as QR code scanning) to the LBA 910, or may select a specific menu of the LBA 910. Operation 9001 may be input from the bundling management server 840, a third bundling management server (not shown), or a specific server (not shown) without involving the user 950.
[0163] Referring to Figure 9 , in operation 9002, the LBA 910 may request and download a remote bundling management command from the bundling management server 940. The LBA 910 may request information for requesting the remote bundling management command from the SSP 920, and may transmit the information to the bundling management server 940. In operation 9003, the bundling management server 940 may verify the information, and after successfully performing the verification, the bundling management server 840 may transmit the remote bundling management command to the LBA 910 in response to the request. The remote bundling management command may include at least one of an identifier of the bundle targeted for bundling management, a bundle family identifier of the target bundle, a bundle family manager identifier of the target bundle, a bundle owner identifier of the target bundle, and a remote management command type.
[0164] In operation 9004, the LBA 910 may request remote bundle management from the SSP 920. In operation 9005, the SSP 920 may check the bundle policy of the target bundle or the remote bundle management policy configured for the SSP 920 to perform remote bundle management. For example, in the case of remote bundle management for installing a bundle, the SSP 920 may receive, via the LBA 910, summary information (bundle metadata) of the bundle to be installed in the SSP 920 and / or a part of the bundle policy from the bundle management server 940. As another example, in addition to the bundle policy stored by itself, the SSP 920 may also receive all or a part of the bundle policy from the LBA 910. As another example, the SSP 920 may preferably apply the remote bundle management policy configured for the SSP 920 regardless of the summary information of the bundle. As another example, the SSP 920 may check the bundle policy of the target bundle stored in the terminal 900 by using the target bundle identifier configured for the remote bundle management command. The detailed operation of the SSP 920 for checking the bundle policy will be described with reference to the description of the accompanying drawings to be described later.
[0165] If it is necessary to verify the remote bundle management server that has transmitted the remote bundle management command according to the bundle policy, the SSP 920 may verify whether the bundle management server 940 corresponds to the bundle management server that allows the transmission of the remote management command according to the bundle policy. If the remote bundle management command is transmitted from a bundle management server that does not allow the transmission of the remote management command according to the bundle policy, the SSP 920 may terminate the remote bundle management. Even if the remote bundle management is performed on a bundle for which remote management is not allowed according to the bundle policy, the SSP 920 may terminate the remote bundle management.
[0166] As a result of checking the bundling policy, if remote management requires the device manager or subscriber to consent to verification, in operation 9006, the SSP 920 can identify the subscriber's intent. In the present disclosure, the subscriber can be a user or group that purchases a bundle from the service provider 930 to use a specific service, or can be the device manager (individual or group) that manages the terminal 900. The execution of operation 9006 can also include the terminal 900, the service provider 930, the device manager 950, and / or the bundling management server 940. The implementation of operation 9006 can utilize various other means provided by the terminal 900, the bundling management server 940, the service provider 930, and the device manager 950, such as checking the digital signature or certificate of the service provider 930 or the device manager 950 for any data (e.g., remote management request message, any string generated by the bundling management server 940 or the SSP 920, etc.), or identifying the private key (credential key) previously provided in the bundle installed in the terminal, the SSP 920, the LBA 910, and / or the bundling management server 940 by the device manager 950 or the service provider 930. The subscriber consent verification means to be used in operation 9006 can be configured in the bundling policy, and if such means are not configured in the bundling policy, any means agreed upon / selected by the terminal 900, the bundling management server 940, the service provider 930, or the device manager 950 can be used. If, as a result of checking the bundling policy, remote management does not require subscriber consent verification, operation 9006 can be omitted. If the subscriber consent verification fails, the SSP 920 can terminate the remote management. If subscriber consent verification is not required, or if the subscriber consent verification is successful, the SSP 920 can perform remote management on the target bundle.
[0167] If the bundling policy requires verification of the remote bundling management server, the SSP 920 can use the verification key (credential) or verification method stored in the bundling policy of the bundle specified by the transmitted remote management command to verify the bundling management server 940 that has transmitted the remote management command. For example, the bundling policy can store a public key that can be used to verify a digital signature, a digital certificate, a public key identifier (PKI) corresponding to the digital certificate or the public key of the digital certificate, a public key of a higher certificate that can verify the digital certificate, or a public key identifier corresponding to the public key of the higher certificate. The stored information can be information associated with the digital certificate for remote bundling management of the bundle, which is issued by the service provider 930 or the bundle owner to the bundling management server 940, where the bundle belongs to the service provider 930 or the bundle owner itself. In addition to the information, the bundling policy can optionally include whether bundling management server verification is required. The SSP 920 can verify the digital signature included in the received remote bundling management command according to the configuration. If the remote bundling management command is transmitted from a bundling management server for which unauthorized verification is impossible, the SSP 920 can terminate the remote bundling management.
[0168] If it is necessary to verify the remote bundling management server that has transmitted the remote bundling management command according to the bundling policy, the SSP 920 can verify according to the bundling policy whether the bundling management server 940 corresponds to a bundling management server that allows the transmission of remote management commands. If the remote bundling management command is transmitted from a bundling management server that is not permitted, the SSP 920 can terminate the remote bundling management. Even if remote bundling management is performed on a bundle that is not permitted for remote management according to the bundling policy, the SSP 920 can terminate the remote bundling management. In operation 9007, the SSP 920 can transmit the result of the remote management command to the LBA 910. In operation 9008, the LBA 910 can notify the bundling management server 940 of the result of executing the remote management command, and in operation 9009, the bundling management server 940 can notify the service provider 930 or the device manager 950 of the result of executing the remote bundling management. The result notified in operation 9009 can include a part or all of the result of executing the remote bundling management transmitted from the LBA 910 in operation 9008.
[0169] Figure 10 A diagram showing an example of configuring a bundling policy according to some embodiments.
[0170] Reference Figure 10 , the bundling policy 1010 can be expressed as a series of parameters. For ease of description, Figure 10 the bundling policy 1010 is expressed in the form of a table, but does not necessarily have a table format and can be configured by listing the parameters. It should be noted thatFigure 10 The configured values of the corresponding parameters shown are merely examples of bundling policies presented for ease of description, and the actual configured values may be different for each bundle.
[0171] The bundling policy 1010 may include a type of local management or remote management command ("command" list) 1011 received by each bundle. Each remote management command may be expressed as a string or a string of numbers indicating the corresponding command. In Figure 10 it, the local management or remote management commands are configured to express the following five: "Install", "Enable", "Disable", "Delete", and "Update Metadata". However, the types of local management or remote management commands that may be included in the command type 1011 are not limited to this, and may be extended to various other bundle management commands. In Figure 10 it, the local management or remote management commands are expressed separately, but one or more local management or remote management commands may be grouped together. For example, the commands may be divided into two types, such as "Install" and "Others (or etc.)" to separately express the commands corresponding to bundle installation and the commands corresponding to others, and all commands may also be expressed in one type (such as "All commands") without classifying the types of commands.
[0172] The bundling policy 1010 may include a "local management" configuration 1012, which indicates the detailed configuration for the local management of the corresponding command according to the classification of the command type 1011.
[0173] More specifically, the local management configuration 1012 may further include an indicator ("Allow" indicator) 1012a, which indicates whether each local management command is allowed. If the local management command of the bundle is allowed, the indicator 1012a may be expressed as a string, a string of numbers, or a logical symbol (Boolean) indicating "Yes". If the local management command of the bundle is not allowed, the indicator 1012a may be expressed as a string, a string of numbers, or a logical symbol (Boolean) indicating "No".
[0174] The local management configuration 1012 may also include an indicator ("end - user consent" indicator) 1012b, which indicates whether the execution of each local management command must require end - user consent. If the bundled local management command needs to be initiated by the end - user, the indicator 1012b may be expressed as a string, numeric string, and / or logical symbol (Boolean) indicating "required". If the bundled local management command does not need to be initiated by the user and if the terminal can initiate the command itself, the indicator 1012b may be expressed as a string, numeric string, and / or logical symbol (Boolean) indicating "not required". If, according to the configuration of the indicator 1012a that allows local management commands, the bundled local management command is not allowed, the indicator 1012b may be expressed as a string, numeric string, and / or logical symbol (Boolean) indicating "not applicable (N / A)".
[0175] The bundling policy 1010 may include a "remote management" configuration 1013, which indicates the detailed configuration for the remote management of corresponding commands according to the classification of the command type 1011.
[0176] More specifically, the remote management configuration 1013 may also include an indicator ("allowed" indicator) 1013a, which indicates whether each remote management command is allowed. If the bundled remote management command is allowed, the indicator 1013a may be expressed as a string, numeric string, or logical symbol (Boolean) indicating "yes". If the bundled remote management command is not allowed, the indicator 1013a may be expressed as a string, numeric string, or logical symbol (Boolean) indicating "no".
[0177] The remote management configuration 1013 may also include an indicator ("end - user consent" indicator) 1013b, which indicates whether the execution of each remote management command must require end - user consent. If the bundled remote management command must require user consent, the indicator 1013b may be expressed as a string, numeric string, or logical symbol (Boolean) indicating "required", and thus, if necessary, may indicate in more detail the means of verifying the user's intention. If user consent is described as "required" but no verification means are specified, or if the terminal cannot use the indicated means for user consent verification, the terminal may select any one of the available verification means. If the bundled remote management command does not require user consent, the indicator 1013b may be expressed as a string, numeric string, and / or logical symbol (Boolean) indicating "not required". If, according to the configuration of the indicator 1013a that allows remote management commands, the bundled remote management command is not allowed, the indicator 1013b may be expressed as a string, numeric string, and / or logical symbol (Boolean) indicating "not applicable (N / A)".
[0178] The remote management configuration 1013 may also optionally include an indicator ("SPBM verification" indicator) 1013c that indicates whether the execution of each remote management command must require information verification (SPBM verification) of the bundling management server that has transmitted the remote management command. The indicator may also optionally include a series of methods capable of verifying the information of the bundling management server or a verification key (credential) that can be used for the verification method. If no verification means is specified, it may indicate that verification is not required. If it is necessary to check the information of the bundling management server that has transmitted the remote management command in order to execute the bundled remote management command, the indicator 1013c may be expressed as a string and / or numeric string indicating the identifier of the bundling management server, and may include, if necessary, the identifiers of multiple bundling management servers. The bundling management server identifier may be referred to as data including at least one of the address of the bundling management server (FQDN, IP address, or URL) or the object identifier (OID) of the corresponding server. Depending on the command type 1011, the bundling management server identifier may not be included, and depending on the command type 1011, different bundling management server identifiers may be included. If it is necessary to use a digital certificate specified by the service provider or bundling owner to verify the digital signature in order to verify the bundling management server that has transmitted the remote management command to execute the bundled remote management command, the indicator 1013c may store the public key, digital certificate, public key identifier (PKID) corresponding to the digital certificate or the public key of the digital certificate, the public key of the higher certificate enabling the verification of the digital certificate, or the public key identifier corresponding to the public key of the higher certificate that can be used to verify the digital signature specified by the service provider or bundling owner. The indicator 1013c may include a shared private key (shared secret, password, symmetric key, etc.) specified by the service provider or bundling owner. The indicator 1013c may include multiple verification methods.
[0179] The remote management configuration 1013 may also include an indicator ("subscriber consent verification" indicator) 1013d that indicates whether subscriber consent verification is required for the execution of each remote management command. If subscriber consent verification is required to execute a bundled remote management command, the indicator 1013d may be expressed as a string, numeric string, or logical symbol (Boolean) indicating "required", and thus, if desired, the means of subscriber consent verification may be indicated in more detail. Various other verification means may be used, for example, verifying security information such as the subscriber's private key ("credential key" of 1013d), or verifying the subscriber's digital signature ("signature token" of 1013d) using a digital certificate. If subscriber consent verification is described as "required" but no verification means is specified, or the terminal and / or the bundled management server cannot use the indicated subscriber consent verification means, the terminal and / or the bundled management server may select any available verification means. If subscriber consent verification is not required to execute a bundled remote management command, the indicator 1013d may be expressed as a string, numeric string, and / or logical symbol (Boolean) indicating "not required". If a bundled remote management command is not allowed according to the configuration of the indicator 1013a that permits remote management commands, the indicator 1013d may be expressed as a string, numeric string, and / or logical symbol (Boolean) indicating "not applicable (N / A)".
[0180] The remote management configuration 1013 may also optionally include an indicator ("SPBM owner verification" indicator) 1013e that indicates whether verification of the entity that has requested a remote management command is required for the execution of each remote management command. If verification of the entity that has requested a bundled remote management command is required to execute the remote management command, the indicator 1013e may be expressed as a string and / or numeric string indicating the identifier of the bundle owner or manager, and may include, if necessary, the identifiers of multiple bundle owners or managers. The bundle owner identifier or the bundle manager identifier may be an object identifier (OID) of a service provider or a device manager, and may be referred to as data including at least one or more object identifiers. Depending on the command type 1011, the bundle owner identifier or the bundle manager identifier may not be included, and depending on the command type 1011, different bundle owner identifiers or bundle manager identifiers may be included.
[0181] Figure 11 A diagram showing an example of SSP remote management configured for remote bundle management according to some embodiments is shown.
[0182] Reference Figure 11 , the SSP remote management configuration 1110 may be expressed as a series of parameters. For ease of description, Figure 11The bundling policy 1110 is presented in tabular form, but is not necessarily tabular and can be configured by listing parameters. It should be noted that Figure 11 the configured values of the corresponding parameters shown in
[0183] are presented only as examples of SSP remote management configurations for ease of description, and the actual configured values can be different. The SSP remote management configuration 1110 can include 1120 identifiers that indicate the classification of the bundles installed in or to be installed in the SSP. The identifiers that indicate the classification of the bundles installed in or to be installed in each SSP can include one of the bundle family identifier, bundle family manager identifier, bundle owner identifier, or device manager identifier, and can appear in various combinations of the identifiers listed above. In Figure 11 it, the SSP remote management configuration is presented as a combination of the bundle family identifier, bundle family manager identifier, and bundle owner identifier, but can also be presented as a combination of various values that can be configured for other bundles, bundle metadata, and remote bundle management commands. For example, the SSP remote management configuration can be presented as a combination 1120a of the bundle family identifier, bundle family manager identifier, and bundle owner identifier, and this can refer to the SSP remote management configuration applied to the bundles in which a specific bundle family identifier, specific bundle family manager identifier, and specific bundle owner identifier are configured. The SSP remote management configuration can be presented as a combination 1120b of the bundle family identifier and bundle family manager identifier, and this can refer to the SSP remote management configuration applied to the bundles in which a specific bundle family identifier and bundle family manager identifier are configured, and can be a configuration applied regardless of the bundle owner identifier. The SSP remote management configuration can be presented only with the bundle family identifier 1120c, and this can refer to the SSP remote management configuration applied to the bundles in which a specific bundle family identifier is configured, and can be a configuration applied regardless of the bundle family manager identifier and bundle owner identifier. The SSP remote management configuration can be "All identifier combinations (All)" 1120d, and can refer to all bundles regardless of the identifiers configured for the bundles. The SSP remote management configuration can additionally be a configuration that includes specific remote bundle management commands.
[0184] If the execution of each remote management command must require subscriber consent verification, the SSP remote management configuration 1110 may indicate a means capable of verifying the subscriber's intent ("subscriber intent verification method" indicator) 1130. For example, if the received remote bundle management command includes the subscriber's digital signature, the means 1130 for verifying the subscriber's intent may include a public key, a digital certificate, or a public key identifier corresponding to the public key of the digital certificate that can be used to verify the digital signature, and a public key identifier (PKID) corresponding to the public key of a higher-level certificate that can verify the digital certificate. Security information (such as the subscriber's private key) and various other verification means may be specified. If no means for subscriber consent verification is specified, or the terminal and / or bundle management server cannot use the indicated means for subscriber consent verification, the terminal and / or bundle management server may select any available verification means. If no verification means is specified, it may be indicated that verification is not required.
[0185] Figure 12 A diagram showing an example of a process for configuring SSP remote management permissions between a device manager, a service provider, and a bundle management server, and between the device manager and the SSP, according to some embodiments;
[0186] Refer to Figure 12 , the device manager 1210 may issue a remote bundle management token 1250 to grant the bundle management server 1220 the permission to generate and transmit remote bundle management commands for the bundles installed in or to be installed in the terminal 1230 managed by the device manager 1210 itself. The remote bundle management token 1250 may be in the form of a digital certificate proving the remote bundle management permission, and may include a public key paired with a specific private key held by the bundle management server 1220. The remote bundle management token 1250 may selectively include at least one of the following values, based on which the bundle management server 1220 may specify remotely manageable bundles among the bundles installed in or to be installed in the terminal 1230 managed by the device manager 1210 itself.
[0187] - Bundle manageable period or remote bundle management token validity period
[0188] - Identifier of the SSP or terminal in which the bundle has been installed or is to be installed
[0189] - Bundle identifier
[0190] - Bundle family identifier
[0191] - Bundle family manager identifier
[0192] - Bundle owner identifier
[0193] - Device manager identifier
[0194] -Remote bundling management commands permitted by the bundling management server
[0195] -Whether a new remote bundling management token can be issued
[0196] The remote bundling management token 1250 may also include a digital signature of the device manager, which is generated using the private key used by the device manager 1210 when issuing the remote bundling management token 1250. The device manager 1210 may possess digital certificates 1260a and 1260b including public keys paired with the private key. The digital certificate 1260b may be issued using the private key paired with the higher digital certificate 1260a.
[0197] The bundling management server 1220 may issue other remote bundling management tokens 1250a and 1250b to other bundling management servers 1220a and 1220b by using the private key paired with the remote bundling management token 1250 issued from the device manager 1210. If the remote bundling management token 1250 is configured such that a new token cannot be issued, the bundling management server 1220 may not be able to issue a remote bundling management token. The digital certificates 1250a and 1250b may selectively include at least one value, based on which the bundling management servers 1220a and 1220b may specify remotely manageable bundles, and the value may be the same as the value specified by the device manager 1210 for the remote bundling management token 1250, or may include some of the specified values, and the two values may be different from each other.
[0198] Reference Figure 12 , the terminal 1230 may store a digital certificate or public key 1260c capable of verifying the remote bundling management token 1250 issued by the device manager 1210 and the remote bundling management tokens 1250a and 1250b issued by the bundling management server 1220. The digital certificate or public key 1260c may be the same as the digital certificates 1260a and 1260c of the device manager 1210, and may be the same as the public key included in the digital certificate. The digital certificate or public key 1260c may be one of the means capable of verifying the subscriber's intention, as Figure 11 shown.
[0199] Figure 13 A diagram showing an example of a process of generating a remote bundling management command by a bundling management server according to some embodiments.
[0200] Reference Figure 13, in operation 13001, service provider 1300 or device manager 1310 may request the bundling management server 1320 to generate a remote bundling management command. In operation 13001, service provider 1300 or device manager 1310 may request the generation of a remote bundling management command including at least one of the following request values.
[0201] - Target terminal or SSP identifier
[0202] - Target bundling identifier
[0203] - Bundling family identifier of the target bundling
[0204] - Bundling family manager identifier of the target bundling
[0205] - Bundling owner identifier of the target bundling
[0206] - Remote management command (e.g., install, enable, disable, delete, etc.)
[0207] Reference Figure 13 , in operation 13002, the bundling management server 1320 may selectively determine whether the device manager 1310 or service provider 1300 that has requested the remote bundling management command has the permission to request the remote bundling management command for the corresponding bundling. The bundling management server 1320 may select at least one of the request values transmitted by the device manager 1310 or service provider 1300 that has requested the remote bundling management command in operation 13001, and if the selected request value does not match the value configured for the bundling management server 1320, the bundling management server 1320 may refuse to generate the remote bundling management command. For example, if the bundling owner identifier of the requested target bundling does not match the device manager 1310 or service provider 1300, the device manager 1310 or service provider 1300 does not have the permission to request the requested remote management command, the bundling management server 1320 does not have the permission to generate the specific remote bundling management command for the requested target bundling, or at least one of the target bundling information (e.g., at least one of the target terminal or SSP identifier, target bundling identifier, bundling family identifier of the target bundling, bundling family manager identifier of the target bundling, and bundling owner identifier of the target bundling) does not match the requested command information, the generation of the remote bundling management command may be refused.
[0208] The bundling management server 1320 may selectively check the configuration of the bundling targeted by the requested remote bundling management command and may generate the remote bundling management command. The remote bundling management command may include at least one of the following values.
[0209] - Target bundling identifier
[0210] - Bundle family identifier for target bundling
[0211] - Bundle family manager identifier for target bundling
[0212] - Bundle owner identifier for target bundling
[0213] - Remote management commands (e.g., install, enable, disable, delete, etc.)
[0214] If the bundle is configured to require subscriber consent verification for remote bundle management commands, the bundle management server can digitally sign the remote bundle management commands by using a private key. The private key used can be the private key paired with the remote bundle management token issued by the device manager 1210 in Figure 12 , which matches the configuration of the target bundle. When selecting the private key for generating the digital signature, a choice can be made among the private keys paired with the remote bundle management tokens, where in the remote bundle management token, at least one configuration value of the bundle matches at least one of the identifier of the SSP or terminal where the bundle has been installed or is to be installed, the bundle identifier, the bundle family identifier, the bundle family manager identifier, the bundle owner identifier, the device manager identifier, and the remote bundle management commands allowed for the bundle management server. In addition to the digital signature, the subscriber consent verification value can be a verification value generated by using a shared private key previously shared between the bundle management server and the target bundle or target SSP.
[0215] If the configuration of the bundle includes a verification key (credential) or verification method specified by the service provider or bundle owner for remote bundle management commands, the bundle management server can add information that can be verified by the available verification key to the remote bundle management commands. For example, the service provider or bundle owner can perform a digital signature with a private key paired with the corresponding certificate, so that verification can be performed using the digital certificate included in the bundle policy. Information that can be verified by a shared private key (shared secret, password, symmetric key, etc.) specified by the service provider or bundle owner can be included.
[0216] In operation 13002, if it is allowed to generate digital signatures for multiple remote bundle management commands with the same private key, the bundle management server 1320 can generate one digital signature including multiple remote bundle management commands.
[0217] If the remote bundle management commands are successfully generated in operation 13002, the bundle management server 1320 can generate an identifier CodeM for the remote bundle management commands, and can store the identifier CodeM in combination with the target SSP identifier and the remote bundle management commands.
[0218] In operation 13003, the bundling management server 1320 may transmit the result (success or failure) of generating a remote bundling management command to the service provider 1300 or the device manager 1310. If the generation of the remote bundling management command is successful, the bundling management server 1320 may selectively include and transmit the identifier of the remote bundling management command.
[0219] Figure 14 A diagram showing an example of a process in which a terminal verifies and executes a remote bundling management command received from a bundling management server according to some embodiments.
[0220] Reference Figure 14 , in operation 14001, the terminal 1400 may request a remote bundling management command from the bundling management server 1430, or may receive a remote bundling management command. For this reception, the LBA 1410 of the terminal 1400 may receive the remote bundling management command by using the information of the SSP 1420. When the remote bundling management command is transmitted to the LBA 1410, the bundling management server 1430 may transmit, together with the remote bundling management command, a digital certificate that can be used to verify a digital signature for subscriber consent verification included in the remote bundling management command, or a higher certificate of the corresponding certificate. The digital certificate may be a remote bundling management token issued by the device manager to the bundling management server. A digital certificate that can be used to verify a signature for bundling management server verification included in the remote bundling management command, or a higher certificate of the corresponding certificate, may be selectively transmitted. The remote bundling management command may include at least one of an identifier of a bundle targeted for bundling management, a bundle family identifier of the target bundle, a bundle family manager identifier of the target bundle, a bundle owner identifier of the target bundle, and a remote management command type.
[0221] In operation 14002, the LBA 1410 may check the information configured for the received remote bundling management command. The LBA 1410 may compare the policy of the target bundle stored in the terminal 1400 with at least one of the target bundle identifier, the bundle family identifier of the target bundle, the bundle family manager identifier of the target bundle, the bundle owner identifier of the target bundle, and the remote management command type in the information configured for the remote bundling management command. The bundling policy may be stored in the metadata of the bundle, the SSP 1420, the LBA 1410, or the terminal 1400, and the application priority may vary according to the implementation. In operation 14002, if user consent is required before executing the remote bundling management command in the bundling policy being compared, the LBA 1410 may execute user consent.
[0222] In operation 14003, the LBA 1410 may transmit a remote bundling management command to the SSP 1420. The LBA 1420 may transmit a part or all of the remote bundling management command received from the bundling management server 1430 in operation 14001. The transmitted remote bundling management command may be a command for remote management (enable, disable, delete, information request, etc.) of a previously installed bundle or an installation command for a new bundle. A digital certificate that can be used to verify a digital signature for subscriber consent verification included in the remote bundling management command, and a higher certificate of the corresponding certificate, may be transmitted together. A digital certificate that can be used to verify a signature for bundling management server verification included in the remote bundling management command, or a higher certificate of the corresponding certificate, may be transmitted selectively.
[0223] In operation 14004, the SSP 1420 may check the policy of the target bundle. The SSP 1420 may compare the policy of the target bundle stored in the terminal 1400 with at least one of the target bundle identifier, the bundle family identifier of the target bundle, the bundle family manager identifier of the target bundle, the bundle owner identifier of the target bundle, and the remote management command type configured in the information for the remote bundling management command. The bundle policy may refer to Figure 10 the remote management configuration in the description provided in. The bundle policy may be configured for the SSP 1420 instead of the bundle metadata.
[0224] In operation 14004, if subscriber consent verification is configured to be mandatory in the execution of the remote bundling management command, the SSP 1420 may verify the subscriber consent verification value included in the remote bundling management command transmitted from the LBA 1410. The configuration may be checked via the bundle policy configured for the bundle metadata or the self-bundle policy configured for the SSP 1420.
[0225] When verifying the digital signature included in the remote bundling management command in operation 14004, as Figure 11 shown, the SSP 1420 may check the SSP remote management configuration and may select the subscriber consent verification means required for verification configured for the target bundle. The subscriber consent verification means may be configured for the bundle policy in the metadata of the bundle, and the SSP may select the subscriber consent verification means.
[0226] For example, to verify the digital signature of a subscriber for a received remote bundle management command, the SSP 1420 may select a public key, digital certificate, or public key identifier corresponding to the public key of the digital certificate that can be used to verify the digital signature, and a public key identifier (PKID) corresponding to the public key of a higher certificate that can verify the digital certificate. Based on the subscriber's consent to the verification value, security information such as the subscriber's private key and various other verification means may be selected. For the verification means, an SSP remote management configuration or bundle policy that matches at least one of the bundle identifier, bundle family identifier, bundle family manager identifier, and bundle owner / device manager identifier of the target bundle may be selected. If no verification means is specified, it may indicate that verification is not required.
[0227] When the digital signature is verified, the SSP 1420 may verify the digital certificate and its higher certificate, where the digital certificate can be used to verify the digital signature for subscriber consent verification transmitted together with the remote bundle management command. The verification valid for the digital certificate may also include verifying that at least one of the validity period, bundle identifier, bundle family identifier, bundle family manager identifier, bundle owner / device manager identifier, and allowed remote bundle management commands included in the digital certificate matches the policy of the target bundle and the SSP remote management configuration.
[0228] If the subscriber's consent verification is successful, the SSP 1420 may execute the remote bundle management command. If the verification fails, the SSP 1420 may reject the execution of the remote bundle management command.
[0229] In operation 14004, when executing a remote bundle management command, if the information verification (SPBM verification) of the bundle management server for which the remote management command has been transmitted is configured to be mandatory, the SSP 1420 may verify the bundle management server check verification value included in the remote bundle management command transmitted from the LBA 1410. The configuration may be checked via the bundle policy configured for the bundle metadata or the self-bundle policy configured for the SSP 1420.
[0230] When verifying the digital signature included in the remote bundle management command in operation 14004, as Figure 10 shown, the SSP 1420 may check the bundle policy of the target bundle and may select the verification means required for verification configured for the bundle policy.
[0231] For example, the received remote bundling management command includes a digital signature of the bundling management server, and in order to verify the digital signature, the SSP 1420 can select a public key that can be used to verify the digital signature based on the bundling policy of the target bundle, the digital certificate, or the public identifier corresponding to the public key of the digital certificate, and the public key identifier (PKID) corresponding to the public key of the higher-level certificate that can verify the digital certificate. Based on the verification value checked by the bundling management server, security information (such as a private key) and various other verification means can be selected. If no verification means is specified, it may indicate that verification is not required.
[0232] If the bundling management server successfully verifies the information, the SSP 1420 can execute the remote bundling management command. If the verification fails, the SSP 1420 can refuse to execute the remote bundling management command.
[0233] The SSP 1420 can determine whether the bundling policy of the bundle targeted by the remote bundling management command is configured to verify at least one of the end-user consent or the subscriber consent verification. If the bundling policy is configured not to verify both the end-user consent and the subscriber consent verification, the SSP 1420 can refuse to execute the remote management command. If the bundling policy is configured to verify the end-user consent or the subscriber consent verification, the SSP 1420 or the LBA 1410 can perform the configured consent verification, and if the verification is successful, the remote bundling management command can be executed.
[0234] In operation 14005, the SSP 1420 can transmit the execution result of the remote bundling management command to the LBA 1410.
[0235] Figure 15 A diagram showing the configuration of a terminal according to some embodiments is shown.
[0236] As Figure 15 shown, the terminal can include a transceiver 1510 and at least one processor 1520. The terminal can include an SSP 1530. For example, the SSP 1530 can be inserted into the terminal or can be embedded in the terminal. The at least one processor 1520 can be referred to as a controller.
[0237] However, the configuration of the terminal is not limited to Figure 15 , and can include more than Figure 15more or fewer components than those shown. According to some embodiments, the transceiver 1510, at least one processor 1520, and a memory (not shown) may be implemented in the form of a single chip. When the SSP 1530 is embedded, the configuration of the terminal may be implemented in the form of a single chip including the SSP 1530. According to some embodiments, the transceiver 1510 may transmit to and receive from a bundling management server signals, information, data, etc. according to various embodiments. The transceiver 1510 may include an RF transmitter that up-converts and amplifies the frequency of the transmitted signal, an RF receiver that amplifies the received signal with low noise and down-converts the frequency, etc. However, this is merely an embodiment of the transceiver 1510, and the components of the transceiver 1510 are not limited to the RF transmitter and the RF receiver. The transceiver 1510 may receive a signal via a wireless channel, output it to at least one processor 1520, and transmit the signal output from at least one processor 1520 via the wireless channel.
[0238] According to some embodiments, the transceiver 1510 may receive from the bundling management server the certificate of the bundling management server, CI information to be used by the SSP 1530, a bundling family identifier, a bound bundling, etc. The transceiver 1510 may transmit to the bundling management server CI information corresponding to a specific bundling family identifier, authentication information of the SSP 1530, etc.
[0239] At least one processor 1520 is an element for overall control of the terminal. According to the various embodiments described above, at least one processor 1520 may control the overall operation of the terminal.
[0240] The SSP 1530 may include a processor or a controller for installing and controlling a bundling, or an application may be installed.
[0241] According to some embodiments, at least one processor or controller in the SSP 1530 may check the certificate issuer (CI) information that may be used when downloading and installing a specific bundling corresponding to a specific bundling family identifier, and may verify at least one of the transmitted bundling management server certificate, CI information to be used by the SSP, and the bundling family identifier based on the CI information of each bundling family identifier pre-configured for the SSP 1530.
[0242] According to some embodiments, at least one processor 1520 may control the transceiver 1510 to transmit CI information corresponding to a specific bundling family identifier to the bundling management server, and may receive from the bundling management server at least one of the bundling management server certificate, CI information to be used by the smart security platform (SSP), and the bundling family identifier.
[0243] The SSP 1530 according to various embodiments may download a bundle and install the bundle. The SSP 1530 may manage the bundle.
[0244] According to some embodiments, the SSP 1530 may operate under the control of the processor 1520. Alternatively, the SSP 1530 may include a processor or a controller for installing and controlling the bundle, or may have an application installed therein. Some or all of the applications may be installed in the SSP 1530 or a memory (not shown).
[0245] The terminal may also include a memory (not shown) and may store data such as default programs, application programs, and configuration information for the operation of the terminal. The memory may include at least one storage medium among a flash type, a hard disk type, a multimedia card micro, a card type memory (e.g., SD or XD memory, etc.), a magnetic memory, a magnetic disk, an optical disk, a random access memory (RAM), a static random access memory (SRAM), a read only memory (ROM), a programmable read only memory (PROM), and an electrically erasable programmable read only memory (EEPROM). The processor 1520 may perform various operations by using various programs, contents, data, etc. stored in the memory.
[0246] Figure 16 A diagram showing a configuration of a bundle management server according to some embodiments is shown.
[0247] According to some embodiments, the bundle management server may include a transceiver 1610 and at least one processor 1620. The configuration of the bundle management server is not limited to Figure 16 and may include more or fewer elements than those shown in Figure 16 . According to some embodiments, the transceiver 1610, the at least one processor 1620, and a memory (not shown) may be implemented in the form of a single chip.
[0248] According to some embodiments, the transceiver 1610 may send to and receive from a terminal, a subscriber, or a service provider signals, information, data, etc. according to various embodiments. For example, the transceiver 1610 may receive SSP authentication information, certificate information corresponding to a bundle family manager identifier and a bundle family identifier or a specific bundle family identifier, etc. from the terminal, and may send a certificate of the bundle management server, certificate information to be used by the SSP, a bundle family identifier, a bound bundle, etc. to the terminal.
[0249] The transceiver 1610 may include an RF transmitter that up-converts and amplifies the frequency of the transmitted signal, an RF receiver that amplifies the received signal with low noise and down-converts the frequency, and the like. However, this is merely an example of the transceiver 1610, and the elements of the transceiver 1610 are not limited to the RF transmitter and the RF receiver. The transceiver 1610 may receive a signal via a wireless channel, output it to at least one processor 1620, and transmit the signal output from at least one processor 1620 via the wireless channel.
[0250] At least one processor 1620 is an element for overall control of the bundling management server. According to various embodiments described above, the processor 1620 may control the overall operation of the bundling management server. At least one processor 1620 may be referred to as a controller.
[0251] According to some embodiments, at least one processor 1620 may select a certificate of the bundling management server to be sent to a terminal and certificate information to be used by the SSP of the terminal, may verify the authentication information (SSP credential) of the SSP of the terminal, and may generate an SPBMToken and a binding bundle.
[0252] According to some embodiments, at least one processor 1620 may send a certificate of the bundling management server, certificate information to be used by the SSP, a bundling family identifier, a binding bundle, etc. to the terminal, and may control the transceiver 1610 to receive certificate information, authentication information of the SSP, etc. corresponding to a specific bundling family identifier from the terminal.
[0253] The bundling management server may further include a memory (not shown), and may store data such as default programs, application programs, and configuration information for the operation of the bundling management server. The memory may include at least one storage medium among a flash type, a hard disk type, a multimedia card micro, a card type memory (e.g., SD or XD memory, etc.), a magnetic memory, a magnetic disk, an optical disk, a random access memory (RAM), a static random access memory (SRAM), a read only memory (ROM), a programmable read only memory (PROM), and an electrically erasable programmable read only memory (EEPROM). The processor 1620 may perform various operations by using various programs, contents, data, etc. stored in the memory.
[0254] In the above detailed embodiments of the present disclosure, according to the presented detailed embodiments, the elements included in the present disclosure are expressed in singular or plural forms. However, for ease of description, the singular form or the plural form is appropriately selected for the presented situation, and the present disclosure is not limited to the elements expressed in singular or plural forms. Therefore, the elements expressed in plural forms may also include a single element, or the elements expressed in singular form may also include multiple elements.
[0255] Although specific embodiments have been described in the detailed description of the present disclosure, various modifications and changes can be made thereto without departing from the scope of the present disclosure. Therefore, the scope of the present disclosure should not be defined as limited to the embodiments, but should be defined by the appended claims and their equivalents.
[0256] It should be understood that the various embodiments of the present disclosure and the terms used therein are not intended to limit the technical features set forth herein to a specific embodiment, and include various changes, equivalents, and / or alternatives of the corresponding embodiments. Regarding the description of the drawings, like reference numerals may be used to designate like or related elements. It should be understood that the singular form of a noun corresponding to an item may include one or more things, unless the relevant context clearly indicates otherwise. As used herein, each of the phrases such as "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" may include all possible combinations of the items listed together in the corresponding phrase. As used herein, terms such as "first", "second", "the first", and "the second" may be used simply to distinguish the corresponding element from another element, and do not limit the element in other respects (e.g., importance or order). It should be understood that if an element (e.g., a first element) is referred to as "coupled to another element (e.g., a second element)", "coupled to the other element", "connected to another element", or "connected to the other element", whether or not there is the term "operably" or "communicatively", this means that the element can be directly (e.g., wired), wirelessly, or via another element (e.g., a third element) coupled to the other element.
[0257] As used herein, the term "module" may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with other terms (e.g., "logic", "logic block", "component", or "circuit"). A "module" may be the smallest unit of a single integrated component adapted to perform one or more functions, or a part thereof. For example, according to an embodiment, a "module" may be implemented in the form of an application specific integrated circuit (ASIC).
[0258] The various embodiments described herein may be implemented as software (e.g., a program) including instructions stored in a machine-readable storage medium (e.g., internal memory or external memory) readable by a machine (e.g., a computer). A machine is a device that can call the stored instructions from the storage medium and operate according to the called instructions, and may include a terminal 250 according to various embodiments. When the instructions are executed by a processor (e.g., Figure 8 the processor 820 in Figure 9When executed by a processor 920) in [ ], the processor may perform functions corresponding to the instructions with or without using other components under the control of the processor. The instructions may include code generated by a compiler or code executable by an interpreter.
[0259] The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Herein, the term "non-transitory" merely means that the storage medium is a tangible device and does not include signals (e.g., electromagnetic waves), but this term does not distinguish where data is stored semi-permanently in the storage medium and where data is temporarily stored in the storage medium.
[0260] The methods according to various embodiments of the present disclosure may be included and provided in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., a compact disc read-only memory (CD-ROM)), or distributed online (e.g., downloaded or uploaded) via an app store (e.g., Play StoreTM), or directly distributed between two user devices (e.g., a smart phone). If distributed online, at least a part of the computer program product may be generated temporarily or stored at least temporarily in a machine-readable storage medium (such as the memory of a manufacturer's server, the server of an app store, or a relay server).
[0261] According to various embodiments, each of the above elements (e.g., a module or a program) may include a single entity or multiple entities. According to various embodiments, one or more of the above elements may be omitted, or one or more other elements may be added. Alternatively or additionally, multiple elements (e.g., modules or programs) may be integrated into a single element. In this case, according to various embodiments, the integrated element may still perform the one or more functions in the same or similar manner as one or more functions of each of the multiple elements were performed by a corresponding element of one of the multiple elements before integration. According to various embodiments, the operations performed by a module, a program, or another element may be performed sequentially, in parallel, repeatedly, or heuristically, or one or more of the operations may be performed in a different order or omitted, or one or more other operations may be added.
[0262] Although the present disclosure has been described with various embodiments, those skilled in the art can conceive of various changes and modifications. The present disclosure is intended to embrace such changes and modifications that fall within the scope of the appended claims.
Claims
1. A method performed by a Local Binding Assistant (LBA) included in a terminal in a wireless communication system, the method comprising: Receiving a remote binding management command from a server; Verifying a first binding policy based on the remote binding management command; Sending the remote binding management command to a Secondary Platform Bundle Loader (SPBL) included in the terminal; and Receiving an execution result of the remote binding management command from the SPBL, wherein a second binding policy is verified by the SPBL based on the remote binding management command, and wherein, after the first binding policy and the second binding policy are verified, the remote binding management command is executed by the terminal.
2. The method according to claim 1, wherein the remote binding management command includes at least one of information on server verification, information on user consent, or information on subscriber consent.
3. The method according to claim 1, wherein the SPBL verifies the authorization of the server based on the remote binding management command.
4. The method according to claim 1, wherein verifying the first binding policy includes verifying user consent.
5. The method according to claim 1, wherein verifying the second binding policy includes verifying subscriber consent.
6. A method performed by a Secondary Platform Bundle Loader (SPBL) included in a terminal in a wireless communication system, the method comprising: Receiving a remote binding management command from a Local Binding Assistant (LBA) included in the terminal; Verifying a second binding policy based on the remote binding management command; and Sending an execution result of the remote binding management command to the LBA, wherein the remote binding management command is sent from a server to the LBA, wherein a first binding policy is verified by the LBA based on the remote binding management command, and wherein, after the first binding policy and the second binding policy are verified, the remote binding management command is executed by the terminal.
7. The method according to claim 6, wherein the remote binding management command includes at least one of information on server verification, information on user consent, or information on subscriber consent.
8. The method according to claim 6, further comprising: Verifying the authorization of the server based on the remote binding management command.
9. The method according to claim 6, wherein verifying the first binding policy includes verifying user consent.
10. The method according to claim 6, wherein verifying the second binding policy includes verifying subscriber consent.
11. A Local Binding Assistant (LBA) included in a terminal, the LBA comprising: A transceiver capable of sending or receiving at least one signal, and A controller coupled to the transceiver, wherein the controller is configured to: Receive a remote binding management command from a server, Verify a first binding policy based on the remote binding management command, Send the remote binding management command to a Secondary Platform Bundle Loader (SPBL) included in the terminal, and Receive an execution result of the remote binding management command from the SPBL, Among them, the second bundling strategy is verified by the SPBL based on the remote bundling management command, and Among them, after the first bundling strategy and the second bundling strategy are verified, the remote bundling management command is executed by the terminal.
12. The LBA according to claim 11, wherein, the remote bundling management command includes at least one of information about server verification, information about user consent verification, or information about subscriber consent.
13. The LBA according to claim 11, wherein, the SPBL verifies the authorization of the server based on the remote bundling management command.
14. The LBA according to claim 11, wherein, the controller is configured such that the verification of the first bundling strategy includes verifying user consent.
15. The LBA according to claim 11, wherein, the verification of the second bundling strategy includes verifying subscriber consent.
16. A secondary platform bundling loader SPBL included in a terminal, the SPBL comprises: a transceiver capable of sending or receiving at least one signal, and a controller coupled to the transceiver, wherein the controller is configured to: receive a remote bundling management command from a local bundling assistant LBA included in the terminal, verify a second bundling strategy based on the remote bundling management command, and send an execution result of the remote bundling management command to the LBA, wherein the remote bundling management command is sent from a server to the LBA, wherein a first bundling strategy is verified by the LBA based on the remote bundling management command, and wherein after the first bundling strategy and the second bundling strategy are verified, the remote bundling management command is executed by the terminal.
17. The SPBL according to claim 16, wherein, the remote bundling management command includes at least one of information about server verification, information about user consent, or information about subscriber consent.
18. The SPBL according to claim 16, wherein, the controller is further configured to verify the authorization of the server based on the remote bundling management command.
19. The SPBL according to claim 16, wherein, the verification of the first bundling strategy is configured to verify user consent.
20. The SPBL according to claim 16, wherein, the controller is configured such that the verification of the second bundling strategy includes verifying subscriber consent.