Provisioning method and terminal device

By establishing a secure channel between the security module and the CA server within the V2X terminal device, the method addresses security risks and cost issues associated with existing V2X terminal configuration methods, ensuring secure and cost-effective provisioning.

JP7742346B2Active Publication Date: 2025-09-19CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2022533202
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-12-03
Filing Date
2020-11-30
Publication Date
2025-09-19
Estimated Expiration
2040-11-30

AI Technical Summary

Technical Problem

The existing methods for initial security configuration of Vehicle-to-Everything (V2X) terminal devices expose the session key outside the secure environment, leading to security risks such as physical attacks and high implementation costs due to the need for dual security modules (USIM and HSM) and pre-configuration of sensitive information.

Method used

A provisioning method that establishes a secure channel directly between the security module (USIM or integrated USIM/HSM) and the Certificate Authority (CA) server, obtaining digital certificates within this secure environment, eliminating the need to transmit the session key outside and reducing the reliance on expensive dual security modules.

Benefits of technology

This approach enhances security by preventing session key exposure to physical attacks and reduces implementation costs by integrating security functions, ensuring secure and cost-effective initial configuration of V2X terminal devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007742346000001
    Figure 0007742346000001
  • Figure 0007742346000002
    Figure 0007742346000002
  • Figure 0007742346000003
    Figure 0007742346000003
Patent Text Reader

Abstract

The present application provides a provisioning method and a terminal device, the provisioning method being applied to the terminal device, and including: a security module establishing a secure channel with a certificate authority (CA) server, obtaining a session key through the secure channel, and obtaining a digital certificate from the CA server, where the security module is for realizing the function of a universal subscriber identity module (USIM).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present application relates to the field of Internet of Vehicles (IoV), and in particular to a provisioning method and a terminal device.

[0002] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims priority from Chinese Patent Application No. 201911219000.X, filed in China on December 3, 2019, the entire contents of which are incorporated herein by reference. [Background technology]

[0003] To reduce the impact of the introduction of Vehicle-to-Everything (V2X) technology on enterprise production, the initial security configuration of IoV terminals should minimize dependency on the security environment and security capabilities of enterprise production. Therefore, it is necessary to seek simpler and more effective methods for V2X terminal identity authentication and information security interaction, and minimize the costs of upgrading and modifying enterprise production lines.

[0004] The Fifth Generation Automotive Association (5GAA) proposed an online initial security configuration method based on the Generic Bootstrapping Architecture (GBA) to avoid offline loading and pre-configuration of X.509 digital certificates on the production line, thereby reducing the cost of security modifications in enterprise production environments. However, the proposed method has the problem that the shared session key (Ks_NAF) is transmitted and exposed outside the secure environment, which poses security risks such as physical attacks. Summary of the Invention [Problem to be solved by the invention]

[0005] The embodiments of the present application provide a provisioning method and a terminal device for solving the problem in the related art that a session key needs to be transmitted between a Universal Subscriber Identity Module (USIM) and a Hardware Security Module (HSM) of a terminal device, resulting in the session key being transmitted outside a secure environment, which presents security risks such as physical attacks and makes it impossible to ensure security of provisioning. [Means for solving the problem]

[0006] To solve the above technical problems, an embodiment of the present application provides a provisioning method applied to a terminal device, the method comprising: The security module , security module and Certificate Authority (CA) Server The CA server uses the session key shared by establishing a secure channel with C obtaining a digital certificate from the A server; The security module is for implementing the functionality of a Universal Subscriber Identity Module (USIM).

[0007] Optionally, if the CA server is an Enrollment Certificate Authority (ECA) server, the digital certificate is an Enrollment Certificate (EC), and obtaining the digital certificate from the CA server comprises: generating a public and private key pair for applying for EC by the security module; and obtaining an EC from an ECA server using the public and private key pair.

[0008] Optionally, if the CA server is an Enrollment Certification Authority (ECA) server, the digital certificate is an Enrollment Certificate (EC), and after obtaining the digital certificate from the CA server: The security module Further comprising storing the EC.

[0009] Furthermore, if the CA server is a Anonymous Certificate Authority (PCA) server, the digital certificate is a Anonymous Certificate (PCA), and obtaining the digital certificate from the CA server includes: The security module signs the PC application message using a private key corresponding to the registration certificate (EC); and obtaining a PC from a PCA server based on the PC application message.

[0010] Specifically, obtaining a PC from the PCA server includes: The method includes receiving a feedback message sent from a PCA server, and using the public key of the PCA server to perform signature verification on the received feedback message to obtain a PC.

[0011] Specifically, after obtaining the PC from the PCA server, The security module uses a private key corresponding to the PC to sign a message of the direct connection communication service of the PC5 interface; Signed M and transmitting the message to an external device.

[0012] Optionally, if the CA server is an Enrollment Certification Authority (ECA) server, the digital certificate is an Enrollment Certificate (EC), and after obtaining the digital certificate from the CA server: The security module transmitting the EC to a hardware security module (HSM); The HSM stores the EC.

[0013] Further, obtaining a digital certificate from the CA server comprises: generating a public / private key pair for the HSM to apply for EC; the HSM sending the public key for applying for EC to the security module; The security module uses the public key to obtain an EC from an ECA server.

[0014] Optionally, if the CA server is a Anonymous Certificate Authority (PCA) server, the digital certificate is a Anonymous Certificate (PCA), and obtaining the digital certificate from the CA server comprises: The security module Sending the PC to a Hardware Security Module (HSM); The HSM stores the PC.

[0015] Further, obtaining a digital certificate from the CA server comprises: generating a public / private key pair for the HSM to apply for the PC; the HSM sending the public key to the security module to claim the PC; The security module uses the public key to obtain the PC from the PCA server.

[0016] Furthermore, after obtaining a digital certificate from the CA server, The security module uses a private key corresponding to the PC to sign a message of the direct connection communication service of the PC5 interface; Signed M and transmitting the message to an external device.

[0017] Specifically, the security module and the CA server establish a GBA secure channel in the manner of Generic Bootstrap Architecture (GBA) based on Universal Integrated Circuit Card (UICC).

[0018] An embodiment of the present application further provides a terminal device, the terminal device comprising: Security Module and Certificate Authority (CA) Server The CA server uses the session key shared by Establish a secure channel with C A security module configured to obtain a digital certificate from a server; The security module is for implementing the functionality of a Universal Subscriber Identity Module (USIM).

[0019] An embodiment of the present application further provides a terminal device, the terminal device comprising: a transceiver; and a processor; The processor controls the security module to perform the following steps: Security Module and Certificate Authority (CA) Server The CA server uses the session key shared by establishing a secure channel with C obtaining a digital certificate from the A server; The security module is for implementing the functionality of a Universal Subscriber Identity Module (USIM).

[0020] An embodiment of the present application provides a computer-readable storage medium having a computer program stored therein, the computer program causing the processor to perform the steps of the provisioning method when executed by the processor. [Effects of the Invention]

[0021] The beneficial effects of the present invention are as follows:

[0022] In the above solution, a secure channel is directly established between a security module capable of realizing the functions of a USIM and a CA server, and a session key and digital certificate are obtained from the CA server through the secure channel. This prevents the session key used to apply for a digital certificate from being transmitted outside the secure channel, reducing the probability of the session key being subjected to physical impact, reducing security risks, and improving provisioning security. [Brief explanation of the drawings]

[0023] [Figure 1]1 shows a schematic diagram of an autonomous method for offline filling in a production line. [Figure 2] A schematic diagram of the DCM agent method for offline filling in a production line is shown. [Figure 3] A schematic diagram of the GBA is shown. [Figure 4] 1 shows an architecture diagram of a PC application based on Transmission Layer Security (TLS). [Figure 5] 1 shows a schematic diagram of security risks in the implementation of GBA-based terminals in the related art; [Figure 6] This shows a schematic diagram of the security risks when the GBA-based configuration scheme proposed by 5GAA is used for PC applications. [Figure 7] 1 shows a flowchart of a provisioning method according to an embodiment of the present application. [Figure 8] 1 shows a schematic diagram of a security realization architecture based on GBA of an EC application according to an embodiment of the present application. [Figure 9] 1 shows a schematic diagram of a GBA-based security realization architecture for PC applications according to an embodiment of the present application; [Figure 10] 1 shows a schematic diagram of a USIM architecture according to an embodiment of the present application; [Figure 11] 1 shows a schematic diagram of a module of a terminal device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION

[0024] First, the related art relating to the embodiments of the present application will be briefly described below.

[0025] Currently, offline loading on the production line is the main method for achieving initial security configuration of V2X terminal equipment (including on-board units (OBUs) and roadside units (RSUs)), and provisioning can be performed on the HSM in the equipment. Here, the provisioning process of OBU equipment before shipping a V2X-enabled automobile is taken as an example. Other types of V2X terminals have similar processing processes.

[0026] According to the implementation method, there are two methods for offline filling in the production line: the autonomous method and the Device Configuration Manager (DCM) agent method, and the processes are shown in Figure 1 and Figure 2, respectively.

[0027] In the autonomous approach, a production line worker triggers the HSM security module of the OBU device via an external device to generate a public / private key pair, or generates a public / private key pair via an external encryption device and then injects it into the HSM. At the same time, the production line also injects the address information and digital certificate of an Enrollment Certificate Authority (ECA) server. The production line worker then triggers the OBU device to access the ECA server. The OBU device uses the ECA server's digital certificate to verify its identity and establish a secure communication channel between them. Finally, under the protection of the secure channel, the OBU device uploads the public key to the ECA server, applies for and downloads an Enrollment Certificate (EC) digital certificate, and securely stores it in the HSM.

[0028] The operating principle of the DCM agent approach is similar to that of the autonomous approach, but the implementation process is different. In the DCM agent approach, the production line deploys DCM agent nodes, which pre-establish mutual authentication with the ECA server, establish a secure communication channel, and provide a unified server for all vehicles soon to be shipped. During the initial security configuration process, the DCM generates a public / private key pair for the OBU device and interacts with the ECA server on behalf of the OBU terminal device to apply for and download an EC digital certificate. Finally, the DCM securely injects the generated public / private key pair, the obtained EC digital certificate, the ECA server certificate, and the ECA server address information into the OBU HSM, completing the initial security configuration of the OBU device.

[0029] In its study report, "Efficient Provisioning System Simplifications," the 5GAA proposed an initial security configuration method for V2X terminal equipment based on GBA technology. This method uses a USIM and its code number (e.g., International Mobile Subscriber Identification Number (IMSI), Mobile Station International Subscriber Directory Number (MSISDN), Integrated Circuit Card Identity (ICCID), etc.) as the initial identifier of the V2X terminal equipment and represents the identity of the equipment. Based on the USIM, the V2X terminal equipment can access the carrier network and perform bilateral authentication and key agreement with the network through the Authentication and Key Agreement (AKA) mechanism, generate and provide a shared session key Ks_NAF for the application, and finally establish a secure transmission channel, such as a TLS secure channel, between the V2X device and the ECA server.

[0030] Figure 3 shows the GBA generic bootstrap architecture, which consists of the following parts:

[0031] A11: Software supporting GAA capabilities provided by V2X terminal equipment, i.e., GAA Server A12: V2X client software in a V2X terminal that interfaces with the GAA Server software A13: USIM that communicates with GAA Server software A14: Network Application Function (NAF) software on the ECA server A15: Bootstrapping Server Function (BSF) Core Network Element

[0032] According to the network GBA security authentication method, a V2X terminal device can use the root key in the USIM card to perform two-way identity authentication with a mobile cellular network through the AKA mechanism and negotiate with the BSF to generate a shared session key Ks_NAF. Subsequently, upon receiving a certificate application request from the V2X terminal device, the ECA server interacts with the BSF to obtain the session key Ks_NAF and authenticates the identity of the V2X terminal device based on Ks_NAF. After identity authentication is successful, the ECA accepts the EC certificate application request from the V2X terminal device and, after successful verification, issues an EC digital certificate to the V2X terminal device. During the above process, application layer information interaction between the ECA server and the V2X terminal device is performed over a secure channel established based on the shared session key Ks_NAF, ensuring the security of message transmission.

[0033] The GBA-based solution described above uses the USIM as the initial identity identifier of the V2X terminal device, eliminating the need to pre-configure any security credentials (e.g., X.509 digital certificates). A secure channel can be established from the V2X terminal device to the ECA server via the mobile cellular network, and device provisioning can be completed online. In this solution, the operations and interactions related to the initial security configuration are completed by the V2X terminal device itself, eliminating the need to rely on the secure environment of the production line to ensure the security of the configuration operation, as is the case with offline loading methods. This significantly reduces the cost of upgrading and modifying an enterprise's production line.

[0034] In addition, this method is applicable to scenarios where the place of production and the place of sale of automobiles are not the same region. The network-side configuration allows the on-board OBU terminal to be docked with the ECA at the place of sale or use of automobiles, and solves the problem of which ECA server's X.509 digital certificate should be pre-configured for the on-board OBU terminal during the automobile production process.

[0035] In the identity authentication and secure channel establishment process, the code number in the USIM can be used as the unique identifier of the V2X device, to avoid the situation where the V2X terminal device is not authenticated in the initial state and cannot be authenticated based on the ECA server X.509 digital certificate alone.

[0036] The Technical Specification for Vehicle-to-Road Cooperation-Based Communication (Anonymous) Certificate Management, currently being drafted by the China Intelligent Transportation Industry Alliance, proposes a method for V2X terminal devices (including OBUs, RSUs, etc.) to apply for and obtain pseudonymous certificates. The overall concept of this method is to use Transport Layer Security (TLS) to perform identity authentication between a Pseudonym Certificate Authority (PCA) server and the V2X terminal device, establish a TLS secure communication channel, and then encourage the V2X terminal device to interact with the PCA server through the TLS secure channel to apply for a PCA digital certificate. The section of the draft specification related to pseudonymous certificate application is described as follows:

[0037] This standard is applicable when an on-board unit (OBU) or roadside unit (RSU) has a valid registration certificate granted by an ECA, and can use it to apply for a communication (anonymity) certificate from an ACA, perform information interaction with an RSU or an OBU, obtain related information services, and perform signature verification on the obtained information. Note that this standard is also applicable when an OBU applies for a communication (anonymity) certificate from an ACA to communicate with another OBU.

[0038] The application programming interface (API) in this specification uses the Hypertext Transport Security Protocol (HTTPS), TLS 1.2 or later is recommended, TLS 1.3 is recommended, supports the standard HTTPS Transport Control Protocol (TCP) port 443, and uses X.509 certificates for identity authentication between components.

[0039] Here, an Authorization Certificate Authority (ACA) is an organization that manages communication (anonymous) certificates, ie, a PCA in this specification.

[0040] To ensure the security of the process of applying for and obtaining a PC, a TLS scheme may be implemented in the V2X terminal as shown in Figure 4. An X.509 device certificate is pre-configured in the HSM for the V2X terminal device, and a TLS secure channel is established between the HSM and the PCA server to ensure communication security. A public and private key pair for the PC is generated within the secure environment of the HSM, and the public key and device information are reported over the TLS secure channel, and the PC digital certificate is applied for, downloaded, and securely stored. The entire scheme is carried out in a secure environment, ensuring the security of the entire process.

[0041] In its research report titled "Efficient Provisioning System Simplifications," 5GAA proposed a method for initial security configuration of V2X terminal equipment based on Generic Bootstrapping Architecture (GBA) technology. Applying this method to PC applications can avoid the need to pre-configure X.509 certificates and reduce the cost of modifying production lines for enterprises.

[0042] Disadvantages of related technologies: The secure initialization process of V2X terminal equipment has very strict requirements for security, as it involves the provisioning of sensitive parameters and information such as keys, digital certificates, etc. Therefore, it is necessary to ensure the security of each link, including the production environment, terminal equipment, and message interaction.

[0043] 1.1 Offline filling on production lines The initial security configuration method for offline loading on the production line requires the generation of a public / private key pair outside the V2X terminal device, followed by an agent to apply for an EC digital certificate. This places extremely high security requirements on the production environment of the manufacturer or V2X terminal supplier (depending on who completes the initial security configuration work). To meet various production safety requirements, such as compliance, audit, and management control, enterprises must invest a great deal of time and money in upgrading and modifying the production line and providing security training to production line workers.

[0044] Currently, many overseas brand automobile companies with sufficient capabilities have established a safe production environment and are using offline refueling for production. However, the majority of Chinese domestic brands do not have such a safe production environment. Forcing them to use offline refueling for production would incur extremely high costs. Therefore, a simpler and safer solution is needed.

[0045] 1.2 Online EC configuration based on GBA technology The implementation method currently proposed by 5GAA on the V2X terminal device side has a security loophole, which poses a security risk due to a physical attack on the shared session key Ks_NAF. The specific reasons are as follows:

[0046] To ensure the security of the initial security configuration process of the V2X terminal device, it is generally required that sensitive security parameters and information (e.g., public and private key pairs, shared keys, various intermediate keys, etc.) related to the process are processed in a local secure environment of the device and must not leave the local secure environment during their lifecycle. The local secure environment of the device is generally provided by a hardware module that has been evaluated and has achieved a certain security level, such as a USIM or a Hardware Security Module (HSM). It is also necessary to ensure the security of message transmission in order to realize the security of communications between the V2X terminal device and the outside world. Corresponding to the initial security configuration process of the V2X terminal device, a secure communication channel is required between the V2X terminal device and the ECA server, and on the terminal side, the secure channel should be terminated in the local security module of the device to ensure that all information interactions take place in a secure environment.

[0047] In the implementation solution proposed in the 5GAA report, the HSM is the target of initial security configuration for the V2X terminal device. A public and private key pair for applying for EC is generated by the HSM, and the HSM and ECA server establish a TLS secure channel using a shared session key (Ks_NAF) generated by the USIM based on GBA technology. However, limited to the V2X terminal device architecture, the USIM is an independent security entity located outside the HSM. Therefore, the USIM must transmit the shared session key (Ks_NAF) generated by the GBA mechanism to the HSM via a transmission channel outside the secure environment. This exposes the shared session key (Ks_NAF) outside the secure environment, particularly through the application processor (AP), which exposes it to security risks such as physical attacks. If the shared session key (Ks_NAF) for establishing the secure channel is leaked during the transmission process, the security of message interactions between the V2X terminal device and the ECA server cannot be ensured.

[0048] Due to the above security risks, enterprises must conduct a security assessment of these risks when selecting a technology solution. Only if the risks are controllable can the GBA initial security configuration solution be used, which greatly limits the application scope of the solution.

[0049] In addition, when the GBA solution proposed by 5GAA is implemented in a terminal, the HSM is responsible for generating public and private key pairs, establishing a TLS secure channel, and applying for, downloading, and storing EC certificates, while the USIM is responsible for generating the associated session keys based on GBA technology. This requires the terminal to simultaneously support two security modules, the USIM and the HSM, which makes the HSM security hardware expensive and increases the terminal implementation costs.

[0050] A relatively straightforward solution to the above drawbacks is to integrate and package the USIM and HSM into the same physical module or chip to prevent key leakage during transmission and improve security. However, such a terminal chip or module product does not currently exist, and therefore cannot be implemented in V2X terminal devices at this stage.

[0051] 1.3 TLS-based PC deployment method The Technical Specifications for Vehicle-to-Vehicle Communication (Anonymous) Certificate Management proposes using TLS to apply for anonymous digital certificates for V2X terminal devices and requires the use of X.509 certificates to establish secure channels from V2X terminal devices to PCA servers. This means that automotive companies or V2X terminal device suppliers must pre-configure X.509 digital certificates for V2X terminal devices, which requires production line upgrades. At the same time, pre-configuring X.509 digital certificates involves the configuration of highly sensitive security information such as keys, so this process imposes strict requirements on a secure production environment, which incurs high costs for companies to upgrade their production lines.

[0052] 1.4 Online deployment of PC based on GBA technology The GBA-based provisioning method proposed by the 5GAA in its "Efficient Provisioning System Simplifications" study report is primarily used for provisioning ECs. This method is primarily used to complete EC provisioning and is not designed for initial PC application. Using this method for PC application poses potential security risks, such as physical attacks, on the terminal. Similar to the problem shown in Figure 5, this causes the session key Ks_NAF to be exposed outside the secure environment during the transmission process, posing a security risk that Ks_NAF may be tampered with and leaked, as shown in Figure 6.

[0053] The present application provides a provisioning method and a terminal device that address the problem in the related art that a session key needs to be transmitted between a USIM and an HSM of a terminal device, and that the session key is transmitted outside a secure environment, posing security risks such as being susceptible to physical attacks.

[0054] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be described in detail below with reference to the drawings and specific embodiments.

[0055] As shown in FIG. 7, the provisioning method of the present application is applied to a terminal device, The security module , security module and Certificate Authority (CA) Server The CA server uses the session key shared by establishing a secure channel with C A. obtaining a digital certificate from the server.

[0056] It should be noted that the security module in the embodiment of the present application is for realizing the functions of a Universal Subscriber Identity Module (USIM). That is, when the security module only realizes the functions of a USIM, the security module is a USIM. Alternatively, when the security module is further used to realize the functions of a USIM and a Hardware Security Module (HSM), it may be understood as representing the integration of a USIM and an HSM in a terminal device, and as having an HSM capable of realizing the USIM functions in the terminal device.

[0057] It should be noted that in this method, a secure channel is directly established between a security module capable of implementing the USIM function and a CA server, and when applying for a digital certificate, the USIM uses a session key to encrypt and protect the application message. There is no need to send the session key from the USIM to an HSM. The session key is not exposed outside the secure environment, reducing the probability of the session key being subjected to physical attacks.

[0058] It should be noted that the terminal device described in the embodiments of the present application is a V2X terminal device based on GBA technology, and may also be other types of V2X terminal devices such as OBU, RSU, pedestrian wearable devices, Internet of Things terminal devices, etc. This solves the problem that the shared session key (Ks_NAF) generated by the GBA negotiation is transmitted outside the local secure environment of the terminal, thereby eliminating security risks such as physical attacks.

[0059] It should be noted that the embodiment may be used to apply for an Enrollment Certificate (EC) or a Pseudonym Certificate (PC), where if the digital certificate is an EC, the CA server is an Enrollment Certificate Authority (ECA) server, and if the digital certificate is a PC, the CA server is a Pseudonym Certificate Authority (PCA) server.

[0060] The specific implementation process of applying for two types of certificates will be described below from the perspective of applying for EC and PC. In the following, the security module is USIM as an example.

[0061] (1) Apply for EC Referring to Figure 8, Figure 8 is an architecture diagram of a method for realizing GBA security. Here, the V2X terminal equipment includes an application processor, an LTE-V2X communication module connected to the application processor, and an LTE-Uu communication module connected to the application processor. The LTE-Uu communication module includes a modem and a USIM. Specifically, a secure channel is established between the USIM and an ECA server, and the USIM obtains EC from the ECA server through the secure channel. It should be noted that in this case, an HSM may or may not exist. Generally, the HSM may be omitted to reduce the production cost of the terminal equipment.

[0062] Specifically, before obtaining an EC from the ECA server, the USIM further needs to generate a public key and a private key pair for applying for an EC, and use the public key and private key pair to obtain an EC from the ECA server. After obtaining the EC, the USIM is further used to store the EC.

[0063] Specifically, the USIM and the ECA server establish a GBA secure channel using a Generic Bootstrap Architecture (GBA) (GBA_U) method based on a Universal Integrated Circuit Card (UICC). The GBA_U solution ensures that the shared session key Ks_NAF or a derived next-level key is entirely generated, stored, and used by the USIM, ensuring that the secure channel between the V2X terminal device and the ECA server is terminated within the USIM on the terminal side. This eliminates the security risks, such as physical attacks, that arise from transmitting the shared session key Ks_NAF or a derived next-level key to the HSM in an insecure environment, as occurs in the methods of the related art.

[0064] It should be further noted that the terminal device can further realize the transmission of a direct connection communication service, specifically, the USIM uses a private key corresponding to the EC to sign a message of the direct connection communication service of the PC5 interface, and sends the signed message of the direct connection communication service of the PC5 interface to the external device.

[0065] That is, in this case, the USIM is the local security module responsible for realizing the initial security configuration of the V2X terminal equipment, and the generation, storage, and use of session keys and password public / private keys, as well as the application, storage, and use of EC, are all performed by the USIM security module.The USIM is a multi-functional security entity with a security level of EAL 4+, and has functions such as random number generation, password algorithm calculation, and secure storage, so it has the ability to safely realize the initial security configuration of the V2X terminal equipment.

[0066] In this solution, the V2X terminal device triggers the USIM to generate a public and private key pair used for EC application. The V2X terminal device then invokes the supported GBA security authentication capability to access the ECA server over the mobile cellular network. The V2X terminal device then negotiates and generates a shared session key Ks_NAF, establishing an initial secure trust relationship between the V2X terminal device and the ECA server. The ECA server verifies whether the identity of the V2X terminal device is legitimate and valid based on the shared session key Ks_NAF. After the verification is successful, the ECA server and the V2X terminal device establish a secure transmission channel to ensure the security of data interactions between them. The secure channel can be established using the session key Ks_NAF or a next-level session key derived based on Ks_NAF. The derived key calculation is performed in the secure environment of the USIM.

[0067] In short, in this case, the main roles of the USIM of the terminal equipment include:

[0068] B11. Establish a GBA secure channel with the ECA server and use the GBA_U method preferentially. Generate a public / private key pair for B12.EC application. B13. Interact with the ECA server via the GBA secure communication channel to apply for and download an EC digital certificate and an ECA server certificate. B14.EC and associated public / private key pairs are securely stored locally.

[0069] (2) Apply for a PC It should be noted that in this case, the V2X terminal equipment includes an application processor, an LTE-V2X communication module connected to the application processor, and an LTE-Uu communication module connected to the application processor, and the LTE-Uu communication module includes a Modem and a USIM. Specifically, a secure channel is established between the USIM and a PCA server, and the USIM obtains a PC from the PCA server through the secure channel. It should be noted that in this case, an HSM may or may not be present. Generally, the HSM may be omitted to reduce the production cost of the terminal equipment.

[0070] Specifically, before acquiring a PC from the PCA server, the USIM further needs to generate a public key and a private key pair for applying for a PC, and then use the public key and private key pair to acquire a PC from the PCA server. After acquiring the PC, the USIM is further used to store the PC.

[0071] It should be noted that the role of the EC is to authenticate the identity of the V2X terminal device, perform signature protection on the PC request message, and apply for a PC. Specifically, the USIM uses a private key corresponding to the EC to sign the PC request message, and then the USIM obtains a PC from the PCA server based on the PC request message. That is, the PC request must be made based on the EC. That is, before making a PC request, the terminal device has already obtained an EC through the request. After securely obtaining the EC, the V2X terminal device interacts with the PCA server to further apply for a PC digital certificate. In this process, the V2X terminal device signs the sent PC request request message and verifies the signature of the received PC request response message to ensure the authenticity and integrity of the message. According to protocol requirements in the related art, the PC request message should be signed using a private key corresponding to the EC. To ensure the security of the use of the private key corresponding to the EC, the embodiment of the present application proposes that the USIM protects the signature of the PC application request message, thereby eliminating potential security risks, such as physical attacks, that may occur when the EC private key is transmitted between the USIM and the HSM. For security and convenience, the USIM may also be responsible for signature verification of the PC application response message.

[0072] Although the USIM has the capability to execute signature / signature verification processes dozens or even hundreds of times per second, there is no high real-time requirement for processing a PC digital certificate application message. Therefore, using the USIM to perform the above process can meet the performance requirements for PC applications.

[0073] After completing the initial security configuration and obtaining an EC digital certificate, the V2X terminal device must use the EC digital certificate to further apply for a PC digital certificate to provide security protection for messages of the direct connection communication service of the PC5 interface.

[0074] According to the protocol in the related art, when a V2X device applies for a PC digital certificate from a PCA server, it uses an EC to prove the legitimacy of its identity, and uses a private key corresponding to the EC to sign the PC application message to ensure the authenticity of the message.

[0075] Furthermore, when receiving a feedback message sent from the PCA server (for example, the feedback message is a certificate application response message), it is necessary to use the public key of the PCA server to perform signature verification on the received feedback message and obtain the PC.

[0076] To ensure the security of the PC digital certificate acquisition and configuration process and prevent potential physical security risks, all keys should be processed in a local secure environment of the V2X terminal device, and the shared session key Ks_NAF generated based on GBA technology should not be transmitted between the USIM and other security modules (e.g., HSM).

[0077] For this reason, in the embodiment of the present application, the USIM is used as a local security module to implement the initial security configuration of the V2X terminal device, and the generation, storage, and use of session keys and password public / private keys, as well as the application, storage, and use of PCs, are all performed by the USIM security module.The USIM is a multi-functional security entity with a security level of EAL 4+, and has functions such as random number generation, password algorithm calculation, and secure storage, and is therefore capable of safely implementing the initial security configuration of the V2X terminal device.

[0078] In this embodiment, the V2X terminal device triggers the USIM to generate a public and private key pair used for PC application. The V2X terminal device then invokes the supported GBA security authentication capability to access the PCA server over the mobile cellular network, negotiate and generate a shared session key Ks_NAF, and establish an initial secure trust relationship between the V2X terminal device and the PCA server. The PCA server verifies whether the identity of the V2X terminal device is legitimate and valid based on the shared session key Ks_NAF. After the verification is successful, the PCA server and the V2X terminal device establish a secure transmission channel to ensure the security of data interactions between them. The secure channel may be established using the session key Ks_NAF or a next-level session key derived based on Ks_NAF. The derived key calculation is performed in the secure environment of the USIM.

[0079] In this embodiment, the USIM generates the public and private key pair required for applying for a PC digital certificate, and establishes a secure communication channel from the USIM to the PCA server using the GBA_U method. Using the GBA secure channel, the USIM interacts with the PCA to apply for a PC digital certificate, downloads the PCA server's certificate, and securely stores the downloaded digital certificate and public and private key pair locally in the USIM.

[0080] A digital signature should be applied to messages such as PC application messages in interactions between V2X terminal equipment and the PCA server using the private key corresponding to the EC stored in the USIM.

[0081] Considering that the transmission rate of direct connection communication messages on the vehicle Internet PC5 interface (i.e., direct link interface) is low, approximately 10 messages per second, the USIM can meet the demand for real-time signatures on transmitted messages. Therefore, the present embodiment proposes using a USIM to perform signature protection on PC5 direct connection communication service messages. That is, when transmitting a PC5 service message, the terminal AP (application processor) first transmits the PC5 service message to the USIM, which then uses a private key corresponding to the PC to sign the message and transmits the service message via the LTE-V2X communication group. At the same time, to reduce the delay in transmitting the PC5 direct connection communication message, the USIM may transmit the obtained PC digital certificate to an external module or chip (e.g., AP, HSM, LTE-V2X communication module). When the external module or chip transmits the PC5 service message, the PC is also transmitted, facilitating point-to-point digital certificate distribution between vehicles and between vehicles and roadside facilities.

[0082] In the embodiment of the present application, all keys related to PC application (e.g., private key corresponding to EC, PC public / private key, shared session key Ks_NAF generated by GBA agreement or derived next-level key, etc.) and password calculation are all processed in the USIM complete environment, ensuring that the GBA secure channel is terminated within the USIM secure environment, so that the PC application, transmission, processing, storage, etc. processes are secure and avoid security risks such as potential physical attacks in the 5GAA solution. Because the PC digital certificate is allowed to be public, sending the PC to an external module or chip for processing does not affect the security of the solution.

[0083] In short, in this case, the main roles of the USIM of the terminal equipment include:

[0084] B21. Establish a GBA secure channel with the PCA server and use the GBA_U method preferentially. B22. Generate a public / private key pair for a PC digital certificate application. B23.GBA interacts with the PCA server via a secure communication channel to apply for and download a PC digital certificate and a PCA server certificate. During this process, the private key corresponding to the EC is used to sign the PC application message, and the public key of the PCA server certificate is used to verify the signature of the received message. B24.PC Securely store digital certificates and associated public and private key pairs locally. B25. The private key corresponding to PC is used to sign the message sent for the direct connection communication service of the PC5 interface. B27. Send the PC to an external module or chip. B28. PC Signs and verifies the application message.

[0085] It should be noted that in order to achieve compatibility with automotive industry terminal solutions in related art, the embodiments of the present application further provide a method for securely applying for certificates based on GBA technology when an HSM generates, stores, and uses keys, thereby expanding the applicability of the present application. It should be noted that in this case, the security module also only implements the functions of a USIM, i.e., the security module is a USIM.

[0086] Specifically, after the USIM obtains a digital certificate from a CA server, it sends the digital certificate to the HSM, which then stores the digital certificate. Furthermore, before applying for a digital certificate, the HSM first generates a public key / private key pair for the digital certificate application and stores the public key / private key pair. The HSM then sends the public key for the digital certificate application to the USIM. The USIM then uses the public key to apply for the digital certificate and obtains the digital certificate from the CA server. In this case, the HSM then transmits a direct connection communication service message. Specifically, the HSM first uses the private key corresponding to the digital certificate to sign a direct connection communication service message of the PC5 interface, and then transmits the signed direct connection communication service message of the PC5 interface to an external device.

[0087] Below, from the perspective of EC and PC applications, the specific implementation process of applying for the two types of certificates is explained as follows:

[0088] (1) Apply for a PC In this case, the HSM is used to generate a public / private key pair required for PC application, and the GBA_U method is used to establish a secure communication channel from the USIM to the PCA server. When applying for a PC, the HSM transmits the public key of the generated PC digital certificate to the USIM, which then interacts with the PCA to apply for a PC digital certificate and downloads the PCA server certificate. The USIM then sends the downloaded PC and PCA server certificates to the HSM for secure storage. During the certificate application process, the USIM digitally signs messages such as the PC application message using the private key corresponding to the stored EC.

[0089] To reduce the delay in transmitting PC5 direct connection communication messages, the USIM / HSM may further transmit the acquired PC to other external modules or chips (e.g., APs, LTE-V2X communication modules). When the external modules or chips transmit PC5 service messages, they also transmit the PC, facilitating point-to-point digital certificate distribution between vehicles and between vehicles and roadside facilities.

[0090] When a V2X terminal device sends a message for the direct connection communication service of the PC5 interface, it sends the message to the HSM, signs it using the private key corresponding to the PC digital certificate, and then transmits it via the LTE-V2X communication group.

[0091] In this case, the public key of the PC is transmitted from the HSM to the USIM, as shown in Figure 9. Since the public key is allowed to be made public, there is no security risk of the public key being leaked, improving security.

[0092] In short, in this case, the main roles of the USIM of the terminal equipment include:

[0093] C11. Establish a GBA secure channel with the PCA server and use the GBA_U method preferentially. C12. Receive the PC public key sent from the HSM and apply for a PC digital certificate for it. C13. Interact with the PCA server via the GBA secure communication channel to apply for and download a PC digital certificate and a PCA server certificate. During this process, the EC uses the private key corresponding to the EC to sign the PC application message and the public key of the PCA server certificate to verify the signature of the received message. C14. Send the PC digital certificate and the PCA server certificate to the HSM.

[0094] In summary, in this case, the main roles of the terminal device HSM include:

[0095] C21.PC Generate a public / private key pair for a digital certificate application. C22. The generated public key is sent to the USIM and used to apply for a PC digital certificate. C23. Securely store the received PC digital certificate and associated public and private key pair locally. A private key corresponding to C24.PC is used to sign the message sent for the direct connection communication service of the PC5 interface.

[0096] (2) Apply for EC In this case, the HSM is used to generate a public / private key pair required for EC application, and the GBA_U method is used to establish a secure communication channel from the USIM to the ECA server. When applying for EC, the HSM transmits the public key of the generated EC digital certificate to the USIM, which then interacts with the ECA to apply for the EC digital certificate and download the ECA server certificate. The USIM then sends the downloaded EC and ECA server certificate to the HSM for secure storage.

[0097] To reduce the delay in transmitting PC5 direct connection communication messages, the USIM / HSM may further transmit the acquired EC to other external modules or chips (e.g., APs, LTE-V2X communication modules), which may transmit the EC together with the PC5 service messages, thereby facilitating point-to-point digital certificate distribution between vehicles and between vehicles and roadside facilities.

[0098] When a V2X terminal device sends a message for the direct connection communication service of the PC5 interface, it sends the message to the HSM, signs it using the private key corresponding to the EC digital certificate, and then transmits it via the LTE-V2X communication group.

[0099] In this case, the public key of the EC is transmitted from the HSM to the USIM. Since the public key is allowed to be made public, there is no security risk of the public key being leaked, improving security.

[0100] In short, in this case, the main roles of the USIM of the terminal equipment include:

[0101] D11. Establish a GBA secure channel with the ECA server and use the GBA_U method preferentially. D12. Receive the EC public key sent from the HSM and apply for EC for it. D13. The GBA interacts with the ECA server via a secure communication channel to apply for and download EC and PCA server certificates. D14. Send the EC and ECA server certificates to the HSM.

[0102] In summary, in this case, the main roles of the terminal device HSM include:

[0103] Generate a public and private key pair for your D21.EC application. D22. The generated public key is sent to the USIM and used for EC application. D23. Securely store the received EC and associated public and private key pair locally. A private key corresponding to D24.EC is used to sign a message sent via the direct connection communication service of the PC5 interface.

[0104] In summary, the following operations must be performed during the initial security configuration of V2X terminal equipment:

[0105] 1. Generate a public and private key pair and prepare for EC / PC application. 2. Establish a secure channel to the ECA server / PCA server and apply for EC / PC to the ECA server / PCA server using the generated public key. 3. Download the digital certificates of the EC / PC and ECA / PCA server granted by the ECA / PCA server. 4. Locally and securely store and use public / private key pairs, digital certificates, etc.

[0106] To meet the demands of the certificate application, a new certificate application function module and related interfaces need to be added to the USIM. The architecture is shown in Figure 10, where: The interface IF1 and the USIM application function are for realizing the GBA flow.

[0107] The interfaces IF2 and IF3 and the certificate application function are used to apply for EC / PC and to process signatures for PC5 messages.

[0108] The interaction flow within the USIM card is as follows:

[0109] Apply for a digital certificate (high security):

[0110] 1. The certificate application module generates a public / private key pair, constructs a certificate request message, and requests via IF3 that the USIM application module cryptographically protect the certificate request using the Ks_NAF generated by the GBA or a derived next level key.

[0111] 2. After completing the encryption of the certificate request, the certificate application module sends the protected certificate request to the ECA / PCA server via AP through IF2 to apply for an EC / PCA digital certificate.

[0112] 3. The digital certificate issued by the ECA / PCA server and the ECA / PCA server certificate are sent to the certificate application module via IF2, and the certificate application module calls the IF3 interface to request that the USIM application module decrypt and verify the message using Ks_NAF or the derived next-level key.

[0113] 4. If the verification is passed, the certificate application module securely stores the decrypted EC / PC and ECA / PCA server certificates and feeds back the processing result.

[0114] PC digital certificate application (high compatibility):

[0115] 1. The certificate application module receives the PC public key generated by the external HSM via IF2.

[0116] 2. The certificate application module constructs a certificate request message and requests via IF3 that the USIM application module cryptographically protect the certificate request using the Ks_NAF generated by the GBA or a derived next level key.

[0117] 3. After completing the encryption of the certificate request, the certificate application module sends the protected certificate request to the PCA server via AP through IF2 to apply for a PC digital certificate.

[0118] 4. The digital certificate issued by the PCA server and the PCA server certificate are sent to the certificate application module via IF2, and the certificate application module calls the IF3 interface to request that the USIM application module decrypt and verify the message using Ks_NAF or the derived next-level key.

[0119] 5. If the verification passes, the Certificate Application Module sends the decrypted PC and PCA server certificates to the HSM for secure storage.

[0120] It should be noted that the embodiment of the present application has the following advantages:

[0121] 1. This application eliminates security risks, such as physical attacks, that exist in the initial security configuration process of V2X terminal devices based on GBA, and ensures security throughout the entire initial security configuration flow.

[0122] 2. This application maximizes the capabilities of the USIM security module in V2X terminal equipment, eliminating the need for the terminal to use an HSM hardware module, improving system security while reducing the implementation costs of the terminal.

[0123] 3. This application is compatible with related technical solutions that generally use HSMs to generate and manage keys in the automotive industry, and has good compatibility.

[0124] 4. This application lays the foundation for ensuring the security of V2X terminal PC5 interface direct connection communications.

[0125] As shown in FIG. 11, the terminal device according to the embodiment of the present application includes: Security Module and Certificate Authority (CA) Server The CA server uses the session key shared by Establish a secure channel with C a security module 111 configured to obtain a digital certificate from an A server; Here, the security module is for realizing the function of a Universal Subscriber Identity Module (USIM).

[0126] Optionally, if the CA server is an Enrollment Certificate Authority (ECA) server, the digital certificate is an Enrollment Certificate (EC), and the security module 111 obtains the digital certificate from the CA server; generating a public and private key pair for applying for EC; and obtaining an EC from an ECA server using the pair of public and private keys.

[0127] Optionally, if the CA server is an Enrollment Certificate Authority (ECA) server, the digital certificate is an Enrollment Certificate (EC), and after obtaining the digital certificate from the CA server, the security module 111 further: The storage unit is configured to store the EC.

[0128] Furthermore, if the CA server is a Anonymous Certificate Authority (PCA) server, the digital certificate is a Anonymous Certificate (PCA), and the security module 111 obtains the digital certificate from the CA server; signing the PC application message using the private key corresponding to the registration certificate (EC); and obtaining a PC from the PCA server based on the PC application message.

[0129] Specifically, the security module 111 obtains the PC from the PCA server; The feedback message sent from the PCA server is received, and the public key of the PCA server is used to perform signature verification on the received feedback message, thereby obtaining the PC.

[0130] Furthermore, after obtaining the PC from the PCA server, the security module 111 further: Signing a message for a direct connection communication service of the PC5 interface using a private key corresponding to the PC; The signed PC5 interface direct connection communication service message is sent to the external device.

[0131] Optionally, if the CA server is an Enrollment Certificate Authority (ECA) server, the digital certificate is an Enrollment Certificate (EC), and after obtaining the digital certificate from the CA server, the security module 111 further: transmitting the EC to a hardware security module (HSM); The HSM is configured to store the EC.

[0132] Furthermore, HSM also: generating a public and private key pair for applying for EC; transmitting a public key for applying for EC to a security module; The security module 111 is further configured to use the public key to obtain an EC from an ECA server.

[0133] Furthermore, if the CA server is a Anonymous Certificate Authority (PCA) server, the digital certificate is a Anonymous Certificate (PCA), and the security module 111 obtains the digital certificate from the CA server; configured to realize transmitting a PC to a hardware security module (HSM); The HSM is configured to store the PC.

[0134] Specifically, the HSM further generates a public / private key pair for applying for the PC; The HSM is configured to transmit a public key for claiming the PC to the security module; The security module 111 is further configured to use the public key to obtain a PC from the PCA server.

[0135] Furthermore, after obtaining the digital certificate from the CA server, the security module 111 further: Signing a message for a direct connection communication service of the PC5 interface using a private key corresponding to the PC; The signed PC5 interface direct connection communication service message is sent to the external device.

[0136] Specifically, the security module and the CA server establish a GBA secure channel in the manner of Generic Bootstrap Architecture (GBA) based on Universal Integrated Circuit Card (UICC).

[0137] It should be noted that the terminal device according to the embodiment of the present application is a terminal device that can execute the above provisioning method, and all implementation forms in the embodiments of the above provisioning method are applicable to the terminal device and can achieve the same or similar beneficial effects.

[0138] An embodiment of the present application further provides a terminal device, the terminal device comprising: a transceiver; and a processor; The processor controls the security module to perform the following steps: Security Module and Certificate Authority (CA) Server The CA server uses the session key shared by establishing a secure channel with C obtaining a digital certificate from the A server; Here, the security module is for realizing the function of a Universal Subscriber Identity Module (USIM).

[0139] Optionally, if the CA server is an Enrollment Certificate Authority (ECA) server, the digital certificate is an Enrollment Certificate (EC), and when the processor executes obtaining the digital certificate from the CA server, Controlling a security module to generate a public key and a private key pair for applying for EC; and obtaining an EC from an ECA server using the public key and private key pair.

[0140] Optionally, if the CA server is an Enrollment Certificate Authority (ECA) server, the digital certificate is an Enrollment Certificate (EC), and after obtaining the digital certificate from the CA server, the processor further: The security module Remember EC Control it so that This will be implemented.

[0141] Furthermore, if the CA server is a Anonymous Certificate Authority (PCA) server, the digital certificate is a Anonymous Certificate (PCA), and when the processor executes obtaining the digital certificate from the CA server, Controlling the security module to sign a PC application message using a private key corresponding to the registration certificate (EC); Acquire a PC from the PCA server based on the PC application message.

[0142] Specifically, when the processor executes obtaining a PC from a PCA server, The feedback message sent from the PCA server is received, and the signature of the received feedback message is verified using the public key of the PCA server to obtain the PC.

[0143] Furthermore, the processor, after executing obtaining the PC from the PCA server, further: Controlling the security module to sign a message of a direct connection communication service of the PC5 interface using a private key corresponding to the PC; Sending the signed PC5 interface direct connection communication service message to the external device.

[0144] Optionally, if the CA server is an Enrollment Certificate Authority (ECA) server, the digital certificate is an Enrollment Certificate (EC), and the processor, after executing obtaining the digital certificate from the CA server, further: controlling the transceiver to transmit the EC to a hardware security module (HSM); The HSM stores the EC.

[0145] The processor further performs the steps of obtaining a digital certificate from a CA server, and Controlling the HSM to generate a public / private key pair for applying for EC; the HSM sending the public key for applying for EC to the security module; The security module uses the public key to obtain the EC from the ECA server.

[0146] Furthermore, if the CA server is a Anonymous Certificate Authority (PCA) server, the digital certificate is a Anonymous Certificate (PCA), and the processor executes obtaining the digital certificate from the CA server; Controlling the transceiver to transmit a PC to a hardware security module (HSM); The HSM stores the PC and performs the above.

[0147] The processor further performs the steps of obtaining a digital certificate from a CA server; generating a public / private key pair for the HSM to apply for the PC; the HSM sending the public key to the security module to claim the PC; The security module uses the public key to obtain the PC from the PCA server.

[0148] Furthermore, the processor, after obtaining the digital certificate from the CA server, further: Controlling the security module to sign a message of a direct connection communication service of the PC5 interface using a private key corresponding to the PC; Sending the signed PC5 interface direct connection communication service message to the external device.

[0149] Specifically, the security module and the CA server are implemented using a Generic Bootstrap Architecture (GBA) based on a Universal Integrated Circuit Card (UICC). (GBA_U) In the method S Establish a cure channel.

[0150] The present invention also provides a terminal device, which includes a memory, a processor, and a computer program stored in the memory and running on the processor, and when the processor executes the computer program, the processor can realize the processes in the above-described embodiments of the provisioning method and achieve the same technical effects. To avoid repetition, the description will be omitted here.

[0151] An embodiment of the present application further provides a computer-readable storage medium. A computer program is stored in the computer-readable storage medium. When the program is executed by a processor, it can realize each process in the above-mentioned provisioning method embodiment and achieve the same technical effect. To avoid repetition, the description will be omitted here. Here, the computer-readable storage medium can be, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, etc.

[0152] As will be appreciated by those skilled in the art, the present application may be provided as a method, a system, or a computer program product. Thus, the present application may take the form of a hardware embodiment, a software embodiment, or an embodiment combining hardware and software. The present application may also take the form of a computer program product embodied in one or more computer-usable storage media (including, but not limited to, magnetic disk memory, optical memory, etc.) containing computer-usable program code.

[0153] This application will be described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of this application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, may be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device, thereby producing an apparatus that, when executed by the processor of the computer or other programmable data processing device, implements the functions defined in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.

[0154] These computer program instructions may be stored on a computer-readable storage medium that can direct a computer or other programmable data processing device to operate in a particular manner, thereby producing an article of manufacture that includes an instruction apparatus that implements the functions defined in one or more of the flows in the flowcharts and / or one or more blocks in the block diagrams.

[0155] These computer program instructions may be loaded into a computer or other programmable data processing device, which then executes a series of operational steps to produce a computer-implemented process. Thus, the instructions executed by the computer or other programmable data processing device provide steps for implementing the functions specified in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.

[0156] Each module, unit, sub-unit, or sub-module may be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), one or more microprocessors (DSPs), or one or more field programmable gate arrays (FPGAs). For example, when a module is implemented in a form in which a program code is called by a processing element, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or another processor capable of calling program code. For example, these modules may be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0157] The terms "first," "second," etc., used in the specification and claims of this application are intended to distinguish between similar objects and not necessarily to describe a particular order or sequence. It should be understood that such terms are interchangeable under appropriate circumstances, so that the embodiments of this application described herein can, for example, be performed in an order other than that illustrated or described herein. The terms "comprise" and "have," and any variations thereof, are intended to cover non-exclusive "comprises." For example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those explicitly listed steps or units, but may also include other steps or units not explicitly listed or inherent in the process, method, product, or apparatus. The term "and / or" used in the specification and claims refers to at least one of the connected objects. For example, A and / or B and / or C includes the following seven cases: a single A, a single B, a single C, a combination of A and B, a combination of B and C, a combination of A and C, and a combination of A, B, and C. Similarly, "at least one of A and B" as used in the specification and claims should be understood as "A alone, B alone, or a combination of A and B."

[0158] The above-described contents are only selective embodiments of the present application, and it should be noted that those skilled in the art may make various improvements and modifications without departing from the principles described herein, and these improvements and modifications also fall within the scope of protection of the present disclosure.

Claims

1. A provisioning method applied to a terminal device, comprising: a security module establishing a secure channel with a certification authority (CA) server using a session key shared between the security module and the CA server, the security module and the CA server establishing the secure channel in a manner of Generic Bootstrap Architecture (GBA) (GBA_U) based on a Universal Integrated Circuit Card (UICC); the security module obtaining a digital certificate from the CA server over the secure channel; the security module is for implementing the functionality of a Universal Subscriber Identity Module (USIM); If the CA server is a Anonymous Certificate Authority (PCA) server, the digital certificate is a Anonymous Certificate (PCA), and obtaining the digital certificate from the CA server comprises: the security module signs a PC application message using a private key corresponding to an enrollment certificate (EC); and obtaining a PC from a PCA server based on the PC application message.

2. Obtaining a PC from the PCA server includes: receiving a feedback message transmitted from the PCA server, and performing signature verification on the received feedback message using the public key of the PCA server to obtain a PC. The provisioning method of claim 1 .

3. After obtaining the PC from the PCA server, The security module signs a message of a direct connection communication service of a PC5 interface using a private key corresponding to the PC; and transmitting the signed message to an external device. The provisioning method of claim 1 .

4. If the CA server is an Enrollment Certification Authority (ECA) server, the digital certificate is an Enrollment Certificate (EC), and after obtaining the digital certificate from the CA server: the security module transmitting the EC to a hardware security module (HSM); the HSM storing the EC. The provisioning method of claim 1 .

5. Obtaining a digital certificate from the CA server comprises: generating a public and private key pair for the HSM to apply for EC; the HSM sending a public key for applying for EC to the security module; The security module uses the public key to obtain the EC from an ECA server. The provisioning method of claim 4.

6. If the CA server is a Anonymous Certificate Authority (PCA) server, the digital certificate is a Anonymous Certificate (PCA), and obtaining the digital certificate from the CA server comprises: transmitting the PC to a Hardware Security Module (HSM); the HSM storing the PC. The provisioning method of claim 1 .

7. Obtaining a digital certificate from the CA server comprises: generating a public and private key pair for the HSM to claim the PC; the HSM sending a public key to the security module for claiming the PC; and the security module uses the public key to obtain a PC from the PCA server. The provisioning method of claim 6.

8. After obtaining the digital certificate from the CA server, The security module signs a message of a direct connection communication service of a PC5 interface using a private key corresponding to the PC; and transmitting the signed message to an external device. The provisioning method of claim 6.

9. A terminal device, A terminal device comprising a security module for implementing the provisioning method according to any one of claims 1 to 8.

10. A terminal device comprising a transceiver and a processor, The processor controls the security module to perform the following steps: establishing a secure channel with a certification authority (CA) server using a session key shared between the security module and the CA server, the secure channel being established between the security module and the CA server in a manner of Generic Bootstrap Architecture (GBA) (GBA_U) based on a Universal Integrated Circuit Card (UICC); and obtaining a digital certificate from the CA server through the secure channel by the security module; the security module is for implementing the functionality of a Universal Subscriber Identity Module (USIM); If the CA server is a Anonymous Certificate Authority (PCA) server, the digital certificate is a Anonymous Certificate (PCA), and the step of obtaining the digital certificate from the CA server comprises: the security module signs a PC application message using a private key corresponding to an enrollment certificate (EC); and acquiring a PC from a PCA server based on the PC application message.

11. A computer-readable storage medium storing a computer program which, when executed by a processor, causes the processor to perform the provisioning method of any one of claims 1 to 8.

Citation Information

Patent Citations

  • Secure communication method between UICC and terminal

    JP2011501908A