Network communication system and provisioning secure element

The network communication system with a provisioning secure element securely distributes shared secret keys in non-cellular networks, addressing the lack of such techniques and establishing a secure channel between devices and operator systems.

JP2025158680APending Publication Date: 2025-10-17TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024061463
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-05
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

Existing technologies lack secure provisioning techniques for distributing shared secret keys in non-cellular networks.

Method used

A network communication system utilizing a provisioning secure element (PSE) that holds a first private key, sets a unique device identifier, generates a second private key based on the identifier and the first key, and securely distributes it to devices via the Internet, establishing a secure authenticated channel.

Benefits of technology

Enables secure distribution of shared secret keys in non-cellular networks, even with untrusted provisioners, ensuring a secure authenticated channel between devices and operator systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025158680000001_ABST
    Figure 2025158680000001_ABST
Patent Text Reader

Abstract

To provide a provisioning technique capable of safely distributing a shared private key regarding a non-cellular network.SOLUTION: A network communication system comprises an operator system which holds a first private key and a provisioning secure element (PSE). The PSE is used for performing provisioning of one or more devices which are connected with the operator system via the Internet. The PSE holds the first private key. When performing provisioning of a target device, the PSE sets a device identifier which is unique to the target device, generates a second private key on the basis of the device identifier and the first private key, and provides the device identifier and the second private key to the target device. The second private key is used as a shared private key in a communication between the target device and the operator system.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to provisioning of devices connected to the Internet. [Background technology]

[0002] Conventionally, there are known protocols for establishing a secure channel between peers that hold a shared secret key, such as Transport Layer Security (TLS) and Authentication and Key Agreement (AKA).

[0003] In cellular networks, the shared secret key is stored in a secure element called a SIM (Subscriber Identity Module) card. The SIM card is inserted into a user device to provision the device. The network operator also holds the shared secret key. A secure channel is established between the user device and the network operator using the shared secret key.

[0004] Patent Literature 1 discloses a technique for provisioning a user device in a cellular network. The user device includes a secure element configured to store data for one or more SIMs (Subscriber Identity Modules). A provisioning service loads SIM data associated with a carrier selected by the user into the secure element of the user device. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2013-535142 Summary of the Invention [Problem to be solved by the invention]

[0006] For non-cellular networks, provisioning techniques for securely distributing shared secret keys have yet to be established.

[0007] One object of the present disclosure is to provide a provisioning technique that allows for secure distribution of shared secret keys for non-cellular networks. [Means for solving the problem]

[0008] The first aspect relates to a network communication system. The network communication system includes an operator system that holds a first private key and a provisioning secure element. The provisioning secure element is used to provision one or more devices that are connected to an operator system via the Internet. The provisioning secure element holds the first private key. When provisioning a target device, the provisioning secure element sets a unique device identifier for the target device, generates a second private key based on the device identifier and the first private key, and provides the device identifier and the second private key to the target device. The second secret key is used as a shared secret key in communications between the target device and the operator system.

[0009] The second aspect has the following features in addition to the features of the first aspect. The target device is Holds the device identifier and second private key provided by the provisioning secure element, Encrypt the data using the retained second private key; Sending encrypted data and device identifiers to the operator system It may be configured as follows. The operator system is Receive encrypted data and a device identifier sent from the target device; generating a second private key based on the retained first private key and the received device identifier; Decrypt the encrypted data using the generated second private key It may be configured as follows.

[0010] The third aspect has the following features in addition to the first or second aspect. The device identifier may include a combination of an element identifier and reference information unique to the provisioned secure element. The provisioning secure element may use different reference information each time provisioning is performed.

[0011] The fourth aspect has the following characteristics in addition to those of the third aspect. The reference information may be a counter. The provisioning secure element may monotonically increment or decrement the counter each time provisioning is performed.

[0012] The fifth aspect has the following characteristics in addition to those of the fourth aspect. The counter may be set to a limit value.

[0013] The sixth aspect relates to a provisioning secure element, which is used to provision one or more devices that are connected to an operator system via the Internet. The operator system holds the first private key. The provisioning secure element includes a processor and a storage device that stores a first private key. When provisioning the target device, the processor sets a unique device identifier for the target device, generates a second private key based on the device identifier and the first private key, and provides the device identifier and the second private key to the target device. The second secret key is used as a shared secret key in communications between the target device and the operator system. [Effects of the Invention]

[0014] According to the present disclosure, even in non-cellular networks, a shared secret key can be securely distributed to a device by using a provisioning secure element. That is, device provisioning can be performed securely even in non-cellular networks. Device provisioning can be performed securely even if the provisioner is an untrusted third party. Then, by using the shared secret key, a secure authenticated channel can be established between the device and the operator system. [Brief explanation of the drawings]

[0015] [Figure 1] FIG. 1 is a conceptual diagram for explaining an overview of a network communication system and an overview of device provisioning. [Figure 2] FIG. 1 is a conceptual diagram illustrating communication between a device and an operator system in a network communication system. [Figure 3] FIG. 10 is a conceptual diagram illustrating a first example of a device identifier. [Figure 4] FIG. 10 is a conceptual diagram illustrating a second example of a device identifier. [Figure 5] FIG. 10 is a conceptual diagram for explaining a modified example. [Figure 6] FIG. 2 is a block diagram illustrating an example of a hardware configuration. DETAILED DESCRIPTION OF THE INVENTION

[0016] Embodiments of the present disclosure will be described with reference to the accompanying drawings.

[0017] 1. Overview 1 is a conceptual diagram for explaining an overview of a network communication system 1 and an overview of provisioning. The network communication system 1 includes one or more devices 10 and an operator system 20. Each device 10 and the operator system 20 are connected to each other via the Internet.

[0018] The device 10 is an IoT (Internet of Things) device connected to the Internet. Examples of the device 10 include an information terminal, a home appliance, a camera, a light, an air conditioner, an electronic lock, a sensor, and the like. The device 10 can also be called an edge device or a user device. The device 10 acquires data and transmits the data to the operator system 20 via the Internet. The device 10 may also receive data from the operator system 20 via the Internet.

[0019] The operator system 20 is a system managed by an operator. The operator may be a business operator, a service provider, a system administrator, or the like. The operator may collect various data from the device 10 and utilize the collected data. The operator may manage, operate, control, etc. the device 10. The operator system 20 receives data from the device 10 via the Internet. The operator system 20 may also transmit data to the device 10 via the Internet.

[0020] 1-1. Device provisioning Consider the provisioning of the device 10 below. The operator system 20 provides a first secret key (root key) K r For example, the first secret key K r is a string of 128 bits or more. In provisioning of the device 10, this first secret key K rA private key associated with the is provided (distributed) to the device 10 in a secure manner.

[0021] According to this embodiment, a "provisioning secure element 30" is used to provision one or more devices 10. In the following description, the provisioning secure element is referred to as a "PSE."

[0022] The PSE 30 exists outside the device 10 and the operator system 20. The PSE 30 has information processing capabilities, storage capabilities, and communication capabilities. For example, the PSE 30 is realized by a terminal or a medium. The PSE 30 may be a card-type medium equipped with an IC (Integrated Circuit) chip. The PSE 30 may be a contactless IC card or a contact IC card. The PSE 30 may be a Java (registered trademark) card. The communication method may be a near-field wireless communication method (NFC, contactless communication method) or a contact communication method. Examples of communication standards include ISO-14443 (NFC) and ISO-7816 (contact interface). As another example, the PSE 30 may be a smartphone equipped with an NFC interface or the like.

[0023] The PSE 30 uses the same first secret key (root key) K as the operator system 20. r The operator holds the first secret key K r The PSE 30 is prepared and issued in advance with the first secret key K r The first secret key K r will not leak from PSE30.

[0024] 1st private key K r The PSE 30 in which the above is written is provided (distributed) in advance by the operator to the provisioner. The provisioner is an entity that performs provisioning of the device 10, and is a third party different from the operator and the user of the device 10. The provisioner does not necessarily have to be a trustworthy entity.

[0025] In the following description, the device 10 that is the target of this provisioning will be referred to as the "target device 10" for convenience.

[0026] When provisioning the target device 10, the provisioner carries and uses the PSE 30. When using the PSE 30, the provisioner may be authenticated. For example, the provisioner may be requested to input a personal identification number (PIN) into the PSE 30. As another example, biometric authentication using the provisioner's fingerprint or the like may be performed. Such authentication of the provisioner is effective from the viewpoint of preventing misuse in the event that the PSE 30 is lost.

[0027] The provisioner presents the PSE 30 to the target device 10. For example, if the target device 10 and the PSE 30 both have an NFC interface, the provisioner may hold the PSE 30 against the target device 10. As another example, if the target device 10 and the PSE 30 both have an ISO-7816 interface, the provisioner may physically connect the PSE 30 directly to the target device 10. As yet another example, an IC card reader may be connected to the target device 10, and the PSE 30 may be connected to the IC card reader.

[0028] When the PSE 30 is presented to the target device 10, the PSE 30 communicates with the target device 10 and provides (transmits) the following two types of information to the target device 10:

[0029] The first piece of information is a device identifier I unique to the target device 10. dev During provisioning of the target device 10, the PSE 30 provides the device identifier I dev Set a different device identifier every time provisioning is performed. dev For example, the device identifier I dev is a string of numbers or a number. Device identifier I devSpecific examples will be described later.

[0030] The second piece of information is the first private key K r A second secret key K associated with d More specifically, the PSE 30 receives the device identifier I dev and the first secret key K r Based on this, the second secret key K d That is, as shown in the following formula (1), the second secret key K d is the device identifier dev and the first secret key K r It is expressed as a function of Formula (1): K d =f(K r ,I dev ) The function f is, for example, a key derivation function (KDF), such as HKDF (described in RFC-5869) or Argon2.

[0031] Device Identifier I dev Since the second secret key K is unique to the target device 10, d The device identifier I is also unique to the target device 10. dev and the second secret key K d The set of I is unique to the target device 10. The PSE 30 communicates with the target device 10 and receives the device identifier I dev and the second secret key K d to the target device 10. Meanwhile, the PSE 30 provides (transmits) the first secret key K r The first secret key K is not provided (transmitted) to the target device 10. r is not output from PSE30 to the outside.

[0032] The target device 10 receives a device identifier I provided (transmitted) from the PSE 30. dev and the second secret key K d The target device 10 receives the set of device identifiers I dev and the second secret key K d Hold.

[0033] In this way, the first secret key K r A second private key K associated with d is securely distributed to the target device 10. Even if the provisioner is an untrusted third party, the second secret key K d can be safely distributed to the target device 10.

[0034] 1-2. Secure Channel 2 is a conceptual diagram for explaining communication between the target device 10 and the operator system 20 after provisioning is completed. In the communication between the target device 10 and the operator system 20, the second secret key K d is used as the common secret key.

[0035] More specifically, the target device 10 holds a second secret key K d The device 10 then encrypts the data to be transmitted by using the encrypted data DAT and generates the encrypted data DAT. Then, the device 10 sends the encrypted data DAT together with the device identifier I dev to the operator system 20.

[0036] The operator system 20 receives the encrypted data DAT sent from the target device 10 and the device identifier I dev Meanwhile, the operator system 20 receives the first secret key K r Therefore, the operator system 20 holds the first secret key K r and the received device identifier I dev a second secret key K for communicating with the target device 10 based on d That is, the operator system 20 can generate the second secret key K for communicating with the target device 10 according to the above formula (1). d The operator system 20 can then generate the generated second secret key K d By using the above, the encrypted data DAT can be decrypted and the original data can be obtained.

[0037] In this way, the second secret key K d As a common secret key, a secure authenticated channel is established between the target device 10 and the operator system 20 .

[0038] 1-3.Effects As described above, according to the present embodiment, even in a non-cellular network, it is possible to securely distribute a shared secret key to the device 10 by using the PSE 30. That is, it is possible to securely provision the device 10 even in a non-cellular network. Even if the provisioner is an untrusted third party, it is possible to securely provision the device 10. Then, by using the shared secret key, it is possible to establish a secure authenticated channel between the device 10 and the operator system 20.

[0039] It is also possible to provision multiple devices 10 by repeatedly using a single PSE 30. In this case, a unique shared secret key is securely distributed to each device 10. The use of a different shared secret key for each device 10 allows a secure authenticated channel to be established between each device 10 and the operator system 20.

[0040] 2. Specific examples of device identifiers Hereafter, device identifier I dev A specific example of this will be described.

[0041] 2-1. First example Figure 3 shows the device identifier I dev Element identifier I pse is an identifier unique to the PSE 30. Element identifier I pse is, for example, a numeric string or a number. Different PSEs 30 have different element identifiers Ipse Typically, an operator will provide an element identifier I pse is given to each PSE 30. The PSE 30 receives the element identifier I pse Hold.

[0042] In the first example, the device identifier I dev is the element identifier I pse and reference information R. The reference information R is set to a different value each time provisioning is performed. The reference information R is, for example, a numeric string or a number. For example, the reference information R is a counter that changes with each provisioning. As another example, the reference information R may be a random number.

[0043] The PSE 30 sets the reference information R to a different value each time provisioning is performed. pse and reference information R. dev The PSE 30 sets the element identifier I pse The concatenation of the reference information R and the device identifier I dev As a result, the device identifier I dev The device identifier I unique to the target device 10 is also set to a different value for each provisioning. dev is set.

[0044] 2-2. Second example Figure 4 shows the device identifier I dev 1 is a conceptual diagram for explaining a second example. The second example is a specific example of the first example. In the second example, the reference information R is a counter C. That is, the device identifier I dev is the element identifier I pse and counter C. Device identifier I dev is the element identifier I pse and counter C.

[0045] The PSE 30 holds a counter C. The initial value of the counter C is arbitrary. The PSE 30 monotonically increases or decreases the counter C every time provisioning is performed. The PSE 30 executes the above formula (1) to obtain the second secret key K d Each time a value of 1 is generated, the counter C may be monotonically increased or decreased.

[0046] 2-3. Third Example In a third example, a single PSE 30 can issue a device identifier I dev A limit value is set for the number of device identifiers I. The limit value is set in advance, for example, by an operator. The PSE 30 does not detect a number of device identifiers I that exceeds the limit value. dev This makes it possible to limit the number of times a single PSE 30 can perform provisioning.

[0047] For example, a limit value is set for counter C in the second example above. For example, if counter C monotonically increases, an upper limit value is set for counter C. As another example, if counter C monotonically decreases, a lower limit value is set for counter C. When counter C reaches the limit value, PSE 30 prohibits further execution of provisioning. This makes it possible to set a limit on the number of provisionings that a single PSE 30 can perform.

[0048] 3. Various modifications A first secret key K prepared throughout the network communication system 1 r There is no particular limitation on the number of first secret keys K r In this case, each PSE 30 has the same first secret key K r However, as mentioned above, the element identifier I pse differs for each PSE30.

[0049] 5 is a conceptual diagram for explaining a modified example. In the modified example, a plurality of first secret keys K r A different first secret key K is prepared for each PSE 30. rThe multiple PSEs 30 are each assigned a different first secret key K r The operator system 20 holds a plurality of first secret keys K r and multiple PSE30 (element identifier I pse ) and maintains an allocation table showing the correspondence between them.

[0050] The operator system 20 receives the encrypted data DAT sent from the target device 10 and the device identifier I dev Receive the received device identifier I dev is the element identifier I pse The operator system 20 refers to the allocation table and assigns the received element identifier I pse The first secret key K associated with r Then, the operator system 20 selects the selected first secret key K r and the received device identifier I dev a second secret key K for communicating with the target device 10 based on d Generate.

[0051] In another variation, if a PSE 30 is lost, all information issued by the PSE 30 may be invalidated. For example, the element identifier I of the lost PSE 30 may be invalidated. pse Device identifier I, including dev As another example, a counter C outside the range from the initial value to the value at the time of loss is set as an invalid counter, and a device identifier I including the invalid counter is set as an invalid counter. dev Information relating to may be invalidated.

[0052] 4. Hardware configuration example FIG. 6 is a block diagram showing an example of the hardware configuration of each of the device 10, the operator system 20, and the PSE 30. As shown in FIG.

[0053] The device 10 includes a processor 11, a storage device 12, and an interface 13. The processor 11 executes various types of information processing. Examples of the processor 11 include a general-purpose processor, a specific-purpose processor, a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), an integrated circuit, etc. The storage device 12 stores various types of information. Examples of the storage device 12 include an HDD (Hard Disk Drive), an SSD (Solid State Drive), a volatile memory, a non-volatile memory, etc. Examples of the various types of information include a second secret key K d , device identifier I dev , etc. The interface 13 includes a communication interface for communicating with the operator system 20. Any communication method with the operator system 20 may be used. The interface 13 also includes a communication interface for communicating with the PSE 30. The communication interface for communicating with the PSE 30 may be an NFC interface or a contact communication interface.

[0054] The operator system 20 includes a processor 21, a storage device 22, and an interface 23. The processor 21 executes various types of information processing. Examples of the processor 21 include a general-purpose processor, a special-purpose processor, a CPU, an ASIC, an FPGA, an integrated circuit, etc. The storage device 22 stores various types of information. Examples of the storage device 22 include an HDD, an SSD, a volatile memory, a non-volatile memory, etc. Examples of the various types of information include a first secret key K r , second secret key K d , device identifier I dev , a function f, an allocation table, etc. The interface 23 includes a communication interface for communicating with the device 10. The communication method with the device 10 is arbitrary.

[0055] The PSE 30 includes a processor 31, a storage device 32, and an interface 33. The processor 31 executes various types of information processing. Examples of the processor 31 include a general-purpose processor, a special-purpose processor, a CPU, an ASIC, an FPGA, an integrated circuit, etc. The storage device 32 stores various types of information. Examples of the storage device 32 include an HDD, an SSD, a volatile memory, a non-volatile memory, etc. Examples of the various types of information include a first secret key K r , element identifier I pse , reference information R, counter C, device identifier I dev , function f, second secret key K d , etc. The interface 33 includes a communication interface for communicating with the device 10. The communication interface for communicating with the device 10 may be an NFC interface or a contact communication interface. The interface 33 may further include an interface for accepting a PIN or the like from the provisioner.

[0056] The PSE 30 may be a card-type medium equipped with an IC chip. The PSE 30 may be a contactless IC card or a contact IC card. The PSE 30 may be a Java (registered trademark) card. The PSE 30 may be a smartphone equipped with an NFC interface or the like. [Explanation of symbols]

[0057] 1 Network Communication System 10 devices 20 Operator System 30 Provisioning Secure Element (PSE)

Claims

1. an operator system that holds a first private key; a provisioning secure element used to provision one or more devices connected to the operator system via the Internet; Equipped with the provisioning secure element holds the first private key; When provisioning a target device, the provisioning secure element: setting a unique device identifier for the target device; generating a second private key based on the device identifier and the first private key; providing the device identifier and the second private key to the target device; It is configured as follows: The second private key is used as a shared private key in communications between the target device and the operator system. Network communication system.

2. 2. The network communication system of claim 1, The target device is holding the device identifier and the second private key provided by the provisioning secure element; encrypting data using the retained second private key; Transmitting the encrypted data and the device identifier to the operator system. It is configured as follows: The operator system receiving the encrypted data and the device identifier transmitted from the target device; generating the second private key based on the retained first private key and the received device identifier; Decrypting the encrypted data using the generated second private key. It was configured as Network communication system.

3. 3. The network communication system according to claim 1, the device identifier comprises a combination of an element identifier and reference information unique to the provisioning secure element; The provisioning secure element is configured to make the reference information different each time provisioning is performed. Network communication system.

4. 4. The network communication system according to claim 3, the reference information is a counter, The provisioning secure element is configured to monotonically increase or decrease the counter each time provisioning is performed. Network communication system.

5. 1. A provisioning secure element used to provision one or more devices connected to an operator system via the Internet, comprising: The operator system holds a first private key; The provisioning secure element comprises: a processor; a storage device for storing the first private key; Equipped with When provisioning a target device, the processor: setting a unique device identifier for the target device; generating a second private key based on the device identifier and the first private key; providing the device identifier and the second private key to the target device; It is configured as follows: The second private key is used as a shared private key in communications between the target device and the operator system. Provisioning Secure Element.

Citation Information

Patent Citations

  • Apparatus and method for provisioning subscriber ID data in a wireless network

    JP2013535142A