Terminal profile generation
By generating data transmission profiles through an automated system, the problem of intensive human-computer interaction in existing technologies is solved, enabling rapid generation and updating of profiles and improving data transmission efficiency and authentication speed.
Patent Information
- Application Number
- CN202480047459.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-07-17
- Filing Date
- 2024-07-11
- Publication Date
- 2026-02-13
AI Technical Summary
In existing technologies, the process of generating data transmission profiles requires a lot of human-computer interaction, resulting in low efficiency and untimely updates to the profiles.
An automated system generates profiles by receiving data files and feature definitions, performing verification, signing, and certificate chain generation, and automatically generating kernel profiles for data transmission, supporting applications such as financial transactions.
It automates and rapidly updates profile generation, improves data transfer efficiency, and supports rapid authentication and profile testing and download.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims priority to U.S. non-provisional application No. 18 / 353,802, filed July 17, 2023, entitled “Terminal Profile Generation,” the disclosure of which is incorporated herein by reference in its entirety for all purposes. Background Technology
[0003] Computer terminals have evolved to support data transfer between accounts. Specifically, a computer terminal can facilitate data transfer between accounts associated with the terminal. The terminal can interact with a service provider that manages one or more accounts in the account, and data transfer will occur between these accounts. The service provider can define restrictions on data transfer using profiles. Specifically, the profile can be associated with a kernel operating on the terminal that facilitates data transfer between accounts, where the profile defines the restrictions on data transfer. In traditional methods, generating these profiles is a manual, intensive process that requires personal input to produce the profiles. Attached Figure Description
[0004] Figure 1 Exemplary system arrangements based on some implementation schemes are illustrated.
[0005] Figure 2 Exemplary processes according to some implementation schemes are illustrated.
[0006] Figure 3 The first part of a flowchart illustrating an exemplary process according to some implementation schemes is shown.
[0007] Figure 4 Examples are given based on some implementation schemes. Figure 3 The second part of the flowchart of an exemplary process.
[0008] Figure 5 Examples are given based on some implementation schemes. Figure 3 The third part of the flowchart of an exemplary process.
[0009] Figure 6 An exemplary process for generating a profile is illustrated according to some implementation schemes.
[0010] Figure 7 Exemplary user equipment (UE) according to some implementation schemes are illustrated.
[0011] Figure 8 It is achievable based on some implementation schemes. Figures 1 to 6 A block diagram of an exemplary computing device for the features and processes of [the device].
[0012] Figure 9 Exemplary architectures or environments are illustrated according to some implementation schemes, which are configured to implement the technologies described herein. Detailed Implementation
[0013] The following detailed description refers to the accompanying drawings. The same reference numerals may be used to identify the same or similar elements in different drawings. In the following description, specific details, such as particular structures, architectures, interfaces, technologies, etc., are set forth for illustrative and not limiting purposes in order to provide a thorough understanding of various aspects of the various embodiments. However, it will be apparent to those skilled in the art, who benefit from this disclosure, that various aspects of the various embodiments may be practiced in other examples departing from these specific details. In some cases, descriptions of well-known devices, circuits, and methods have been omitted so as not to obscure the description of the various embodiments with unnecessary detail.
[0014] The implementation described herein may involve a process for generating a profile of the kernel to be used for data transfer. Specifically, profile generation can be automated, allowing for little or no human interaction in profile generation. Automated processes for profile generation can be executed faster than traditional methods involving human interaction. Furthermore, in some cases, profiles may require authentication, where automated processes for profile generation can provide faster updates, potentially leading to faster authentication than traditional methods.
[0015] The embodiments described herein may include a system that generates a profile to be used for data transfer. Specifically, the system can generate a profile that can be assigned to a kernel used to perform the data transfer. The system can receive a request to generate a profile, which includes definitions of characteristics of the profile to be generated by the system. In this embodiment, the definition of the characteristics may be received as a data file providing the defined characteristics of the profile. The system can perform validation operations on the data file and / or the definition of the characteristics to verify that the request for the profile is valid and / or authorized for execution.
[0016] The system can utilize the definition of data files and / or characteristics to generate binary files indicating those characteristics. To indicate the validity of the binary file, the system can sign it. The system can generate one or more key and / or certificate chains, using these chains to sign the binary file. The system can then use the key and / or certificate chains to sign the binary file to produce a profile, which is the signed binary file. The system can make the profile available for testing and / or downloadable to a terminal for data transfer. In some implementations, data transfer may include financial transactions, where the terminal can exchange value between accounts associated with the terminal.
[0017] Figure 1 An exemplary system arrangement 100 according to some implementations is illustrated. System arrangement 100 may implement a method for generating a kernel profile for use in automating data transfers. For example, in some implementations, the profile may be assigned to a kernel that can be used in a point-of-sale (POS) device and / or a device acting as a POS for making payment transactions involving at least two accounts. System arrangement 100 may be able to generate profiles for testing and / or production implementations. System arrangement 100 or parts thereof may provide the profile to terminals for implementation.
[0018] System setup 100 may include partner device 102. Partner device 102 may be a computer device associated with a service provider. The service provider may use partner device 102 to access other components within system setup 100 to request the generation of a profile for the service provider. In some cases, partner device 102 may store and / or be used to generate data files used to generate the profile. In some embodiments, the data file may be a YAML file.
[0019] System deployment 100 may include a service provider interface device 104. Service provider interface device 104 may host a portal accessible by partner devices (such as partner device 102). The portal hosted by service provider interface device 104 provides an interface that allows partner device 102 to upload data files used to generate profiles, define properties used to generate data files, and / or copy and modify data files from previously generated profiles. Partner device 102 may establish a connection with service provider interface device 104.
[0020] Service provider interface device 104 can convert data files into other files used for generating profiles and / or verifying data files. For example, service provider interface device 104 can convert data files into intermediate files. In some implementations, intermediate files can be used for data file verification.
[0021] Service provider interface device 104 can verify received data files (either uploaded, generated, or copied and modified). For example, service provider interface device 104 can verify that the profile corresponding to the data file was authorized for generation, and / or that the data file has the correct format and / or acceptable characteristics. In some implementations, service provider interface device 104 can verify that the format of entries within the data file is correct. Furthermore, service provider interface device 104 can verify that the values within the data file are acceptable and / or that the dependencies between values within the data file are acceptable.
[0022] System deployment 100 may include a TEST profile manager 106. The TEST profile manager 106 may be coupled to a service provider interface device 104 and may receive intermediate files from the service provider interface device 104. The TEST profile manager 106 may convert the intermediate files into binary files to be used for profiles. The binary files may define profile characteristics and / or may include information from data files. In some implementations, characteristics may include the maximum value to be transferred between accounts by a kernel associated with the profile, the kernel to which the profile can be assigned, the payment card that can utilize the profile, or other restrictions related to the profile's use.
[0023] TEST profile manager 106 can generate one or more keys for signing binary files to produce profiles. In some embodiments, the one or more keys generated by TEST profile manager 106 may include a public key and a private key to be used for signing the binary file. In some embodiments, the one or more keys generated by TEST profile manager 106 may be specific to TEST profile manager 106.
[0024] TEST profile manager 106 can generate a certificate signing request (CSR) to request a certificate chain for the profile. The CSR may include one or more keys generated by TEST profile manager 106. For example, TEST profile manager 106 may generate a CSR based on one or more keys generated by TEST profile manager 106. The CSR may include a public key generated by TEST profile manager 106.
[0025] System deployment 100 may include a Public Key Infrastructure (PKI) 108. PKI 108 can generate a certificate chain for profiles. PKI 108 can be coupled to a TEST Profile Manager 106 and can receive CSRs from the TEST Profile Manager 106. PKI 108 can generate a certificate chain for generating profiles with data files. PKI 108 can generate the certificate chain using CSRs with one or more keys available to PKI 108. The certificate chain generated by PKI 108 based on the CSRs received from the TEST Profile Manager 106 may include one or more certificates corresponding to PKI 108 and / or one or more certificates corresponding to the TEST Profile Manager 106. PKI 108 can provide the generated certificate chain to the TEST Profile Manager 106.
[0026] TEST profile manager 106 can receive a certificate chain from PKI 108. TEST profile manager 106 can generate profiles using the received certificate chain and binary files. For example, TEST profile manager 106 can use the certificate chain to sign the profile. System layout 100 may include a TEST database 110 for storing profiles associated with TEST profile manager 106. TEST profile manager 106 can store the generated profiles in TEST database 110. TEST profile manager 106 can store profiles associated with profile identifiers (IDs). Profile IDs can be used to identify profiles. TEST profile manager 106 can assign profile IDs to profiles. In some implementations, TEST profile manager 106 may store a data file and / or binary file corresponding to the profile along with the profile.
[0027] Once a profile has been generated, the TEST profile manager 106 can provide the profile ID to the service provider interface device 104 and indicate that the profile ID is associated with the generated profile. The service provider interface device 104 can forward the profile ID to the partner device 102. The profile ID can be presented to the users of the partner device 102, and the users of the partner device 102 can use the profile ID to refer to the generated profile.
[0028] A terminal (such as first terminal 112) can establish a connection with TEST profile manager 106 to retrieve profiles from TEST profile manager 106. For example, first terminal 112 can provide a request for a profile to TEST profile manager 106. The request may include a profile ID corresponding to the requested profile. TEST profile manager 106 can verify that first terminal 112 is authorized to retrieve the requested profile. TEST profile manager 106 can provide limited access to specific terminals. For example, TEST profile manager 106 can restrict access to terminals authorized to test profiles, which may include terminals authorized by the service provider. If TEST profile manager 106 determines that first terminal 112 is authorized to access the requested profile, TEST profile manager 106 can determine whether the profile is stored in TEST database 110, and if it determines that the profile is stored in TEST database 110, retrieve the profile from TEST database 110. The TEST profile manager 106 can provide the retrieved profile to the first terminal 112 based on a request received from the first terminal 112.
[0029] Service provider interface device 104 can also receive requests from partner device 102 to upgrade a profile to production (PROD). Specifically, partner device 102 can transmit a request to upgrade a previously generated TEST profile to a PROD profile. The profile upgrade request may include a profile ID corresponding to the profile to be upgraded. Service provider interface device 104 can use the profile ID to identify the profile to be upgraded. Service provider interface device 104 can retrieve data files and / or intermediate files corresponding to the profile to be upgraded based on the request.
[0030] System deployment 100 may include a PROD profile manager 114. A service provider interface device 104 may provide intermediate files corresponding to the profile to be promoted to the PROD profile manager 114. Specifically, the PROD profile manager 114 may be coupled to the service provider interface device 104 and may receive intermediate files from the service provider interface device 104. The PROD profile manager 114 may convert the intermediate files into binary files to be used for the profile.
[0031] PROD profile manager 114 can generate one or more keys for signing binary files to produce profiles. The one or more keys generated by PROD profile manager 114 may differ from the one or more keys generated by TEST profile manager 106. In some embodiments, the one or more keys generated by PROD profile manager 114 may include a public key and a private key to be used for signing the binary file. In some embodiments, the one or more keys generated by PROD profile manager 114 may be specific to PROD profile manager 114.
[0032] PROD Profile Manager 114 can generate a Certificate Signature (CSR) to request a certificate chain for the profile. The CSR may include a public key generated by PROD Profile Manager 114. PROD Profile Manager 114 can generate the CSR based on the public key generated by PROD Profile Manager 114.
[0033] PROD Profile Manager 114 can provide a Certificate Signature (CSR) to PKI 108. Specifically, PKI 108 can be coupled to PROD Profile Manager 114 and can receive CSRs from PROD Profile Manager 114. PKI 108 can generate a certificate chain for generating a profile with data files. The certificate chain generated by PKI 108 based on the CSR received from PROD Profile Manager 114 may include one or more certificates corresponding to PKI 108 and / or one or more certificates corresponding to PROD Profile Manager 114. The certificate chain generated for PROD Profile Manager 114 may differ from the certificate chain generated by TEST Profile Manager 106 for the same binary file. PKI 108 can provide the generated certificate chain to PROD Profile Manager 114.
[0034] PROD Profile Manager 114 can receive a certificate chain from PKI 108. PROD Profile Manager 114 can use the received certificate chain and binary file to generate a profile. For example, PROD Profile Manager 114 can use the certificate chain to sign the profile. System layout 100 may include a PROD database 116 for storing profiles associated with PROD Profile Manager 114. PROD Profile Manager 114 can store the generated profiles in PROD database 116. PROD Profile Manager 114 can store profiles associated with profile IDs. Profile IDs can be used to identify profiles. In some embodiments, the profile ID may be the same as the profile ID used by TEST Profile Manager 106 for the profile. In other embodiments, the profile ID may be different from the profile ID used by TEST Profile Manager 106, and PROD Profile Manager 114 may assign the profile ID to the profile. In some implementations, the PROD profile manager 114 may store data files and / or binary files corresponding to the profile together with the profile.
[0035] Once a profile has been generated, the PROD profile manager 114 can provide the profile ID to the service provider interface device 104 and indicate that the profile ID is associated with the generated profile. The service provider interface device 104 can forward the profile ID to the partner device 102. The profile ID can be presented to the user of the partner device 102, and the user of the partner device 102 can use the profile ID to refer to the generated profile.
[0036] A terminal (such as a second terminal 118) can establish a connection with the PROD Profile Manager 114 to retrieve a profile from the PROD Profile Manager 114. For example, the second terminal 118 can provide a request for a profile to the PROD Profile Manager 114. The request may include a profile ID corresponding to the requested profile. The PROD Profile Manager 114 can verify that the second terminal 118 is authorized to retrieve the requested profile. The PROD Profile Manager 114 can provide extended access to more terminals than those provided to the TEST Profile Manager 106. For example, the PROD Profile Manager 114 can provide access to client terminals authorized by the service provider, which may be more terminals than those authorized to access the TEST Profile Manager 106. If the PROD Profile Manager 114 determines that the second terminal 118 is authorized to access the requested profile, the PROD Profile Manager 114 can determine whether the profile is stored in the PROD Database 116, and if it is determined that the profile is stored in the PROD Database 116, retrieve the profile from the PROD Database 116. PROD profile manager 114 can provide the retrieved profile to the second terminal 118 based on a request received from the second terminal 118.
[0037] In other embodiments, system arrangement 100 may include a single profile manager and a single database, instead of two profile managers and two databases. In these embodiments, the single profile manager may perform the features of TEST profile manager 106, PROD profile manager 114, or both. Furthermore, the single database may perform the features of TEST database 110, PROD database 116, or both.
[0038] Figure 2 An exemplary process 200 according to some implementation schemes is illustrated. For example, process 200 may be performed by a system, such as system arrangement 100 (… Figure 1 The system is represented by ). Procedure 200 can be executed to generate a kernel profile to be used for data transfer.
[0039] In 202, process 200 may include receiving profile data. For example, a partner device (such as partner device 102) Figure 1 The profile data can be provided to the service provider interface device (such as service provider interface device 104). Figure 1 Providing profile data may include providing a data file containing the profile data, providing characteristics for generating the data file, and / or indicating previously generated profiles to be used to generate the data file. In some implementations, the data file may be a YAML data file.
[0040] In step 204, process 200 may include verifying the profile data. For example, the service provider interface device may verify that the profile data has correctly formatted entries, acceptable values, and / or dependencies between acceptable values. In some implementations, the service provider interface device may perform a verification process on a data file corresponding to the profile data and / or generate an intermediate file corresponding to the data file to perform the verification process.
[0041] In step 206, process 200 may include creating a key for the TEST profile. For example, the service provider interface device may generate an intermediate file from a data file. The service provider interface device may then provide the intermediate file to a TEST profile manager (such as TEST profile manager 106). Figure 1 The TEST profile manager can use intermediate files to generate binary files corresponding to the data files. The TEST profile manager can generate one or more keys to be used to generate the requested TEST profile. In some implementations, one or more keys may correspond to the TEST profile manager.
[0042] In step 208, process 200 may include transmitting a CSR to generate a signed certificate for the TEST profile. For example, a TEST profile manager may generate a CSR. The CSR may include one or more keys generated by the TEST profile manager. In some implementations, the CSR may include a public key generated by the TEST profile manager for the TEST profile. The TEST profile manager may send the certificate to a PKI (such as PKI 108). Figure 1 The PKI can transmit the CSR. It can generate a certificate chain for creating a profile. The PKI can use the CSR and / or one or more keys available to the PKI to generate the certificate chain. The PKI can then provide the certificate chain to the TEST profile manager.
[0043] In step 210, process 200 may include storing a TEST profile. For example, a TEST profile manager may generate a TEST profile using a certificate chain and binary file received from a PKI. In some implementations, the TEST profile manager may use the certificate chain to sign the TEST profile. The TEST profile manager may store the TEST profile in a TEST database (such as TEST database 110). Figure 1 ))middle.
[0044] In step 212, process 200 may include transmitting a success / failure indication. For example, the TEST profile manager may transmit a success / failure indication to the service provider interface device based on whether the TEST profile was successfully generated and stored. The success / failure indication may indicate that the TEST profile was successfully generated based on a TEST profile that was generated and stored in the TEST database. The success / failure indication may indicate that the generation of the TEST profile failed based on a TEST profile that was not generated and / or stored in the TEST database.
[0045] In step 214, process 200 may include receiving an upgrade request for PROD. For example, a service provider interface device may receive an upgrade request to upgrade a profile from TEST to PROD. The upgrade request may include a profile ID indicating the profile to be upgraded. The service provider interface device may determine the profile to be upgraded based on the upgrade request.
[0046] In 216, process 200 may include transmitting profile data to a PROD profile manager. For example, a service provider interface device may transmit profile data to a PROD profile manager (such as PROD profile manager 114). Figure 1 The process involves transmitting profile data corresponding to the TEST profile to be promoted. Transmitting the profile data may include sending a data file containing the profile data to the PROD Profile Manager and / or sending an intermediate file corresponding to the profile data to the PROD Profile Manager. In some implementations, the data file may be a YAML data file. The PROD Profile Manager may use the intermediate file to generate a binary file corresponding to the data file.
[0047] In step 218, process 200 may include transmitting a CSR to generate a signed certificate for the PROD profile. For example, a PROD profile manager may generate one or more keys to be used to generate the PROD profile. In some implementations, the one or more keys may correspond to the PROD profile manager. The one or more keys generated by the PROD profile manager may be different from the one or more keys generated by the TEST profile manager.
[0048] The PROD Profile Manager can generate a Certificate Signature (CSR) for generating a PROD profile. The CSR may include one or more keys generated by the PROD Profile Manager. In some implementations, the CSR may include a public key generated by the PROD Profile Manager for the PROD profile. The PROD Profile Manager can transmit the CSR to the PKI. The PKI can generate a certificate chain for generating the profile. The certificate chain generated for the PROD Profile Manager may differ from the certificate chain generated for the TEST Profile Manager. The PKI can provide the certificate chain to the PROD Profile Manager.
[0049] In 220, process 200 may include storing a PROD profile. For example, a PROD profile manager may generate a PROD profile using a certificate chain and binary file received from a PKI. In some implementations, the PROD profile manager may use the certificate chain to sign the PROD profile. The PROD profile manager may store the PROD profile in a PROD database (such as PROD database 116). Figure 1 ))middle.
[0050] In 222, process 200 may include transmitting a success / failure indication. For example, the PROD profile manager may transmit a success / failure indication to the service provider interface device based on whether the PROD profile was successfully generated and stored. The success / failure indication may indicate that the PROD profile was successfully generated based on the PROD profile that was generated and stored in the PROD database. The success / failure indication may indicate that the generation of the PROD profile failed based on the PROD profile that was not generated and / or stored in the PROD database.
[0051] Figures 3 to 5 A flowchart illustrating an exemplary process 300 according to some implementation schemes is shown. For example, Figure 3 The first part of a flowchart of an exemplary process 300 according to some implementation schemes is illustrated. Figure 4 The second part of a flowchart illustrating an exemplary process 300 according to some implementation schemes is shown. Figure 5 The third part of a flowchart illustrating an exemplary process 300 according to some implementation schemes is shown. Process 300 can be performed by a system, such as system arrangement 100 (… Figure 1 The system is represented by ). Procedure 300 can be executed to generate a kernel profile to be used for data transfer.
[0052] Process 300 can begin at 302. At 302, the service provider can access a portal for requesting the generation of a profile. The portal can be an application with limited access, such as requiring a user to log in for use. The service provider can access this portal via a partner device (such as partner device 102). Figure 1 Access portal. The portal can be accessed via service provider interface devices (such as service provider interface device 104). Figure 1 Hosting. The portal can provide service providers with one or more operations for defining profile configurations. Profile configurations can define the characteristics of the profile to be generated. Characteristics may include the maximum value to be transferred between accounts by the kernel associated with the profile, the kernel to which the profile can be assigned, the payment card that can be used with the profile, or other restrictions related to the profile's usage.
[0053] In some implementations, the operations used to define the configuration of a profile presented by the portal may include cloning and modifying a previously generated profile to define the configuration, uploading a data file to define the configuration, or input entries (such as in an application presented by the portal) to define the configuration. The service provider may select the operations used to define the configuration. The portal may determine the service provider's selection for the operations used to define the configuration and thus proceed. For example, the portal may determine whether the service provider has selected to clone a previously generated profile in 304. If the portal determines in 304 that the service provider has not selected to clone a previously generated profile, the portal may determine in 306 whether the service provider has selected to upload a data file. If the portal determines in 306 that the service provider has not selected to upload a data file, the portal may determine that the service provider has selected input entries to define the profile's configuration. While the order of these determinations is described in the current implementation, it should be understood that in other implementations, the order of determination and / or default determination may differ.
[0054] If the portal determines in 304 that the service provider chose to clone a previously generated profile, the portal can identify the previously generated profile in 308 based on information provided by the service provider (such as the profile ID and / or selection from service providers of available previously generated profiles). Furthermore, in 308, the portal can also identify the profile from a database (such as TEST database 110). Figure 1 ) and / or PROD database 116 ( Figure 1 The portal retrieves data related to a previously generated profile (such as the previously generated profile, a data file corresponding to the previously generated profile, and / or a binary file corresponding to the previously generated profile). The portal can generate a copy of the retrieved data. The portal can present an interface to the service provider displaying entries of the configuration corresponding to the copy of the retrieved data, where the service provider can edit the entries. Once the service provider indicates that the editing of the entries is complete, the portal can generate a data file based on the entries, which can be used to generate a new profile. In some implementations, the data file can be a YAML file.
[0055] If the portal determines in step 306 that the service provider has chosen to upload a file, then the portal can present an interface in step 310 allowing the service provider to upload the file. In step 310, the service provider can upload a profile data file. The portal can use the profile data file as the data file for generating the profile, or it can generate a data file to be used for generating the profile based on the profile data file. In some implementations, the data file can be a YAML file. Where the format of the profile data file uploaded by the service provider differs from the format to be used for generating the profile, the portal can convert the profile data file to the format to be used for generating the profile.
[0056] If the portal determines that the service provider has selected input entries, then in step 312, the portal may present the service provider with an interface that allows the service provider to input root-level settings. The service provider can input entries into the interface to define the configuration of the profile to be generated. In some implementations, the entries may include a country code and / or a Hardware Security Module (HSM) key ID. In step 314, the portal may also allow the service provider to select the kernels and / or Payment Network Operators (PNOs) to which profiles can be assigned. In step 316, the portal may determine whether the service provider has indicated that more kernels and / or PNOs should be assigned profiles. If the portal determines in step 316 that the service provider has indicated that more kernels and / or more PNOs should be assigned, then the portal may return to step 314. If the portal determines in step 316 that the service provider has indicated that the indicated kernels and / or PNOs are complete, then the portal may generate a data file based on the root-level settings entries and / or the indicated kernels and / or PNOs.
[0057] In 318, process 300 can continue with the data files generated and / or received by the portal. Process 300 can proceed from 318 to 320. Figure 3 320 can advance to Figure 4 320.
[0058] Process 300 can proceed from 320 to 402. In 402, a data file editor can be presented to edit profile fields within the data file. In some implementations, the data file editor can be a YAML editor. The data file editor allows the user to modify fields within the data file.
[0059] In 404, the system can determine whether the data file will be submitted for viewing. For example, the user can instruct whether a data file generated by the data file editor in 402 will be submitted for viewing. The system can determine where the user has indicated that the data file will be submitted for viewing. If the system determines that the data will not be submitted for viewing, the system can determine in 406 whether the data file will be discarded, such as by asking the user whether the data file should be discarded. If the system determines that the data file will be discarded, process 300 can proceed from 406 to 306 via 408, where the system can determine whether the service provider has selected the option to upload the profile data file to generate a profile. If the system determines that the profile will not be discarded, process 300 can proceed from 406 to 402, where the data file is presented in the data file editor for editing.
[0060] If the system determines in 404 that the data file will be submitted for viewing, the process can proceed to 410. In 410, the profile's status can be changed to "Viewing". For example, a data file can be changed to a "Viewing" status. A data file changed to a "Viewing" status indicates that data will be viewed.
[0061] In section 412, tasks can be created for viewing data files. For example, a task can be created where the system will view a data file and / or a user will view a data file. In the case where a user will view a data file, the task being created can enable notifications to be sent to the user.
[0062] Process 300 can proceed from 412 to 414. Figure 4 414 can proceed to Figure 5 414.
[0063] Process 300 can proceed from 414 to 502. In 502, the system can determine the viewing type. For example, the user can indicate the viewing type for a data file. The system can present options for viewing the data file by downloading it for viewing and / or viewing it in an editor.
[0064] If the system determines that it wants to view the data file in an editor, process 300 can proceed to 504, whereby the system can display the data file in an editor for viewing. For example, the system can display the data file in a data file editor. In some implementations, the data file editor can be a YAML editor. The data file editor can allow users to view the data file and add comments to it.
[0065] If the system determines that it needs to download the data file, process 300 can proceed to 506, where the system can allow the download. For example, a user can download the data file from the system for external viewing. Process 300 can then proceed to 506 through 504, where comments can be added to the data file based on external viewing.
[0066] If step 508 occurs, the system can determine whether the data file has been approved. For example, the user can indicate whether the data file viewed in step 504 has been approved. If the system determines that the data has not been approved, process 300 can proceed to step 510, where the profile is sent back to the editor. Specifically, in step 402, the data file can be sent back to the editor for presentation via step 512.
[0067] If the system determines in 508 that the data file is approved, process 300 can proceed to 514, where the profile can be approved. For example, the system can determine that the data profile is approved for generating a profile. In 516, the status of the profile can be changed to approved. For example, the status of the data file can be changed to approved. The data file can be provided for generating the profile, such as generating a binary file from the data file and signing the binary file, such as regarding the service provider interface device 104, the profile manager (such as TEST profile manager 106). Figure 1 ) and / or PROD Profile Manager 114 ( Figure 1 As described in PKI 108, the system can generate a profile from a data file.
[0068] Figure 6 An exemplary process 600 for generating a profile is illustrated according to some implementation schemes. For example, process 600 can be executed to generate a profile of the kernel for data transfer. Process 600 can be executed by a system, such as with respect to system layout 100 (…). Figure 1 The system described.
[0069] In 602, process 600 may include receiving a data file defining a profile to be generated. For example, the system may receive a data file defining a profile to be generated for a kernel to be used for data transfer. Receiving the data file may include receiving the profile data file, receiving a data file associated with a previously generated profile requested to be cloned, and / or receiving the data file based on entries provided by a service provider, as described throughout this disclosure.
[0070] In 604, process 600 may include performing a verification process on a data file. For example, the system may perform a verification process on a data file to determine the verification required for the generated profile.
[0071] In some implementations, the verification process may include performing a first set of verifications on the data file. The system may generate an intermediate file, which is in a different format from the data file, at least in part based on the data file. As part of the verification process, the system may perform a second set of verifications on the intermediate file.
[0072] In some implementations, performing the verification process may include verifying the format of one or more entries within a data file. Furthermore, performing the verification process may include verifying one or more values within a data file. The system may also verify any dependencies between one or more values within a data file.
[0073] In 606, process 600 may include generating a binary file corresponding to the data file. For example, the system may generate a binary file corresponding to the data file, which will be used for a profile. In some implementations, the binary file may include a TEST binary file.
[0074] In 608, process 600 may include generating one or more keys for signing the binary file. For example, the system may generate one or more keys for signing the binary file based at least in part on a profile verified for generation. In some implementations, one or more keys may be generated by the system's profile manager (such as TEST Profile Manager 106). Figure 1 ) and / or PROD Profile Manager 114 ( Figure 1 Generate. Furthermore, one or more keys may include a first set of one or more keys.
[0075] In 610, process 600 may include signing the binary file. For example, the system may sign the binary file with one or more keys to generate a profile. In some implementations, the profile may include a TEST version profile (such as a profile generated by TEST profile manager 106).
[0076] In some implementations, signing a binary file may include generating a certificate chain corresponding to the data file. Furthermore, in some implementations, signing a binary file may include signing the binary file using a certificate chain.
[0077] In some implementations, signing a binary file may include generating a Certificate Signature (CSR) by the system's profile manager using the public key from one or more keys. Furthermore, the system may provide the CSR to the system's PKI via the profile manager. The system may generate a certificate chain by the PKI based at least in part on the CSR. Additionally, the system may sign the binary file using the certificate chain via the profile manager.
[0078] In some implementations where the binary file includes a TEST binary file and the profile includes a TEST version file, process 600 may further include storing the TEST version profile in a system TEST database, the system's TEST database being used to provide limited access to the TEST version profile. For example, the system may store the TEST version profile in a TEST database.
[0079] In some implementations, process 600 may further include receiving an instruction to upgrade a TEST version profile to a PROD version profile (such as a profile generated by the PROD profile manager 114). For example, the system may receive an instruction to upgrade a TEST version profile to a PROD version profile. This instruction may include a profile ID indicating the TEST version profile.
[0080] In some implementations, process 600 may also include generating a PROD version profile based at least in part on instructions for improving the TEST version profile. For example, the system may generate a PROD version profile.
[0081] In some implementations, generating a PROD version profile may include generating a PROD binary file corresponding to the data file, which will be used in the PROD version profile. Generating a PROD version profile may also include generating a second set of one or more keys for signing the PROD binary file. Furthermore, the system can use the second set of one or more keys to sign the PROD binary file to generate the PROD version profile.
[0082] In some implementations, the TEST binary file can be generated by the system's TEST profile manager (such as TEST profile manager 106). Additionally, in some implementations, a first set of one or more keys can be generated by the TEST profile manager. In some implementations, the PROD binary file can be generated by the system's PROD profile manager (such as PROD profile manager 114). Furthermore, in some implementations, a second set of one or more keys can be generated by the PROD profile manager.
[0083] In some implementations, signing the TEST binary file may include generating a first CSR by the TEST profile manager using a first public key from one or more keys in a first set. The system may also send the TEST profile to the system's PKI (such as PKI 108). Figure 1 The first Certificate Signature (CSR) is provided as part of the signature of the TEST binary. Signing the TEST binary may also include generating a first certificate chain by the PKI based at least in part on the first CSR. Signing the TEST binary may include generating a TEST version profile by having the TEST profile manager sign the TEST binary with the first certificate chain.
[0084] In some implementations, signing a PROD binary file may include generating a second CSR by the PROD profile manager using a second public key from one or more second sets of keys. The system may also allow the PROD profile manager to provide the second CSR to the PKI as part of the signature of the PROD binary file. Signing a PROD binary file may also include generating a second certificate chain by the PKI, at least in part, based on the second CSR, which is different from the first certificate chain. Signing a PROD binary file may include signing the PROD binary file with the second certificate chain by the PROD profile manager to produce a PROD version profile.
[0085] Figure 7 An exemplary user equipment (UE) 700 according to some implementation schemes is illustrated. UE 700 may be a terminal that can utilize a profile generated by the system (such as a first terminal 112). Figure 1 ) and / or the second terminal 118 ( Figure 1 Examples of one of the following: UE 700. UE 700 can be any mobile or non-mobile computing device, such as, for example, a mobile phone, computer, tablet, industrial wireless sensors (e.g., microphones, carbon dioxide sensors, pressure sensors, humidity sensors, thermometers, motion sensors, accelerometers, laser scanners, fluid level sensors, stock sensors, voltmeters / ammeters, actuators, etc.), video surveillance / monitoring devices (e.g., cameras, camcorders, etc.), wearable devices (e.g., smartwatches), and loosely coupled IoT devices. In some implementations, UE 700 can be a RedCap UE or an NR-Light UE.
[0086] UE 700 may include a processor 704, an RF interface circuit 708, a memory / storage device 712, a user interface 716, a sensor 720, a drive circuit 722, a power management integrated circuit (PMIC) 724, an antenna structure 726, and a battery 728. The components of UE 700 may be implemented as integrated circuits (ICs), portions of such integrated circuits, discrete electronic devices or other modules, logic components, hardware, software, firmware, or combinations thereof. Figure 7 The block diagram is intended to show a simplified view of some of the components of the UE 700. However, some of the components shown may be omitted, additional components may be present, and different arrangements of the components shown may occur in other specific implementations.
[0087] The components of UE 700 can be coupled to various other components via one or more interconnects 732, which can represent any type of interface, input / output, bus (local, system, or extension), transmit line, trace, optical connection, etc., allowing various circuit components (on common or different chips or chipsets) to interact with each other.
[0088] Processor 704 may include processor circuitry, such as, for example, baseband processor circuitry (BB) 704A, central processing unit circuitry (CPU) 704B, and graphics processing unit circuitry (GPU) 704C. Processor 704 may include any type of circuitry or processor circuitry that executes or otherwise operates computer-executable instructions (such as program code, software modules, or functional processes from memory / storage device 712) to cause UE 700 to perform the operations described herein.
[0089] In some implementations, the baseband processor circuit 704A can access the communication protocol stack 736 in the memory / storage device 712 to communicate over a 3GPP-compliant network. Generally, the baseband processor circuit 704A can access the communication protocol stack to perform user plane functions at the PHY, MAC, RLC, PDCP, SDAP, and PDU layers; and control plane functions at the PHY, MAC, RLC, PDCP, RRC, and non-access layer layers. In some implementations, PHY layer operations may additionally / optionally be performed by components of the RF interface circuit 708.
[0090] The baseband processor circuit 704A can generate or process baseband signals or waveforms carrying information in a 3GPP-compliant network. In some implementations, the waveforms used for NR can be based on cyclic prefix OFDM (CP-OFDM) in the uplink or downlink, and Discrete Fourier Transform Extended OFDM (DFT-S-OFDM) in the uplink.
[0091] Memory / storage device 712 may include one or more non-transitory computer-readable media including instructions (e.g., communication protocol stack 736) that can be executed by one or more processors in processor 704 to cause UE 700 to perform the various operations described herein. Memory / storage device 712 includes any type of volatile or non-volatile memory that can be distributed throughout UE 700. In some embodiments, some of memory / storage devices 712 may be located on processor 704 itself (e.g., L1 cache and L2 cache), while other memory / storage devices 712 are external to processor 704 but accessible via a memory interface. Memory / storage device 712 may include any suitable volatile or non-volatile memory, such as, but not limited to, dynamic random access memory (DRAM), static random access memory (SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, solid-state memory, or any other type of memory device technology.
[0092] The RF interface circuit 708 may include transceiver circuitry and a radio frequency front-end module (RFEM) that allows the UE 700 to communicate with other devices via a radio access network. The RF interface circuit 708 may include various components arranged in the transmit or receive path. These components may include, for example, switches, mixers, amplifiers, filters, synthesizer circuitry, control circuitry, etc.
[0093] In the receiving path, the RFEM can receive the radiated signal from the air interface via antenna structure 726, and continue to filter and amplify the signal (using a low-noise amplifier). The signal can be provided to the receiver of the transceiver, which down-converts the RF signal into a baseband signal that is provided to the baseband processor of processor 704.
[0094] In the transmission path, the transceiver's transmitter up-converts the baseband signal received from the baseband processor and provides the RF signal to the RFEM. The RFEM can then amplify the RF signal using a power amplifier before it is radiated across the air interface via antenna 726.
[0095] In various implementations, the RF interface circuit 708 can be configured to transmit / receive signals in a manner compatible with NR access technologies.
[0096] Antenna 726 may include antenna elements to convert electrical signals into radio waves for propagation through the air and to convert received radio waves back into electrical signals. These antenna elements may be arranged in one or more antenna panels. Antenna 726 may have omnidirectional, directional, or combinations thereof antenna panels to enable beamforming and multiple-input multiple-output communication. Antenna 726 may include microstrip antennas, patch antennas, phased array antennas, printed antennas fabricated on the surface of one or more printed circuit boards, etc. Antenna 726 may have one or more panels designed for a specific frequency band included in FR1 or FR2.
[0097] User interface circuitry 716 includes various input / output (I / O) devices designed to enable users to interact with UE 700. User interface 716 includes input device circuitry and output device circuitry. Input device circuitry includes any physical or virtual components for accepting input, particularly including one or more physical or virtual buttons (e.g., a reset button), a physical keyboard, a keypad, a mouse, a touchpad, a touchscreen, a microphone, a scanner, or a headset. Output device circuitry includes any physical or virtual components for displaying information or otherwise conveying information, such as sensor readings, actuator positions, or other similar information. Output device circuitry may include any number or combination of audio or visual displays, particularly including one or more simple visual outputs / indicators (e.g., binary status indicators, such as light-emitting diodes (LEDs) and multi-character visual outputs), or more complex outputs, such as display devices or touchscreens (e.g., liquid crystal displays (LCDs), LED displays, quantum dot displays, projectors, etc.), where the output of characters, graphics, multimedia objects, etc., is generated or produced by the operation of UE 700.
[0098] Sensor 720 may include devices, modules, or subsystems designed to detect events or changes in their environment and transmit information about the detected events (sensor data) to other devices, modules, subsystems, etc. Examples of such sensors include, in particular: inertial measurement units including accelerometers, gyroscopes, or magnetometers; microelectromechanical systems (MEMS) or nanoelectromechanical systems (NEMS) with 3-axis accelerometers, 3-axis gyroscopes, or magnetometers; level sensors; flow sensors; temperature sensors (e.g., thermistors); pressure sensors; barometric pressure sensors; gravimeters; altimeters; image capture devices (e.g., cameras or lensless aperture sensors); light detection and ranging sensors; proximity sensors (e.g., infrared radiation detectors, etc.); depth sensors; ambient light sensors; ultrasonic transceivers; microphones or other similar audio capture devices; and so on.
[0099] The driving circuit 722 may include software and hardware elements that operate to control a specific device embedded in, attached to, or otherwise communicatively coupled to the UE 700. The driving circuit 722 may include various drivers that allow other components to interact with or control various input / output (I / O) devices that may exist within or be connected to the UE 700. For example, the driving circuit 722 may include: a display driver for controlling and allowing access to a display device; a touchscreen driver for controlling and allowing access to a touchscreen interface; a sensor driver for obtaining sensor readings from sensor circuit 720 and controlling and allowing access to sensor circuit 720; a driver for obtaining actuator positioning of an electromechanical component or controlling and allowing access to an electromechanical component; a camera driver for controlling and allowing access to an embedded image capture device; and an audio driver for controlling and allowing access to one or more audio devices.
[0100] The PMIC 724 manages the power supplied to various components of the UE 700. Specifically, for the processor 704, the PMIC 724 controls power source selection, voltage scaling, battery charging, or DC-DC conversion.
[0101] In some implementations, the PMIC 724 can control or otherwise incorporate various power-saving mechanisms of the UE 700. For example, if the platform UE is in the RRC_Connected state, where it remains connected to the RAN node as it anticipates receiving traffic soon, it can then enter a state known as Discontinuous Receive Mode (DRX) after a period of inactivity. During this state, the UE 700 can power down for short intervals, thus saving power. If there is no data traffic activity over a longer period, the UE 700 can transition to the RRC_Idle state, where it is disconnected from the network and does not perform operations such as channel quality feedback or handover. The UE 700 enters a very low-power state and performs paging, at which point it periodically wakes up again to listen to the network and then power down again. The UE 700 may not receive data in this state; to receive data, it may need to transition back to the RRC_Connected state. Additional power-saving modes can render the device unusable from the network for periods exceeding the paging interval (from seconds to hours). During this period, the device is completely unable to connect to the network and can be completely powered off. Any data transmitted during this time will cause significant delays, which are assumed to be acceptable.
[0102] Battery 728 can power UE 700, but in some examples, UE 700 may be installed and deployed in a fixed location and may have a power source coupled to the power grid. Battery 728 may be a lithium-ion battery, a metal-air battery (such as zinc-air, aluminum-air, lithium-air batteries), etc. In some specific implementations, such as in vehicle-based applications, battery 728 may be a typical lead-acid automotive battery.
[0103] Figure 8 It is achievable based on some implementation schemes. Figures 1 to 6 A block diagram of an exemplary computing device 800 illustrating its features and processes. Computing device 800 is a partner device 102 ( Figure 1 ), service provider interface device 104 ( Figure 1 ), TEST Profile Manager 106 ( Figure 1 ), PKI 108 ( Figure 1 ), First terminal 112 ( Figure 1 ), PROD Profile Manager 114 ( Figure 1 ) and / or the second terminal 118 ( Figure 1 Example of computing device 800. Computing device 800 may include a memory interface 802, one or more data processors, a graphics processor and / or a central processing unit 804, and a peripheral device interface 806. The memory interface 802, one or more processors 804, and / or the peripheral device interface 806 may be separate components or may be integrated into one or more integrated circuits. The various components in computing device 800 may be coupled via one or more communication buses or signal lines.
[0104] Sensors, devices, and subsystems can be coupled to peripheral interface 806 to facilitate multiple functionalities. For example, motion sensor 810, light sensor 812, and proximity sensor 814 can be coupled to peripheral interface 806 to facilitate orientation, illumination, and proximity functions. Other sensors 816 can also be connected to peripheral interface 806, such as Global Navigation Satellite System (GNSS) (e.g., GPS receiver), temperature sensors, biometric sensors, magnetometers, or other sensing devices to facilitate related functionalities.
[0105] The camera subsystem 820 and optical sensor 822 (e.g., an electro-coupled device (CCD) or complementary metal-oxide-semiconductor (CMOS) optical sensor) can be used to facilitate camera functions such as recording photos and video clips. The camera subsystem 820 and optical sensor 822 can be used to collect images of the user to be used during user authentication (e.g., by performing facial recognition analysis).
[0106] Communication functionality can be facilitated by one or more wireless communication subsystems 824, which may include radio frequency receivers and transmitters and / or optical (e.g., infrared) receivers and transmitters. The specific design and implementation of the communication subsystem 824 may depend on the communication network through which the computing device 800 intends to operate. For example, the computing device 800 may include subsystems designed to operate via GSM networks, GPRS networks, EDGE networks, Wi-Fi or WiMax networks, and Bluetooth. ™ The communication subsystem 824 for network operation.
[0107] The audio subsystem 826 can be coupled to the speaker 828 and the microphone 830 to facilitate voice-enabled functions such as speaker recognition, voice copying, digital recording, and telephone functions. The audio subsystem 826 can be configured to facilitate, for example, processing of voice commands, voiceprint identification, and voice authentication.
[0108] I / O subsystem 840 may include touch surface controller 842 and / or other input controller 844. Touch surface controller 842 may be coupled to touch surface 846. Touch surface 846 and touch surface controller 842 may, for example, use any of a variety of touch-sensitive technologies (including, but not limited to, capacitive, resistive, infrared, and surface acoustic wave technologies) and other proximity sensor arrays or other elements for determining one or more contact points with touch surface 846 to detect contact and movement or their interruption.
[0109] Other input controllers 844 may be coupled to other input / control devices 848, such as one or more buttons, rocker switches, thumbwheels, infrared ports, USB ports, and / or pointing devices (such as styluses). One or more buttons (not shown) may include volume up / down buttons for speaker 828 and / or microphone 830.
[0110] In one implementation, pressing the button for a first duration unlocks the touch surface 846; and pressing the button for a second duration longer than the first duration turns the computing device 800 on or off. Pressing the button for a third duration activates a voice control or voice command module that allows the user to speak commands into the microphone 830 to have the device execute those commands. The user can customize the functionality of one or more buttons. For example, the touch surface 846 can also be used to implement virtual or soft buttons and / or a keyboard.
[0111] In some examples, computing device 800 may display recorded audio and / or video files, such as MP3, AAC, and MPEG files. In some examples, computing device 800 may include an MP3 player such as an iPod. ™ Functionality.
[0112] Memory interface 802 can be coupled to memory 850. Memory 850 may include high-speed random access memory and / or non-volatile memory, such as one or more disk storage devices, one or more optical storage devices, and / or flash memory (e.g., NAND, NOR). Memory 850 may store operating system 852, such as Darwin, RTXC, LINUX, UNIX, OSX, WINDOWS, or embedded operating systems (such as VxWorks).
[0113] Operating system 852 may include instructions for handling basic system services and for performing hardware-related tasks. In some examples, operating system 852 may be a kernel (e.g., a UNIX kernel). In some examples, operating system 852 may include instructions for generating profiles. For example, operating system 852 may implement profile generation operations, such as regarding... Figures 1 to 6 As described.
[0114] The memory 850 may also store communication instructions 854 that facilitate communication with one or more additional devices, one or more computers, and / or one or more servers. The memory 850 may include graphical user interface instructions 856 that facilitate graphical user interface processing; sensor processing instructions 858 that facilitate sensor-related processing and functions; telephone instructions 860 that facilitate telephone-related processes and functions; electronic message processing instructions 862 that facilitate electronic message sending and receiving processes and functions; web browsing instructions 864 that facilitate web browsing-related processes and functions; media processing instructions 866 that facilitate media processing-related processes and functions; GNSS / navigation instructions 868 that facilitate GNSS and navigation-related processes and instructions; and / or camera instructions 870 that facilitate camera-related processes and functions.
[0115] Memory 850 can store software instructions 872 to facilitate other processes and functions, such as references Figures 1 to 6 The described brief storage procedures and functions.
[0116] The memory 850 may also store other software instructions 874, such as network video instructions that facilitate processes and functions related to network video; and / or network shopping instructions that facilitate processes and functions related to online shopping. In some embodiments, the media processing instructions 866 are divided into audio processing instructions and video processing instructions, to facilitate processes and functions related to audio processing and video processing, respectively.
[0117] Each of the instructions and applications identified above may correspond to a set of instructions for performing one or more functions described above. These instructions do not need to be implemented as a separate software program, process, or module. Memory 850 may include additional instructions or fewer instructions. Furthermore, various functions of computing device 800 may be implemented in hardware and / or software, including in one or more signal processing and / or application-specific integrated circuits.
[0118] Figure 9 An exemplary architecture or environment 900 according to some implementation schemes is illustrated, which is configured to implement the techniques described herein. Architecture 900 includes user equipment 906 (e.g., a first terminal 112). Figure 1 ) and / or the second terminal 118 ( Figure 1 )) and service provider computer 902 (e.g., service provider interface device 104 ( Figure 1 ), TEST Profile Manager 106 ( Figure 1 ), PKI 108 ( Figure 1 ), TEST database 110 ( Figure 1 ), PROD Profile Manager 114 ( Figure 1 ), PROD database 116 ( Figure 1 (or combinations thereof). In some examples, exemplary architecture 900 may also be configured to enable user equipment 906 and service provider computer 902 to share information. In some examples, the devices may be connected via one or more networks 908 (e.g., via Bluetooth, WiFi, the Internet). In some examples, service provider computer 902 may be configured to implement at least some of the technologies described herein with reference to user equipment 906, and vice versa.
[0119] In some examples, network 908 may include any one or a combination of many different types of networks, such as wired networks, the Internet, wireless networks, cellular networks, satellite networks, other private networks and / or public networks, or any combination thereof. While the illustrated example represents user equipment 906 accessing service provider computer 902 via network 908, the described techniques are equally applicable to situations where user equipment 906 interacts with service provider computer 902 via a landline, a public phone booth, or any other means. It should also be noted that the described techniques are applicable to other client / server deployments (e.g., set-top boxes) as well as non-client / server deployments (e.g., locally stored applications, peer-to-peer configurations).
[0120] As described above, user equipment 906 can be any type of computing device, such as, but not limited to, mobile phones, smartphones, personal digital assistants (PDAs), laptops, desktop computers, thin client devices, tablet computers, wearable devices (such as smartwatches), electronic devices in mobile vehicles or transportation equipment, etc. In some examples, user equipment 906 can communicate with service provider computer 902 via network 908 or via other network connections.
[0121] In one exemplary configuration, user equipment 906 may include at least one memory 914 and one or more processing units (or processors) 916. Processor 916 may be implemented, as appropriate, in hardware, computer-executable instructions, firmware, or a combination thereof. The specific implementation of the computer-executable instructions or firmware of processor 916 may include computer-executable instructions or machine-executable instructions written in any suitable programming language to perform the various functions described. User equipment 906 may also include a geolocation device (e.g., a Global Positioning System (GPS) device, etc.) for providing and / or recording geolocation information associated with user equipment 906. In some examples, processor 916 may include a GPU and a CPU.
[0122] Memory 914 may store program instructions that can be loaded and executed on processor 916, as well as data generated during the execution of these programs. Depending on the configuration and type of user equipment 906, memory 914 may be volatile memory (such as random access memory (RAM)) and / or non-volatile memory (such as read-only memory (ROM), flash memory). User equipment 906 may also include additional removable storage devices and / or non-removable storage devices 926, including but not limited to magnetic storage devices, optical disk and / or magnetic tape storage devices. Disk drives and their associated non-transitory computer-readable media may provide non-volatile storage devices for computer-readable instructions, data structures, program modules and other data to computing devices. In some examples, memory 914 may include a variety of different types of memory, such as static random access memory (SRAM), dynamic random access memory (DRAM) or ROM. Although the volatile memory described herein may be referred to as RAM, any volatile memory in which the data stored will not be retained after being removed from the host and / or power supply is appropriate.
[0123] Removable and non-removable memory 914 and additional storage device 926 are examples of non-transitory computer-readable storage media. For example, non-transitory computer-readable storage media may include volatile or non-volatile, removable or non-removable media implemented by any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Memory 914 and additional storage device 926 are examples of non-transitory computer storage media. Additional types of computer storage media that may be present in user equipment 906 may include, but are not limited to, phase-change RAM (PRAM), SRAM, DRAM, RAM, ROM, electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, optical disc read-only memory (CD-ROM), digital video disc (DVD) or other optical storage devices, magnetic tape cassettes, magnetic tape, disk storage devices or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to user equipment 906. Any combination of the above should also be included within the scope of non-transitory computer-readable storage media. Alternatively, computer-readable communication media may include computer-readable instructions, program modules, or other data transmitted within data signals such as carrier waves or other transmission means. However, as used herein, computer-readable storage media do not include computer-readable communication media.
[0124] User equipment 906 may also include a communication connection 928 that allows user equipment 906 to communicate with a data repository, another computing device or server, user terminals and / or other devices via a network 908. User equipment 906 may also include I / O devices 930, such as a keyboard, mouse, pen, voice input device, touch screen input device, display, speaker and printer.
[0125] Turning to the contents of memory 914 in more detail, memory 914 may include operating system 912 and / or one or more applications or services for implementing the features disclosed herein, such as application 911 (e.g., mapping application, web application) and mapping engine 913. About Figures 1 to 3 The technique described in 2 can be executed by the mapping engine 913.
[0126] The service provider computer 902 may also be any type of computing device, such as, but not limited to, a collection of virtual or “cloud” computing resources, a remote server, a mobile phone, a smartphone, a PDA, a laptop computer, a desktop computer, a thin client device, a tablet computer, a wearable device, a server computer, or a virtual machine instance. In some examples, the service provider computer 902 may communicate with the user equipment 906 via network 908 or via other network connections.
[0127] In one exemplary configuration, the service provider computer 902 may include at least one memory 942 and one or more processing units (or processors) 944. The processor 944 may be implemented, as appropriate, in hardware, computer-executable instructions, firmware, or a combination thereof. The specific implementation of the computer-executable instructions or firmware of the processor 944 may include computer-executable instructions or machine-executable instructions written in any suitable programming language to perform the various functions described.
[0128] Memory 942 may store program instructions that can be loaded and executed on processor 944, as well as data generated during the execution of these programs. Depending on the configuration and type of service provider computer 902, memory 942 may be volatile memory (such as RAM) and / or non-volatile memory (such as ROM and flash memory). Service provider computer 902 may also include additional removable storage devices and / or non-removable storage devices 946, including but not limited to magnetic storage devices, optical disk and / or magnetic tape storage devices. Disk drives and their associated non-transitory computer-readable media may provide non-volatile storage devices for computer-readable instructions, data structures, program modules and other data for computing devices. In some examples, memory 942 may include a variety of different types of memory, such as SRAM, DRAM or ROM. While the volatile memory described herein may be referred to as RAM, any volatile memory in which the data stored will not be retained after being removed from the host and / or power supply is appropriate. Removable and non-removable memory 942 and additional storage device 946 are additional examples of non-transitory computer-readable storage media.
[0129] The service provider computer 902 may also include a communication connection 948 that allows the service provider computer 902 to communicate with a data repository, another computing device or server, user terminals and / or other devices via a network 908. The service provider computer 902 may also include I / O devices 950, such as a keyboard, mouse, pen, voice input device, touch input device, monitor, speakers and printer.
[0130] Turning to the contents of memory 942 in more detail, memory 942 may include operating system 952 and / or one or more applications 941 or services for implementing the features disclosed herein, such as references Figures 1 to 6 Those described.
[0131] As is widely recognized, the use of personally identifiable information should comply with privacy policies and practices that are generally accepted to meet or exceed industry or governmental requirements for protecting user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly explained to users.
[0132] For one or more embodiments, at least one of the components illustrated in one or more of the foregoing figures may be configured to perform one or more operations, techniques, processes, or methods described in the Embodiments section below. For example, the baseband circuitry described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more examples below. Similarly, circuitry associated with the UE, base station, network element, etc., described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more embodiments described in the Embodiments section below.
[0133] In some implementations, an application executing on a user's device may be used to perform some or all of the operations described herein. Circuits, logic modules, processors, and / or other components may be configured to perform the various operations described herein. Those skilled in the art will understand that, depending on the specific implementation, such configuration can be accomplished through the design, setup, interconnection, and / or programming of particular components, and again, depending on the specific implementation, the configured components may be reconfigurable or not reconfigurable for different operations. For example, a programmable processor can be configured by providing appropriate executable code; a dedicated logic circuit can be configured by appropriately connecting logic gates and other circuit elements; and so on.
[0134] As described above, one aspect of the present invention is the collection, sharing, and use of data, including authentication tags and data from which those tags are derived. This disclosure contemplates that, in some instances, the collected data may include personal information data that uniquely identifies or can be used to contact or locate specific individuals. Such personal information data may include demographic data, location-based data, telephone numbers, email addresses, Twitter IDs, home addresses, data or records related to a user's health or fitness level (e.g., vital sign measurements, medication information, exercise information), date of birth, or any other identifying information or personal information.
[0135] This disclosure recognizes that the use of such personal information data in the techniques of this invention can be beneficial to users. For example, personal information data can be used to authenticate another device and vice versa to control which device ranging operations can be performed. Furthermore, this disclosure also contemplates other uses of personal information data that are beneficial to users. For example, health and fitness data can be shared to provide insights into a user's overall health status or can be used as positive feedback for individuals using technology to pursue health goals.
[0136] This disclosure anticipates that entities responsible for the collection, analysis, disclosure, transmission, storage, or other use of such personal information data will comply with robust privacy policies and / or privacy measures. Specifically, such entities should implement and adhere to privacy policies and measures that are recognized as meeting or exceeding industry or governmental requirements for maintaining the privacy and security of personal information data. Such policies should be easily accessible to users and should be updated as the collection and / or use of data changes. Personal information from users should be collected for legitimate and reasonable entity purposes and should not be shared or sold outside of these legitimate purposes. Furthermore, such collection / sharing should be conducted only after receiving informed consent from users. Additionally, such entities should consider taking any necessary steps to protect and safeguard the right to access such personal information data and ensure that other entities with access to personal information data comply with the privacy policies and procedures of other entities. Furthermore, such entities may subject themselves to third-party assessments to demonstrate their compliance with widely accepted privacy policies and privacy practices. Moreover, policies and measures should be adapted to the specific types of personal information data collected and / or accessed, and to applicable laws and standards, including considerations of specific jurisdictions. For example, in the United States, the collection or acquisition of certain health data may be governed by federal and / or state laws, such as the Health Insurance Portability and Accountability Act (HIPAA); while in other countries, health data may be subject to other regulations and policies and should be handled accordingly. Therefore, different privacy practices should be maintained for different types of personal data in each country.
[0137] Regardless of the foregoing, this disclosure also contemplates implementation schemes for users to selectively block the use or access to personal information data. That is, this disclosure contemplates providing hardware and / or software components to prevent or block access to such personal information data. For example, in relation to sharing content and performing ranging, the inventive technology can be configured to allow users to opt-in or opt-out at any time during or after registering for the service to participate in the collection of personal information data. In addition to providing opt-in and opt-out options, this disclosure also contemplates providing notifications related to access to or use of personal information. For example, users may be notified when downloading an application that their personal information data will be accessed, and then reminded again just before the application accesses the personal information data.
[0138] Furthermore, the intent of this disclosure is that personal information data should be managed and processed in a manner that minimizes the risk of unintentional or unauthorized access or use. Once data is no longer needed, this risk can be minimized by restricting data collection and deleting data. Additionally, and where applicable, including in certain health-related applications, data deidentification can be used to protect user privacy. Where appropriate, deidentification can be facilitated by removing specific identifiers (e.g., date of birth, etc.), controlling the amount or characteristics of stored data (e.g., collecting location data at the city level rather than address level), controlling how data is stored (e.g., aggregating data among users), and / or other methods.
[0139] Therefore, while this disclosure broadly covers the use of personal information data to implement one or more of the various disclosed embodiments, it is also contemplated that various embodiments can be implemented without access to such personal information data. That is, various embodiments of the present invention will not become inoperable due to the absence of all or part of such personal information data.
[0140] In some examples, "circuit" can refer to, be part of, or include the following: hardware components configured to provide the described functionality, such as electronic circuits, logic circuits, processors (shared, dedicated, or grouped) or memories (shared, dedicated, or grouped), application-specific integrated circuits (ASICs), field-programmable devices (FPDs) (e.g., field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), complex PLDs (CPLDs), high-capacity PLDs (HCPLDs), structured ASICs, or programmable system-on-chips (SoCs)), digital signal processors (DSPs), etc. In some embodiments, a circuit may execute one or more software or firmware programs to provide at least some of the described functionality. The term "circuit" can also refer to a combination of one or more hardware elements (or combinations of circuits used in electrical or electronic systems) and program code for executing the functionality. In these embodiments, the combination of hardware elements and program code may be referred to as a particular type of circuit.
[0141] As used herein, the term "processor circuit" means a circuit capable of sequentially and automatically performing a series of arithmetic or logical operations or recording, storing, or transmitting digital data; a part of, or including, a circuit capable of sequentially and automatically performing a series of arithmetic or logical operations or recording, storing, or transmitting digital data. The term "processor circuit" may also refer to an application processor, baseband processor, central processing unit (CPU), graphics processing unit, single-core processor, dual-core processor, triple-core processor, quad-core processor, or any other device capable of executing or otherwise operating computer-executable instructions (such as program code, software modules, and / or functional procedures).
[0142] As used herein, the term "interface circuit" refers to circuitry that enables the exchange of information between two or more components or devices, a portion thereof, or includes circuitry that enables the exchange of information between two or more components or devices. The term "interface circuitry" may refer to one or more hardware interfaces, such as buses, I / O interfaces, peripheral component interfaces, or network interface cards.
[0143] As used herein, the term "user equipment" or "UE" refers to equipment of a remote user that has radio communication capabilities and can describe network resources in a communication network. Furthermore, the term "user equipment" or "UE" can be considered synonymous and can be referred to as a client, mobile phone, mobile device, mobile terminal, user terminal, mobile unit, mobile station, mobile user, subscriber, user, remote station, access agent, user agent, receiver, radio equipment, reconfigurable radio equipment, reconfigurable mobile device, etc. Additionally, the term "user equipment" or "UE" can include any type of wireless / wired equipment or any computing device that includes a wireless communication interface.
[0144] As used herein, the term "computer system" means any type of interconnected electronic device, computer device, or component thereof. Additionally, the term "computer system" or "system" may refer to various components of a computer that are communicatively coupled to each other. Furthermore, the term "computer system" or "system" may refer to multiple computer devices or multiple computing systems that are communicatively coupled to each other and configured to share computing resources or network resources.
[0145] As used herein, the term "resource" refers to physical or virtual devices, physical or virtual components within a computing environment, or physical or virtual components within a specific device, such as computer equipment, mechanical equipment, memory space, processor / CPU time, processor / CPU utilization, processor and accelerator load, hardware time or utilization, power supply, input / output operations, port or network sockets, channel / link allocation, throughput, memory utilization, storage, network, databases and applications, units of workload, etc. "Hardware resource" can refer to computing, storage, or networking resources provided by physical hardware components. "Virtualized resource" can refer to computing, storage, or networking resources provided by virtualization infrastructure to applications, devices, systems, etc. The terms "network resource" or "communication resource" can refer to resources that a computer device / system can access via a communication network. The term "system resource" can refer to any kind of shared entity providing services and can include computing or network resources. System resources can be considered as a coherent set of functions, network data objects, or services that can be accessed through a server, wherein such system resources reside on a single host or multiple hosts and are clearly identifiable.
[0146] As used herein, the term "channel" refers to any tangible or intangible transmission medium used to transmit data or data streams. The term "channel" may be synonymous or equivalent with "communication channel," "data communication channel," "transmission channel," "data transmission channel," "access channel," "data access channel," "link," "data link," "carrier," "radio frequency carrier," or any other similar term indicating a means or medium through which data is transmitted. Additionally, as used herein, the term "link" refers to a connection between two devices for the purpose of transmitting and receiving information.
[0147] As used in this article, the terms "instantiate" and "instantiate" refer to the creation of an instance. "Instance" also refers to the concrete occurrence of an object, which may occur, for example, during the execution of program code.
[0148] The term "connection" can refer to an established signaling relationship between two or more elements at a common communication protocol layer through a communication channel, link, interface, or reference point.
[0149] As used herein, the term "network element" refers to the physical or virtualized equipment or infrastructure used to provide wired or wireless communication network services. The term "network element" may be considered synonymous with or referred to as networked computers, network hardware, network equipment, network nodes, virtualized network functions, etc.
[0150] The term "information element" refers to a structural element that contains one or more fields. The term "field" refers to the individual content of an information element, or the data element that contains that content. An information element may include one or more additional information elements.
[0151] Although this disclosure has been described with respect to specific embodiments, it should be understood that this disclosure is intended to cover all modifications and equivalents within the scope of the following claims.
[0152] For all purposes, all patents, patent applications, publications, and specifications mentioned herein are incorporated herein by reference in their entirety. No document is acknowledged as prior art.
[0153] Accordingly, the specification and drawings should be considered illustrative rather than restrictive. However, it will be apparent that various modifications and changes may be made thereto without departing from the broader spirit and scope of this disclosure as set forth in the claims.
[0154] Other variations are within the scope of this disclosure. Therefore, although the disclosed technology is susceptible to various modifications and alternative constructions, certain exemplary embodiments are shown in the accompanying drawings and have been described in detail above. However, it should be understood that this disclosure is not intended to be limited to the specific forms disclosed, but rather is intended to cover all modifications, alternative constructions, and equivalents falling within the scope and spirit of this disclosure as defined by the appended claims.
[0155] In the context of describing the disclosed embodiments (particularly in the context of the following claims), the terms “a,” “an,” and “the,” as well as similar indicator words, shall be construed as covering both the singular and plural, unless otherwise specified herein or clearly contradicted by the context. Unless otherwise stated, the terms “comprising,” “having,” “including,” and “containing” shall be construed as open-ended terms (i.e., meaning “including but not limited to”). The term “connected” is construed as including, attaching, or joining together, even if there is interference. The phrase “based on” shall be understood as open-ended and not in any way limiting, and is intended to be construed or otherwise understood as “at least partially based on” where appropriate. Unless otherwise stated herein, the description of numerical ranges herein is intended merely as a simple way of referring separately to each individual value falling within that range, and each individual value is incorporated into the specification as if separately referenced herein. All methods described herein can be performed in any suitable order unless otherwise stated herein or clearly contradicted by the context. Unless otherwise stated, all examples or exemplary language (e.g., "such as") used herein are intended merely to better illustrate embodiments of this disclosure and do not limit the scope of this disclosure. No language in the specification should be construed as indicating that any unstated element is essential to the practice of this disclosure. Unless expressly indicated to the contrary, the use of "or" is intended to mean "inclusive or" rather than "exclusive or". Referring to a "first" component does not necessarily require the provision of a second component. Furthermore, unless expressly stated otherwise, referring to a "first" or "second" component does not limit the referenced component to a particular location. The term "based on" is intended to mean "at least partially based on".
[0156] Unless otherwise specifically stated, parse languages such as the phrase “at least one of X, Y, or Z” are understood in context to generally refer to items, terms, etc., which can be X, Y, or Z, or any combination thereof (e.g., X, Y, and / or Z). Therefore, such parse languages are generally not intended and should not imply that certain embodiments require the existence of at least one of X, at least one of Y, or at least one of Z. Additionally, unless otherwise specifically stated, union languages such as the phrase “at least one of X, Y, and Z” should also be understood to mean X, Y, Z, or any combination thereof, including “X, Y, and / or Z”.
[0157] This document describes preferred embodiments of the present disclosure, including the best modes known to the inventors for carrying out the present disclosure. Variations of those preferred embodiments will become apparent to those skilled in the art after reading the foregoing description. The inventors expect those skilled in the art to appropriately employ such variations, and the inventors intend to practice the present disclosure in ways different from those specifically described herein. Therefore, as permitted by applicable law, this disclosure includes all modifications and equivalents to the subject matter recited in the appended claims. Furthermore, unless otherwise indicated herein or clearly contradicted by the context, this disclosure encompasses any combination of all possible variations of the foregoing elements.
[0158] All references cited in this article, including publications, patent applications and patents, are incorporated herein by reference, as each reference is individually and specifically indicated to be incorporated by reference and elaborated in the entire text.
[0159] The specific details of a particular implementation may be combined in any suitable manner or differ from those shown and described herein without departing from the substance and scope of the implementation of the described technology.
[0160] The above description of exemplary embodiments of the described technology is provided for illustrative and descriptive purposes. It is not intended to be exhaustive, nor is it intended to limit the described technology to the precise form described, and many modifications and variations are possible in accordance with the above teachings. This embodiment has been chosen and described to fully illustrate the principles of the described technology and its practical application, thereby enabling others skilled in the art to fully utilize the described technology in various embodiments and with various modifications suitable for the particular intended use.
[0161] All publications, patents and patent applications cited in this article are incorporated herein by reference in their entirety for all purposes.
[0162] Example
[0163] Additional example implementations are provided in the following sections.
[0164] Example 1 may include one or more non-transitory computer-readable media having instructions that, when executed by one or more processors of the system, cause the system to: receive a data file defined as a profile to be generated by a kernel for data transfer; perform a verification process on the data file to determine verification of the profile to be generated; generate a binary file corresponding to the data file to be used for the profile; generate one or more keys for signing the binary file, at least in part based on the verified profile to be generated; and sign the binary file with the one or more keys to generate the profile.
[0165] Example 2 may include one or more non-transitory computer-readable media according to claim 1, wherein performing the verification process includes: performing a first set of verifications on a data file; generating an intermediate file based at least in part on the data file, the intermediate file being in a different format from the data file; and performing a second set of verifications on the intermediate file.
[0166] Example 3 may include one or more non-transitory computer-readable media as claimed in claim 1, wherein performing the verification process includes: verifying the format of one or more entries in a data file, verifying one or more values in a data file, and verifying the interdependencies between one or more values in a data file.
[0167] Example 4 may include one or more non-transitory computer-readable media according to claim 1, wherein signing the binary file includes: generating a certificate chain corresponding to the data file, and using the certificate chain to sign the binary file.
[0168] Example 5 may include one or more non-transitory computer-readable media as claimed in claim 1, wherein one or more keys are generated by the system's profile manager, and wherein signing the binary file includes: generating a Certificate Signing Request (CSR) by the profile manager using the public key from one or more keys; providing the CSR to the system's Public Key Infrastructure (PKI) by the profile manager; generating a certificate chain by the PKI based at least in part on the CSR; and signing the binary file by the profile manager using the certificate chain.
[0169] Example 6 may include one or more non-transitory computer-readable media as claimed in claim 1, wherein the binary file includes a TEST binary file, wherein the profile includes a TEST version profile, and wherein the instructions, when executed by one or more processors of the system, further cause the system to: store the TEST version profile in a system TEST database, the system TEST database providing limited access to the TEST version profile; receive an instruction to promote the TEST version profile to a production (PROD) version profile; generate a PROD version profile at least in part based on the instruction to promote the TEST version profile; and store the PROD version profile in a system PROD database, the system PROD database providing extended access to the PROD version profile.
[0170] Example 7 may include one or more non-transient computer-readable media as claimed in claim 6, wherein one or more keys include a first set of one or more keys, and wherein generating a PROD version profile includes: generating a PROD binary file corresponding to a data file, the PROD binary file being used for the PROD version profile; generating a second set of one or more keys for signing the PROD binary file; and signing the PROD binary file with the second set of one or more keys to generate a PROD version profile.
[0171] Example 8 may include one or more non-transitory computer-readable media as claimed in claim 7, wherein the TEST binary file is generated by the system's TEST profile manager, wherein the first set of one or more keys is generated by the TEST profile manager, wherein the PROD binary file is generated by the system's PROD profile manager, and wherein the second set of one or more keys is generated by the PROD profile manager.
[0172] Example 9 may include one or more non-transitory computer-readable media as claimed in claim 8, wherein signing the TEST binary file includes: generating a first certificate signing request (CSR) by the TEST profile manager using a first public key from one or more keys in a first set; providing the first CSR to the public key infrastructure (PKI) of the system by the TEST profile manager; generating a first certificate chain by the PKI based at least in part on the first CSR; and signing the TEST binary file with the first certificate chain by the TEST profile manager to generate a TEST version profile; and signing the PROD binary file includes: generating a second CSR by the PROD profile manager using a second public key from one or more keys in a second set; providing the second CSR to the PKI by the PROD profile manager; generating a second certificate chain by the PKI based at least in part on the second CSR, the second certificate chain being different from the first certificate chain; and signing the PROD binary file with the second certificate chain by the PROD profile manager to generate a PROD version profile.
[0173] Example 10 may include a method for generating a profile, the method comprising: receiving a data file by a system, the data file defining a profile to be generated by a kernel for data transfer; performing a verification process on the data file by the system to determine verification for the profile to be generated; generating a binary file corresponding to the data file by the system, the binary file to be used for the profile; generating one or more keys by the system for signing the binary file, at least in part based on the verified profile to be generated; and signing the binary file with the one or more keys by the system to generate the profile.
[0174] Example 11 may include the method of claim 10, wherein performing the verification process includes: performing a first set of verifications on a data file; generating an intermediate file, at least in part based on the data file, the intermediate file being in a different format from the data file; and performing a second set of verifications on the intermediate file.
[0175] Example 12 may include the method of claim 10, wherein performing the verification process includes: verifying the format of one or more entries in a data file, verifying one or more values in a data file, and verifying the interdependencies between one or more values in a data file.
[0176] Example 13 may include the method according to claim 10, wherein signing the binary file includes: generating a certificate chain corresponding to the data file, and signing the binary file with the certificate chain.
[0177] Example 14 may include the method of claim 10, wherein one or more keys are generated by the system's profile manager, and wherein signing the binary file includes: generating a Certificate Signing Request (CSR) by the profile manager using the public key from one or more keys; providing the CSR to the system's Public Key Infrastructure (PKI) by the profile manager; generating a certificate chain by the PKI based at least in part on the CSR; and signing the binary file by the profile manager using the certificate chain.
[0178] Example 15 may include the method of claim 10, wherein the binary file includes a TEST binary file, wherein the profile includes a TEST version profile, and wherein the method further includes: storing the TEST version profile in a system's TEST database, the system's TEST database providing limited access to the TEST version profile; receiving an instruction from the system to promote the TEST version profile to a production (PROD) version profile; generating a PROD version profile by the system based at least in part on the instruction to promote the TEST version profile; and storing the PROD version profile in a system's PROD database, the system's PROD database providing extended access to the PROD version profile.
[0179] Example 16 may include the method of claim 15, wherein one or more keys include a first set of one or more keys, and wherein generating a PROD version profile includes: generating a PROD binary file corresponding to a data file, the PROD binary file being used for the PROD version profile; generating a second set of one or more keys for signing the PROD binary file; and signing the PROD binary file with the second set of one or more keys to generate a PROD version profile.
[0180] Example 17 may include a system comprising: a memory for storing a profile; and one or more processors coupled to the memory, the one or more processors being configured to: receive a data file defining a profile to be generated by a kernel for data transfer; perform a verification process on the data file to determine verification of the profile to be generated; generate a binary file corresponding to the data file to be used for the profile; generate one or more keys for signing the binary file, at least in part based on the verified profile to be generated; and sign the binary file with the one or more keys to generate the profile.
[0181] Example 18 may include the system of claim 17, wherein signing a binary file includes: generating a certificate chain corresponding to a data file, and using the certificate chain to sign the binary file.
[0182] Example 19 may include the system of claim 17, wherein one or more keys are generated by the system’s profile manager, and wherein signing the binary file includes: generating a certificate signing request (CSR) by the profile manager using the public key from one or more keys; providing the CSR to the system’s public key infrastructure (PKI) by the profile manager; generating a certificate chain by the PKI based at least in part on the CSR; and signing the binary file by the profile manager using the certificate chain.
[0183] Example 20 may include the system of claim 17, wherein the binary file includes a TEST binary file, wherein the profile includes a TEST version profile, and wherein one or more processors are further configured to: store the TEST version profile in a TEST database of the system, the TEST database of the system providing limited access to the TEST version profile; receive an instruction to promote the TEST version profile to a production (PROD) version profile; generate a PROD version profile based at least in part on the instruction to promote the TEST version profile; and store the PROD version profile in a PROD database of the system providing extended access to the PROD version profile.
[0184] Unless otherwise expressly stated, any embodiment described above may be combined with any other embodiment (or combination of embodiments). The foregoing description of one or more specific embodiments is illustrative and descriptive, but is not intended to be exhaustive or to limit the scope of the embodiments to the precise forms disclosed. In view of the teachings above, modifications and variations are possible, or modifications and variations may be obtained from practice of various embodiments.
[0185] Although the above embodiments have been described in considerable detail, many variations and modifications will become apparent to those skilled in the art once the above disclosure is fully understood. It is intended that the following claims be construed as encompassing all such variations and modifications.
Claims
1. One or more computer-readable media, the one or more computer-readable media having instructions that, when executed by one or more processors of a system, cause the system to: Receive a data file, which is defined as a kernel-generated profile to be used for data transfer; A verification process is performed on the data file to determine the verification of the profile used to generate it; Generate a binary file corresponding to the data file, the binary file to be used in the profile; One or more keys for signing the binary file are generated, at least in part, based on the profile used to generate the binary file, which has been verified. as well as The binary file is signed using one or more keys to generate the profile.
2. The one or more computer-readable media according to claim 1, wherein performing the verification process comprises: Perform the first set of verifications on the data file; An intermediate file is generated, at least in part, based on the data file, the intermediate file being in a different format from the data file; and Perform a second set of verifications on the intermediate file.
3. One or more computer-readable media according to claim 1 or 2, wherein performing the verification process comprises: Verify the format of one or more entries within the data file; Verify one or more values within the data file; as well as Verify the dependencies between one or more values within the data file.
4. One or more computer-readable media according to any one of claims 1 to 3, wherein signing the binary file comprises: Generate a certificate chain corresponding to the data file; as well as The binary file is signed using the certificate chain.
5. One or more computer-readable media according to any one of claims 1 to 3, wherein the one or more keys are generated by the system's profile manager, and wherein signing the binary file comprises: The profile manager generates a certificate signing request (CSR) using the public key from one or more of the keys. The profile manager provides the CSR to the system's public key infrastructure (PKI); The certificate chain is generated by the PKI based at least in part on the CSR; and The profile manager uses the certificate chain to sign the binary file.
6. One or more computer-readable media according to any one of claims 1 to 5, wherein the binary file includes a TEST binary file, wherein the profile includes a TEST version profile, and wherein the instructions, when executed by the one or more processors of the system, further cause the system to: The TEST version profile is stored in the TEST database of the system, and the TEST database of the system is used to provide limited access to the TEST version profile; Receive an instruction to upgrade the TEST version profile to a production (PROD) version profile; The PROD version profile is generated at least in part based on the instructions for improving the TEST version profile; as well as The PROD version profile is stored in the PROD database of the system, which provides extended access to the PROD version profile.
7. The computer-readable medium of claim 6, wherein the one or more keys comprise a first set of one or more keys, and wherein generating the PROD version profile comprises: Generate a PROD binary file corresponding to the data file, the PROD binary file being used for the PROD version profile; Generate a second set of one or more keys for signing the PROD binary file; as well as The PROD binary file is signed using one or more keys from the second set to generate the PROD version profile.
8. The computer-readable medium of claim 7, wherein the TEST binary file is generated by the TEST profile manager of the system, wherein the first set of one or more keys is generated by the TEST profile manager, wherein the PROD binary file is generated by the PROD profile manager of the system, and wherein the second set of one or more keys is generated by the PROD profile manager.
9. One or more computer-readable media according to claim 8, wherein: Signing the TEST binary file includes: The TEST profile manager generates a first certificate signing request (CSR) using the first public key from one or more keys in the first group. The first CSR is provided to the public key infrastructure (PKI) of the system by the TEST profile manager; The first certificate chain is generated by the PKI based at least in part on the first CSR; and The TEST profile manager uses the first certificate chain to sign the TEST binary file to generate the TEST version profile; and Signing the PROD binary file includes: The PROD profile manager generates a second CSR using the second public key from one or more keys in the second group; The PROD profile manager provides the second CSR to the PKI; A second certificate chain is generated by the PKI based at least in part on the second CSR, the second certificate chain being different from the first certificate chain; and The PROD profile manager uses the second certificate chain to sign the PROD binary file to generate the PROD version profile.
10. A method for generating a profile, the method comprising: The system receives a data file, which is defined as the profile generated by the kernel for use in data transfer. The system performs a verification process on the data file to determine the verification of the profile used to generate it; The system generates a binary file corresponding to the data file, which is to be used in the profile. The system generates one or more keys for signing the binary file, based at least in part on the profile used to generate it, which has been verified. as well as The system uses one or more keys to sign the binary file to generate the profile.
11. The method of claim 10, wherein performing the verification process comprises: Perform the first set of verifications on the data file; An intermediate file is generated, at least in part, based on the data file, the intermediate file being in a different format from the data file; and Perform a second set of verifications on the intermediate file.
12. The method of claim 10 or 11, wherein performing the verification process comprises: Verify the format of one or more entries within the data file; Verify one or more values within the data file; as well as Verify the dependencies between one or more values within the data file.
13. The method according to any one of claims 10 to 12, wherein signing the binary file comprises: Generate a certificate chain corresponding to the data file; as well as The binary file is signed using the certificate chain.
14. The method according to any one of claims 10 to 12, wherein the one or more keys are generated by the system's profile manager, and wherein signing the binary file comprises: The profile manager generates a certificate signing request (CSR) using the public key from one or more of the keys. The profile manager provides the CSR to the system's public key infrastructure (PKI); The certificate chain is generated by the PKI based at least in part on the CSR; and The profile manager uses the certificate chain to sign the binary file.
15. The method according to any one of claims 10 to 14, wherein the binary file includes a TEST binary file, wherein the profile includes a TEST version profile, and wherein the method further comprises: The system stores the TEST version profile in the system's TEST database, which provides limited access to the TEST version profile. The system receives an instruction to upgrade the TEST version profile to a production (PROD) version profile; The PROD version profile is generated by the system based at least in part on the instructions for improving the TEST version profile; as well as The system stores the PROD version profile in the system's PROD database, which provides extended access to the PROD version profile.
16. The method of claim 15, wherein the one or more keys comprise a first set of one or more keys, and wherein generating the PROD version profile comprises: Generate a PROD binary file corresponding to the data file, the PROD binary file being used for the PROD version profile; Generate a second set of one or more keys for signing the PROD binary file; as well as The PROD binary file is signed using one or more keys from the second set to generate the PROD version profile.
17. A system comprising: Memory used to store briefs; and One or more processors coupled to the memory, the one or more processors being used to: Receive a data file, the data file being defined as the profile generated by the kernel for use in data transfer; A verification process is performed on the data file to determine the verification of the profile used to generate it; Generate a binary file corresponding to the data file, the binary file to be used in the profile; One or more keys for signing the binary file are generated, at least in part, based on the profile used to generate the binary file, which has been verified. as well as The binary file is signed using one or more keys to generate the profile.
18. The system of claim 17, wherein signing the binary file comprises: Generate a certificate chain corresponding to the data file; as well as The binary file is signed using the certificate chain.
19. The system of claim 17, wherein the one or more keys are generated by the system's profile manager, and wherein signing the binary file comprises: The profile manager generates a certificate signing request (CSR) using the public key from one or more of the keys. The profile manager provides the CSR to the system's public key infrastructure (PKI); The certificate chain is generated by the PKI based at least in part on the CSR; and The profile manager uses the certificate chain to sign the binary file.
20. The system according to any one of claims 17 to 19, wherein the binary file includes a TEST binary file, wherein the profile includes a TEST version profile, and wherein the one or more processors are further configured to: The TEST version profile is stored in the TEST database of the system, and the TEST database of the system is used to provide limited access to the TEST version profile; Receive an instruction to upgrade the TEST version profile to a production (PROD) version profile; The PROD version profile is generated at least in part based on the instructions for improving the TEST version profile; as well as The PROD version profile is stored in the PROD database of the system, which provides extended access to the PROD version profile.