Systems and methods for using a participant identification module as a pseudonymous certification authority (PCA)
The SIM functions as a PCA to issue short-term certificates and separate server functions, addressing scalability and security issues in IoT device authentication, ensuring privacy and reducing tracking.
Patent Information
- Application Number
- JP2024573543
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-07-07
- Filing Date
- 2023-07-07
- Publication Date
- 2025-07-10
AI Technical Summary
Conventional PKI models for securing messages between IoT devices are not scalable and secure, leading to potential data leakage and device tracking issues.
Utilizing a subscriber identity module (SIM) as a pseudonymous certificate authority (PCA) to anonymize devices by verifying device identity and issuing short-term certificates, separating server functions into transport and data processing layers to maintain privacy and scalability.
The SIM-based solution provides secure, scalable, and private authentication for IoT devices by periodically updating short-term certificates, preventing tracking and reducing infrastructure burden.
Smart Images

Figure 2025521467000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to the authentication of communication devices. More particularly, but not exclusively, the present disclosure relates to the authentication of communication devices that use a subscriber identity module as a PCA.
Background Art
[0002] Conventional PKI models for securing messages between a growing number of devices are not scalable and are not secure from a privacy perspective. Point-to-point encryption can provide authentication and digital certificates can provide a secure environment for IoT devices to function, but there is still a possibility of data leakage and hacking with existing PKI schemes. PKI is a core component of TLS (Transport Layer Security), and the implementation of PKI for IoT brings the expected standardization and security, but more can be done to make PKI-based systems scalable and secure.
[0003] Between a client device and a server device, a PKI system uses a TLS handshake and both the client and the server exchange their certificates in the clear. In other words, device activity can be tracked every time a connection is established by the exchange that takes place during a conventional TLS handshake. Further, if all or most of the devices in an IoT or other environment use a conventional PKI model, it places a heavy burden on the PKI infrastructure system when trying to accommodate all devices that communicate with each other between vehicles, machines, and other devices.
[0004] Not all of the subject matter discussed in the Background section is necessarily prior art, and one should not assume that it is prior art solely based on the discussion in the Background section. In accordance with these guidelines, the recognition of a problem in the prior art discussed in the Background section, or a problem related to such subject matter, should not be treated as prior art unless it is clearly stated to be prior art. Instead, the discussion of any subject matter in the Background section should be treated as part of the inventor's approach to a particular problem and may itself be inventive.
Summary of the Invention
Means for Solving the Problems
[0005] In some embodiments, a method of using a subscriber identity module (SIM) as a pseudonym certificate authority (PCA) to anonymize a device having the SIM and reduce tracking of the device can include one or more processors and a memory coupled to the one or more processors. The memory can include computer instructions that, when executed by the one or more processors, cause the one or more processors to perform an operation of verifying a device identity presented by the device, where the SIM functions as a Registration Authority, and an operation of issuing a new certificate in response to a certificate sign request (CSR) submitted by the device, where the SIM functions as a Certificate Authority (CA).
[0006] In some embodiments, the SIM is an applet or virtual SIM stored within the device. In some embodiments, the SIM is a physical card.
[0007] In some embodiments, the SIM is securely provisioned with a copy of the device root CA certificate to verify the device identity certificate chain and a communication CA certificate to issue a new communication end-entity device certificate stored on the device or the SIM. In some embodiments, the SIM is an applet, the communication CA certificate has a public key, the device root CA certificate has a private key, and the private key is securely stored in the applet as part of device provisioning. In some embodiments, the device is provisioned with the device root CA certificate and the communication CA certificate at the factory or securely pushed remotely through a dedicated remote management server.
[0008] In some embodiments, one or more processors further perform device authentication by having the device obtain the current time from a trusted time source, having the device submit a new communication end-entity device certificate and the current time to the SIM, having the SIM verify the chain using a copy of the device root CA certificate, and having the SIM verify the date associated with the copy of the device root CA certificate using the current time. The method can further perform device authentication by having the SIM generate a secure random challenge, store it in the SIM with the current time, having the SIM encrypt the secure random challenge using the public key associated with the communication CA certificate to form an encrypted challenge, and having the SIM send the encrypted challenge to the device. The method can further perform device authentication by having the device decrypt the encrypted challenge using the private key associated with the device root CA certificate and provide the decrypted challenge, and having the device store the decrypted challenge.
[0009] In some embodiments, one or more processors further perform, by the device, an operation of generating a public / private key pair associated with a communication CA certificate, an operation of constructing a CSR including a challenge password by the device, an operation of generating a private key for signing the CSR by the device, and an operation of submitting the CSR to the SIM. The method further performs, by the SIM, an operation of obtaining a password and a time, an operation of checking the challenge password, an operation of verifying the CSR signature using the public key, an operation of checking rules and generating an expiration date from the current time, and an operation of issuing a new certificate by the SIM when all rules are checked and passed, for the CSR.
[0010] In some embodiments, the SIM acts as a PCA to generate a short-term end-entity certificate dedicated to signing broadcast messages. In some embodiments, the device obtains a new communication certificate periodically to prevent tracking.
[0011] In some embodiments, the method separates a server part responsible for transport functioning as a technical front-end from a server part responsible for data processing functioning as a business logic back-end, such that the device as a client remains unknown to the technical front-end, but it is still known that the device is a valid client.
[0012] In some embodiments, the method provides authentication between IoT devices in a scalable manner using a PKI infrastructure that uses short-term certificates.
[0013] In some embodiments, a system for authenticating a communication device by issuing a certificate includes a subscriber identification module (SIM) in the form of an applet that is securely linked to the device and used as a pseudonymous certification authority (PCA). In some embodiments, the SIM verifies the device identity presented by the device, where the SIM functions as a registration authority and issues a new certificate in response to a certificate signature request (CSR) submitted by the communication device, where the SIM is configured to function as a certification authority (CA).
[0014] In some embodiments, a copy of the device root CA certificate is securely provisioned to the SIM for verifying the certificate chain of the device identity, and a communication CA certificate is securely provisioned to the SIM for issuing a new communication end entity device certificate stored on the device or the SIM. In some embodiments, the system includes one or more processors of the SIM and the communication device, and the processors further perform device authentication by obtaining the current time from a trusted time source at the communication device and submitting the new communication end entity device certificate and the current time to the SIM. This authentication can further include the SIM using a copy of the device root CA certificate to verify the chain, using the current time to verify the date associated with the copy of the device root CA certificate, generating a secure random challenge and storing it with the current time in the SIM, encrypting the secure random challenge using the public key for the communication CA certificate to form an encrypted challenge, and transmitting the encrypted challenge to the device. The authentication can further include the device using the private key for the device root CA certificate to decrypt the encrypted challenge and provide the decrypted challenge, and storing the decrypted challenge at the device.
[0015] In some embodiments, one or more processors can further perform, by a communication device, an operation of generating a public / private key pair associated with a communication CA certificate for a certificate signature request (CSR), an operation of constructing a CSR including a challenge password, an operation of generating a private key for signing the CSR, and an operation of submitting the CSR to the SIM. The CSR further includes, by the SIM, an operation of obtaining a password and a time, an operation of checking the challenge password, an operation of verifying the CSR signature using the public key, an operation of checking rules and generating an expiration date from the current time, and an operation of issuing a new certificate by the SIM when all rules are checked and passed, where the new certificate is a short-term certificate.
[0016] In some embodiments, the system separates a server part responsible for transport functioning as a technical front end from a server part responsible for data processing functioning as a business logic backend, and the communication device as a client remains unknown to the technical front end, but it is still known that the communication device is a valid client.
[0017] In some embodiments, a system for authenticating a device by issuing a certificate can include a subscriber identification module (SIM) in the form of an applet that is securely linked to the device and used as a pseudonymous certification authority (PCA), a copy of a device root CA certificate used to verify a certificate chain of a device identity securely provisioned to the SIM, and a communication CA certificate used to issue a new communication end entity device certificate stored on the device or the SIM. In some embodiments, the SIM is configured to verify a device identity presented by a communication device. The SIM receives a new communication end entity device certificate and the current time to the SIM, verifies the chain using a copy of the device root CA certificate, uses the current time to verify the date associated with the copy of the device root CA certificate, generates a secure random challenge, stores it with the current time to the SIM, encrypts the secure random challenge using the public key associated with the communication CA certificate to form an encrypted challenge, and is configured to function as a registration authority by transmitting the encrypted challenge to the device for decryption and storage of the decrypted challenge by the device. In some embodiments, the SIM further issues a new certificate in response to a certificate signing request (CSR) submitted by the device, where the SIM functions as a certification authority (CA).
[0018] In some embodiments, the system, in response to the CSR, performs operations of generating a public / private key pair associated with the communication CA certificate on the device, constructing a CSR including a challenge password, generating a private key for signing the CSR, and submitting the CSR to the SIM. In some embodiments, the SIM obtains a password and a time, checks the challenge password, verifies the CSR signature using the public key, checks the rules, and generates an expiration from the current time. In some embodiments, the SIM further issues a new certificate if all rules are checked and pass.
[0019] In some embodiments, the system separates the server part responsible for transport, which functions as the technical front end, from the server part responsible for data processing, which functions as the business logic back end, and the device as a client remains unknown to the technical front end but is still known to be a valid client.
[0020] In some embodiments, the system issues a group of certificates with appropriate start / end dates to optimize access between the device and the SIM.
[0021] Non-limiting and non-exhaustive embodiments will be described with reference to the following drawings. In the drawings, like reference numerals represent like parts throughout the various figures unless otherwise specified. The sizes and relative positions of the elements in the drawings are not necessarily drawn to scale. For example, the shapes of the various elements are selected, enlarged, and positioned to make the drawings easier to view. The particular shapes of the elements drawn are selected to be easily recognizable within the drawings. Hereinafter, one or more embodiments will be described with reference to the accompanying drawings.
Brief Description of the Drawings
[0022]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
[0023] In the following description, some specific details are set forth in order to provide a thorough understanding of the various disclosed embodiments. However, one of ordinary skill in the art will understand that the embodiments may be practiced without one or more of these specific details, or with other methods, components, materials, etc. Well-known structures may be omitted or shown and described in simplified form to avoid obscuring the description of the embodiments needlessly.
[0024] These embodiments relate to communication between IoT devices, such as those defined by V2X (Vehicle-to-Everything). V2X is a vehicle communication system in which broadcast messages are exchanged between a vehicle and other entities. For obvious reasons, these messages need to be secured. Usually, here, for example, a PKI model is used to verify the signature of each broadcast message. Embodiments herein propose a way to deploy this PKI infrastructure in such an ecosystem in a scalable way that does not overburden the infrastructure. The embodiments are not limited to V2X systems, and the V2X system is used only as an example. Any embodiment that needs to issue short-term certificates can utilize these embodiments. For example, another direct application of this embodiment is the anonymization of client connections to a technology platform such as a public IoT Hub (refer to AWS IoT Core).
[0025] In the above context where a PKI model is used to secure messages between IoT devices, privacy is strongly demanded. To avoid IoT device tracking (or vehicle tracking), it is necessary to periodically update the device certificates used to sign broadcast messages or to connect to a backend server, which places a heavy burden on a dedicated certificate authority that needs to regularly provide new certificates for an ever-increasing number of devices. The "end entity" certificates used in this context in various embodiments herein are short-term and need to be updated frequently.
[0026] This problem is solved by using the SIM as a "pseudonymous certificate authority" and providing a scalable solution regardless of the number of devices involved.
[0027] Embodiments herein are premised on the ability of an IoT device to provide its device identity. The means for generating and / or managing this device identity can be done in many ways. For example, in the context of the present disclosure, the SIM can have two roles through a dedicated applet:
[0028] In the first role as a Registration Authority (RA), the SIM first (through the applet) verifies the device identity presented by the device (device authentication).
[0029] In the second role as a Certification Authority (CA), the SIM can issue a new certificate from the Certificate Signing Request (CSR) submitted by the device.
[0030] To fulfill these roles, the SIM (applet) needs to be properly and securely provisioned with the following information:
[0031] The root CA certificate (usually secret), referred to herein as the "device root CA certificate", is used to verify the device identity certificate chain.
[0032] The root CA certificate or intermediate CA certificate (usually public), referred to herein as the "communication CA certificate", is used to issue a new communication "end entity" device certificate. For this CA certificate, the private key also needs to be installed in the applet in a secure manner. The same intermediate CA certificate can be installed in multiple SIMs.
[0033] FIG. 1 shows the system 100 after remote management that can be realized at the time of factory issuance or provisioning, or by over-the-air (OTA) programming of the SIM and / or device. More specifically, the SIM as applet 106 functions as a device certification authority, i.e., CA 108 (usually secret), by being provisioned with a root CA 110 or intermediate CA 112 that is copied to the applet 106 as intermediate CA 114. Also, the root CA certificate 118 (usually public), which is used to issue a new communication “end entity” device certificate (see 500 in FIG. 5) for the device 104, is used to provide the intermediate CA 120 of the applet 106. Again, these certificates can be installed at the factory or securely pushed remotely through a dedicated remote management server. The device 104 is a communication device, and both the device 104 and the applet 106 can be part of another device 102, and note that such a device 102 can be, for example, a vehicle, an IoT device, or almost any other device that can have the communication device 104 and the applet 106.
[0034] FIG. 2 shows the system 100 in which the SIM or applet 106 functions as a PCA at the time when a device identity is issued for the device 104. FIG. 2 shows a system 100 similar to the system 100 shown in FIG. 1, but further shows that the device ID or device ID end entity certificate 115 is issued to the device 104 in a trustworthy manner, as represented by the step or process 105. Both the system 100 of FIG. 1 and FIG. 2 represent a preliminary or initial environment that enables some of the embodiments herein. FIG. 1 represents the provisioning of the applet 106, and FIG. 2 represents the provisioning of the device identity or device identity issuance to the device 104. Here, the process starts with device authentication.
[0035] More specifically, the method and system according to the embodiment are shown starting from the system 100 of FIG. 3 and the method or timeline 400 of FIG. 4, where the SIM functions as a PCA during device authentication for device 104.
[0036] The method 400 starts at 122, where the device 104 obtains the current time (from the network or other reliable time source). This time is reliable.
[0037] Next, at 412, the device 104 pushes or submits its previously obtained device identity certificate 115 (see FIG. 2) and the current time 122.
[0038] At 413, the SIM (applet 106) verifies the chain using the "device intermediate CA certificate" 114. At 414, the SIM or applet 106 further verifies the date associated with this certificate using the current time. At 415, the SIM or applet 106 generates a secure random challenge and stores it with the current time. Then, at 416, the SIM or applet 106 encrypts the random challenge with the "device identity certificate" public key 120 and, at 417, returns the challenge to the device 104. Then, at 124, the device can decrypt the encrypted random challenge using the device ID certificate private key (115) and store the random challenge.
[0039] A challenge password is required to authenticate a device that requests a "short-term" certificate. This authentication is mandatory.
[0040] FIGS. 5 and 6 show the system 100 and the timeline or method 600, and further show the steps of CSR submission and certificate issuance using the SIM as a PCA.
[0041] Method 600 begins, at 611, with device 104 generating a key pair (public / private). This key pair is associated with device communication certificate 500, which, in most embodiments, is a short-term or transient communication certificate.
[0042] At 612, device 104 constructs a CSR that includes a challenge password. At 613, device 104 signs the CSR request using the generated private key. Then, at 614, device 104 submits the CSR request to SIM or applet 106.
[0043] At 615, SIM or applet 106 obtains the password and time, and further, at 616, checks the challenge password. Next, at 617, SIM or applet 106 can verify the CSR signature using the provided public key. At 618, SIM or applet 106 checks rules (which may be part of the applet configuration) and generates an expiration from the current time. If SIM or applet 106 passes all rules or checks, at 620, SIM or applet 106 issues a new communication certificate 500.
[0044] In this regard, SIM or applet 106 acts as a PCA (Pseudonymous Certification Authority) that generates a short-term end entity certificate dedicated to signing broadcast messages. Since the "Communication CA" 116 is public, other entities can verify the "Device Communication" certificate chain and the signature of the received message.
[0045] This operation can be periodically performed by device 104 (or 102) to obtain a new communication certificate, thereby preventing tracking activities by malicious attackers. Thus, the embodiments solve the technical problem of providing privacy in a scalable manner that does not overly burden the PKI infrastructure.
[0046] In some various embodiments, the system or method can issue a group of certificates with appropriate start / end dates to optimize the access between the device and the SIM.
[0047] Some of the embodiments herein can be extended to the needs of other PKIs, and in particular can be extended to issue certificates with particularly short validity periods, or "short-term" certificates.
[0048] The strong security level provided by the SIM substantially guarantees a trustworthy chain. Further, note that the illustrated examples generally provide for the use of a virtual SIM or applet, but the same concept can also be applied to physical SIM cards with similar capabilities.
[0049] In some embodiments where the certificate is short-term, since the certificate expires in a short period of time, in practice, there is no need to provide a revocation mechanism.
[0050] Also, the remote management of the SIM as a PCA (applet) can ultimately invalidate or replace the "communication intermediate CA certificate" used to issue new "end entity" certificates. In other words, the service can be temporarily stopped through the remote management of the SIM as needed.
[0051] In relation to anonymization use cases of some embodiments, typically, an end-to-end secure channel is established between a client and a server based on mutual authentication. From the server's perspective, it is important to check whether the client attempting to connect is authorized. From the client's perspective, it is important to verify whether the target server is the expected server to avoid a man-in-the-middle attack. Certificates typically represent device identities. First, both the server and the client need to trust each other by checking their certificate chains. The problem is that during this process called the TLS handshake, both the client and the server exchange their certificates in plain text or in a state where they are subject to tracking. In other words, every time a connection is established using the conventional TLS handshake method, it is possible to track device activities. Clearly, as soon as encryption is enabled, it becomes impossible to access the exchanged data, but tracking remains possible. In a typical TLS handshake method, encryption is enabled during a step called "server finished" at the end of the TLS handshake process.
[0052] As shown in system 700 of FIG. 7, the solution provided herein includes separating a server portion responsible for transport (referred to herein as technical front end 702) from a portion responsible for data processing (hereinafter referred to as business logic back end 704). Short-term certificates 701, 703, etc., recommended in some embodiments, are used to connect to the technical front end 702. A device certificate 703 representing the device identity is used by the business logic back end 704, and a communication certificate 701 is used by the technical front end 702.
[0053] Therefore, from the perspective of the technical front end 702, the client's identity remains unknown. However, since the presented "short-term" certificate is valid and trustworthy, the technical front end knows that it is a valid client. As soon as a secure channel is established, the device identity (device certificate) can be exchanged in a confidential manner that guarantees privacy and anonymity.
[0054] At the end of the process according to the embodiment, since the process is still mutual authentication with additional anonymity of the client (meaning higher privacy), the security level is improved.
[0055] In any grammatical form, in the specific context where the terms "substantially", "about", or "usually" are used as modifiers in this disclosure and any appended claims, if there is no specific clarification regarding their explicit use (for example, for changing a structure, dimension, measurement, or any other characteristic), it should be understood that the characteristic may vary by up to 30 percent.
[0056] The terms "comprising" and "including", and their derivatives, shall be construed in an open, inclusive sense without limitation in all their syntactic contexts (e.g., "including but not limited to"). The term "or" is inclusive and means "and / or". The phrases "associated with" and "associated therewith", and their derivatives, can be understood to mean, among other things, included in, contained within, interconnected with, containing, contained within, connected to (with), coupled to (with), communicable with, cooperating with, interposed in, juxtaposed with, proximate to, connected to (with), having the characteristics of, etc.
[0057] Unless the context otherwise requires, throughout this specification and the appended claims, the word "comprise", and variations such as "comprises" and "comprising", are to be interpreted in an open, inclusive sense, such as "including, but not limited to".
[0058] References throughout this specification to "one embodiment" or "an embodiment" or "some embodiments" and variations thereof mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, the appearances of the phrases "in one embodiment" or "in an embodiment" in various places throughout this specification are not necessarily all referring to the same embodiment. Further, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0059] As used in this specification and the appended claims, the singular forms "a", "an", and "the" include plural referents unless the content and context clearly indicate otherwise. It should also be noted that the conjunctions "and" and "or" are generally employed in their broadest sense that includes "and / or" unless the content and context clearly dictate otherwise. Further, the configurations of "and" and "or" as described herein as "and / or" are intended to include embodiments that include all of the relevant items or concepts, and one or more other alternative embodiments that include only some of the relevant items or concepts.
[0060] In this disclosure, a serial list uses a comma, which may be known as an Oxford comma, a Harvard comma, a serial comma, or other similar term. Such a list is intended to connect words, clauses, or sentences such that items following the comma are also included in the list.
[0061] When context requires it in this disclosure, unless the context provides otherwise, the singular form means the plural and vice versa. All pronouns shall mean the individuals, entities, companies, or corporations to which they refer and include them. Also, the masculine form shall mean the feminine form and vice versa.
[0062] When configured as described herein, each computing device or processor may be transformed from a general-purpose and non-special-purpose computing device or processor into a composite device that includes hardware and software configured for specific and particular purposes that provides more than conventional functionality and solves specific technical problems with specific technical solutions. When configured as described herein, as long as any of the inventive concepts described herein are determined by an appropriate adjudicating authority to be subsumed in an abstract idea, an ordered combination of elements and limitations is clearly presented, and the abstract idea is transformed into its tangible and specific application to provide the required inventive concept.
[0063] The headings and "Abstract of the Disclosure" provided herein are for convenience only and do not limit or interpret the scope or meaning of the embodiments. Additional embodiments can be provided by combining the various embodiments described above. Embodiments can be modified and additional embodiments can be provided by adopting concepts from various patents, applications, and publications as needed.
Claims
1. A method of using a subscriber identity module (SIM) as a pseudonymous certification authority (PCA) to anonymize a device having the SIM and reduce tracking of the device, comprising: one or more processors and a memory coupled to the one or more processors, the memory including computer instructions that, when executed by the one or more processors, cause the one or more processors to verify a device identity presented by the device, where the SIM functions as a registration authority, and issue a new certificate in response to a certificate signing request (CSR) submitted by the device, where the SIM functions as a certification authority (CA). A method for performing the above operations.
2. The method according to claim 1, wherein the SIM is an applet stored in the device.
3. The method according to claim 1, wherein the SIM is securely provisioned with a copy of a device root CA certificate for verifying a certificate chain of the device identity and a communication CA certificate for issuing a new communication end entity device certificate stored in the device or the SIM.
4. The method according to claim 3, wherein the SIM is an applet, the communication CA certificate has a public key, the device root CA certificate has a private key, and the private key is stored in the applet in a secure manner as part of device provisioning.
5. The one or more processors are caused to obtain the current time from a reliable time source by the device, submit a new communication end entity device certificate and the current time to the SIM by the device, verify the chain using a copy of the device root CA certificate by the SIM, verify the date associated with the copy of the device root CA certificate using the current time by the SIM, generate a secure random challenge by the SIM and store it in the SIM together with the current time, encrypt the secure random challenge using the public key related to the communication CA certificate by the SIM to form an encrypted challenge, and send the encrypted challenge to the device by the SIM. The device decrypts the encrypted challenge using the private key related to the device root CA certificate and provides the decrypted challenge. The device stores the decrypted challenge. The method according to claim 3, further performing device authentication by performing the above.
6. One or more processors generate a certificate signing request (CSR). The device generates a public / private key pair associated with the communication CA certificate. The device constructs a CSR including a challenge password. The device generates a private key for signing the CSR. The device submits the CSR to the SIM. The SIM obtains a password and a time. The SIM checks the challenge password. The SIM verifies the CSR signature using the public key. The SIM checks the rules and generates an expiration date from the current time. The SIM issues a new certificate when all rules are checked and passed. The method according to claim 5, further performed by performing the above.
7. The method according to claim 1, wherein the SIM acts as a PCA to generate a short-term end-entity certificate dedicated to signing broadcast messages.
8. The method according to claim 1, wherein the method separates the server part responsible for transport, which functions as a technical front-end, from the server part responsible for data processing, which functions as a business logic back-end, and the device as a client remains unknown to the technical front-end, but it is still known that the device is a valid client.
9. The method according to claim 1, wherein the method uses a PKI infrastructure that uses short-term certificates to provide authentication between IoT devices in a scalable manner.
10. A system for authenticating a communication device by issuing a certificate, comprising: A subscriber identification module (SIM) in the form of an applet, securely linked to the device and used as a pseudonymous certification authority (PCA). The SIM verifies the device identity presented by the device, where the SIM functions as a registration authority. Issue a new certificate in response to a Certificate Signing Request (CSR) submitted by a communication device, where the SIM functions as a Certificate Authority (CA). A system configured as such. **Claim 11** The system according to claim 10, wherein the SIM is securely provisioned with a copy of the device root CA certificate for verifying the certificate chain of the device identity and a communication CA certificate for issuing a new communication end entity device certificate stored in the device or the SIM. **Claim 12** One or more processors of the SIM and the communication device perform the operation of obtaining the current time from a reliable time source by the communication device, the operation of submitting a new communication end entity device certificate and the current time to the SIM by the communication device, the operation of verifying the chain using a copy of the device root CA certificate by the SIM, the operation of verifying the date associated with the copy of the device root CA certificate using the current time by the SIM, the operation of generating a secure random challenge by the SIM and storing it in the SIM together with the current time, the operation of encrypting the secure random challenge using the public key related to the communication CA certificate by the SIM to form an encrypted challenge, the operation of transmitting the encrypted challenge to the device by the SIM, and the operation of decrypting the encrypted challenge using the private key related to the device root CA certificate by the device and providing the decrypted challenge, the operation of storing the decrypted challenge by the device to further perform device authentication, according to the system of claim 11. **Claim 13** One or more processors perform the Certificate Signing Request (CSR) by generating a public / private key pair associated with the communication CA certificate by the communication device, constructing a CSR including a challenge password by the communication device, generating a private key for signing the CSR by the communication device, submitting the CSR to the SIM by the communication device, obtaining the password and time by the SIM, checking the challenge password by the SIM, verifying the CSR signature using the public key by the SIM The SIM checks the rules and generates an expiration date from the current time, and when all rules are checked and passed by the SIM, issues a new certificate, where the new certificate is a short-term certificate, The system according to claim 12, further performed by doing so.
14. A system for authenticating a device by issuing a certificate, A subscriber identification module (SIM) in the form of an applet that is securely linked to the device and used as a pseudonymous certification authority (PCA), A copy of the device root CA certificate used to verify the certificate chain of the device identity securely provisioned to the SIM, A communication CA certificate used to issue a new communication end entity device certificate stored on the device or in the SIM Comprising The SIM Verifies the device identity presented by the communication device, where the SIM Receives a new communication end entity device certificate and the current time to the SIM, The SIM uses a copy of the device root CA certificate to verify the chain, The SIM uses the current time to verify the date associated with the copy of the device root CA certificate, The SIM generates a secure random challenge, stores it in the SIM together with the current time, The SIM encrypts the secure random challenge using the public key for the communication CA certificate to form an encrypted challenge, The SIM sends the encrypted challenge to the device for decryption and storage of the decrypted challenge by the device Functions as a registration authority by doing so, Responds to a certificate signing request (CSR) submitted by the device to issue a new certificate, where the SIM functions as a certification authority (CA) A system configured as such.
15. When the system responds to the CSR, The device generates a public / private key pair associated with the communication CA certificate, The device constructs a CSR including a challenge password, The device generates a private key for signing the CSR, The device submits the CSR to the SIM, The SIM obtains the password and the time, The operation of checking the challenge password by the SIM, and The operation of verifying the CSR signature using the public key by the SIM, and The operation of checking the rules by the SIM and generating an expiration date from the current time by the SIM, and The operation of issuing a new certificate when all the rules are checked and passed by the SIM The system according to claim 14, which performs the above operations.
Citation Information
Patent Citations
Data collection method, data collection apparatus, data collection device and computer-readable storage medium
JP2022531040A
Authentication process for issuing sequence of short-lived digital certificates
US10277406B1
Cryptographic methods and systems for managing digital certificates
US20190123915A1
Initial configuration method and terminal device
WO2021109967A1