Electronic device for authentication and operation method thereof
The electronic device addresses the challenge of certificate authentication and management by using a processor to extract, verify, and manage certificates, ensuring secure and reliable data communication.
Patent Information
- Application Number
- PCT/KR2024/019618
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-05
- Filing Date
- 2024-12-03
- Publication Date
- 2025-06-12
AI Technical Summary
Existing electronic devices face challenges in efficiently authenticating and managing certificates for secure data communication, particularly in determining the validity and expiration of certificates.
An electronic device is equipped with a processor that extracts certificates from files, verifies their validity by transmitting requests to a certificate issuing authority, and manages expired certificates by checking an exception list for storage or deletion.
The solution ensures secure and reliable authentication by validating certificates in real-time, managing expired certificates effectively, and maintaining system security by deleting invalid certificates.
Smart Images

Figure KR2024019618_12062025_PF_FP_ABST
Abstract
Description
Electronic device for authentication and method of operation thereof
[0001] Embodiments disclosed in this document relate to an electronic device for authentication and a method of operating the same.
[0002] User terminals or Internet of Things (IoT) devices (e.g., TVs, monitors, smart home appliances, etc.) can perform device authentication for data communication. Certificates can be used for device authentication, and these certificates can ensure a reliable connection between servers and clients. A valid certificate is signed by a trusted issuer, generated using a secure algorithm, and may include a certificate whose expiration date has not expired.
[0003] An operating method of an electronic device according to one embodiment of the present disclosure includes extracting a certificate from a file stored in the electronic device, in response to identifying that the certificate is a new certificate, transmitting a verification request of the certificate to a certificate issuing authority, in response to receiving a response from the certificate issuing authority that the certificate is valid, determining whether the validity period of the certificate has expired, if the validity period of the certificate has expired, determining whether the certificate is included in an exception list, and in response to determining that the certificate is included in the exception list, storing the certificate in a memory of the electronic device, wherein the exception list may include at least one certificate.
[0004] In one embodiment, the method of operating the electronic device may include an operation of identifying the extracted certificate as a new certificate when identifying that the extracted certificate is stored in a memory or database of the electronic device.
[0005] In one embodiment, the method of operating the electronic device may include, in response to identifying that the extracted certificate is not a new certificate, determining whether the validity period of the certificate has expired.
[0006] In one embodiment, the method of operating an electronic device may include, in response to identifying that the certificate is not included in the exception list, deleting the certificate from the electronic device.
[0007] In one embodiment, the method of operating the electronic device may include, in response to receiving a response from the certificate issuing authority that the certificate is invalid, deleting the certificate.
[0008] In one embodiment, a method of operating an electronic device may include an operation of identifying files stored in the electronic device, an operation of extracting string information from the files, an operation of identifying at least one authentication information from the string information, and an operation of extracting the certificate from the at least one authentication information.
[0009] In one embodiment, a method of operating an electronic device may include files of the electronic device including a release image of the electronic device.
[0010] In one embodiment, the method of operating the electronic device may include an operation of identifying certificate start information from the string information, an operation of identifying certificate end information, and an operation of extracting a string between the certificate start information and the certificate end information as the certificate.
[0011] In one embodiment, the release image may include data relating to software and firmware of the electronic device.
[0012] In one embodiment, the method of operating the electronic device may include transmitting a request for verification of the certificate to the certificate issuing authority through an access point (AP).
[0013] An electronic device according to one embodiment of the present disclosure includes a memory, a communication unit, and a processor electrically connected to the memory and the communication unit, wherein the processor is configured to extract a certificate from a file stored in the electronic device, and in response to identifying that the certificate is a new certificate, transmit a verification request of the certificate to a certificate issuing authority, and in response to receiving a response from the certificate issuing authority that the certificate is valid, determine whether the validity period of the certificate has expired, and if the validity period of the certificate has expired, determine whether the certificate is included in an exception list, and in response to determining that the certificate is included in the exception list, store the certificate in a memory of the electronic device, wherein the exception list may include at least one certificate.
[0014] In one embodiment, the processor may identify the extracted certificate as a new certificate if it identifies that the extracted certificate is stored in the memory or database of the electronic device.
[0015] In one embodiment, the processor, in response to identifying that the extracted certificate is not a new certificate, may determine whether the validity period of the certificate has expired.
[0016] In one embodiment, the processor may, in response to identifying that the certificate is not included in the exception list, delete the certificate from the electronic device.
[0017] In one embodiment, the processor may delete the certificate in response to receiving a response from the certificate issuing authority that the certificate is invalid.
[0018] In one embodiment, the processor can identify files stored in the electronic device, extract string information from the files, identify at least one authentication information from the string information, and extract the certificate from the at least one authentication information.
[0019] In one embodiment, the processor may be configured such that the files of the electronic device include a release image of the electronic device.
[0020] In one embodiment, the processor can identify certificate start information, identify certificate end information, and extract a string between the certificate start information and the certificate end information as the certificate from the string information.
[0021] In one embodiment, the release image may include data relating to software and firmware of the electronic device.
[0022] In one embodiment, the processor may transmit a request for verification of the certificate to the certificate issuing authority via an access point (AP).
[0023] FIG. 1 illustrates a block diagram of an electronic device according to one embodiment.
[0024] FIG. 2 illustrates an authentication environment of an electronic device according to one embodiment.
[0025] FIG. 3 illustrates a block diagram of an electronic device for authentication according to one embodiment.
[0026] Figure 4 illustrates an operational flow of an electronic device according to one embodiment.
[0027] Figure 5 illustrates an operational flow of an electronic device according to one embodiment.
[0028] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings so that those skilled in the art can easily implement the present disclosure. However, the present disclosure may be implemented in various different forms and is not limited to the embodiments described herein. In connection with the description of the drawings, the same or similar reference numerals may be used for identical or similar components. Furthermore, in the drawings and related descriptions, descriptions of well-known functions and configurations may be omitted for clarity and conciseness.
[0029] FIG. 1 illustrates a block diagram of an electronic device according to one embodiment. The electronic device (100) can perform various computing functions and may include a device capable of wirelessly communicating with surrounding electronic devices or server devices (e.g., an Internet of Things (IoT) server). For example, the electronic device may include a display device (e.g., a TV, a monitor), a smart home appliance, or a user device (e.g., a smartphone, a wearable device). The electronic device (100) may include various types of electronic devices without limitation to the above-described contents.
[0030] According to one embodiment, the memory (120) is a storage medium used by the electronic device (100) and can store data such as at least one instruction (121) or setting information corresponding to at least one program. The program may include an operating system (OS) program and various application programs.
[0031] In one embodiment, the memory (120) may include at least one type of storage medium among a flash memory type, a hard disk type, a multimedia card micro type, a card type memory (e.g., an SD or XD memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read only memory (ROM), an electrically erasable programmable ROM (EEPROM), a programmable ROM (PROM), a magnetic memory, a magnetic disk, and an optical disk.
[0032] According to one embodiment, the image input device (130) can receive images and image information through a tuner (not shown), an input / output device (not shown), or a communication device (150). The image input device (130) can include at least one of the tuner and the input / output device. The tuner can select only the frequency of a broadcast channel to be received by the electronic device (100) from among many radio wave components through amplification, mixing, resonance, etc. of a broadcast signal received wirelessly or wiredly. The broadcast signal can include video, audio, and additional data (e.g., an Electronic Program Guide (EPG)). The tuner can receive real-time broadcast channels (or real-time viewing images) from various broadcast sources such as terrestrial broadcasting, cable broadcasting, satellite broadcasting, and Internet broadcasting. The tuner can be implemented as an integrated unit with the electronic device (100) or as a separate tuner electrically connected to the electronic device (100). The input / output unit may include at least one of an HDMI (High Definition Multimedia Interface) input port, a component input jack, a PC input port, and a USB input jack, which can receive images and image information from an external device of the electronic device (100) under the control of the processor (110). It is obvious to those skilled in the art that the input / output unit may be added, deleted, and / or changed depending on the performance and structure of the electronic device (100).
[0033] According to one embodiment, the display (140) may perform functions for outputting information in the form of numbers, characters, images, and / or graphics. The display (140) may include at least one hardware module for outputting. The at least one hardware module may include, for example, at least one of a Liquid Crystal Display (LCD), a Light Emitting Diode (LED), a Light Emitting Polymer Display (LPD), an Organic Light Emitting Diode (OLED), an Active Matrix Organic Light Emitting Diode (AMOLED), or a Flexible LED (FLED). The display (140) may display a screen corresponding to data received from the processor (110). The display (140) may be referred to as an “output unit,” a “display unit,” or other terms having equivalent technical meanings thereto. The “screen” may include an image displayed on the display of an electronic device. The image may be referred to by terms such as a frame. Various types of objects such as icons, text, photos, videos, widgets, etc. may be displayed on the screen.
[0034] According to one embodiment, the communication device (150) may provide a wired / wireless communication interface that enables communication with an external device. The communication device (150) may include at least one of a wired Ethernet, a wireless LAN communication unit, and a short-range communication unit. The wireless LAN communication unit may include, for example, Wi-Fi, and may support the wireless LAN standard (IEEE802.11x) of the Institute of Electrical and Electronics Engineers (IEEE). The wireless LAN communication unit may be wirelessly connected to an AP (Access Point) under the control of the processor (110). The AP may include a device that enables devices to be connected using a related standard using Wi-Fi in a computer network. The short-range communication unit may wirelessly perform short-range communication with an external device under the control of the processor (110). Short-range communication may include Bluetooth, Bluetooth Low Energy, Infrared Data Association (IrDA), Ultra Wide Band (UWB), and Near Field Communication (NFC). The above external devices may include server devices that provide video services, etc., and mobile terminals (e.g., phones, tablets, etc.).
[0035] According to one embodiment, the processor (110) may execute at least one instruction (121) stored in the memory (120) to perform calculations or data processing related to control and / or communication of at least one other component of the electronic device (100). The processor (110) may include at least one of a central processing unit (CPU), a graphics processing unit (GPU), a micro controller unit (MCU), a sensor hub, a supplementary processor, a communication processor, an application processor, an application specific integrated circuit (ASIC), or a field programmable gate array (FPGA), and may have multiple cores.
[0036] In one embodiment, the processor (110) may control at least one other component (e.g., a hardware or software component) of the electronic device (100) connected to the processor (110), for example, by executing software, and may perform various data processing or calculations. According to one embodiment, as at least a part of the data processing or calculation, the processor (110) may store commands or data received from other components in a volatile memory, process the commands or data stored in the volatile memory, and store result data in a non-volatile memory. According to one embodiment, the processor (110) may include a main processor (e.g., a central processing unit or an application processor) or an auxiliary processor (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor) that can operate independently or together therewith. For example, when the electronic device (100) includes a main processor and an auxiliary processor, the auxiliary processor may be configured to use lower power than the main processor or to be specialized for a given function. The auxiliary processor may be implemented separately from the main processor or as part of it.
[0037] In one embodiment, the processor (110) may obtain image frame data from at least one of the memory (120), the image input device (130), or the communication device (150). The processor (110) may receive the image frame data from at least one of the memory (120), the image input device (130), or the communication device (150). The image frame data may include data regarding frames constituting an image. For example, the image frame data may be identified from the memory (120) (e.g., recorded and stored image). For example, the image frame data may include data obtained from the communication device (150) or the image input device (130) (e.g., real-time streaming image).
[0038] FIG. 2 illustrates an example of an authentication environment of an electronic device according to one embodiment.
[0039] In one embodiment, the authentication environment of an electronic device (100) (e.g., the electronic device (100) of FIG. 1) may include an electronic device (100), an AP (210), a certificate verification device (220), a certificate issuing authority (230), and an IoT network (240).
[0040] In one embodiment, the AP (210) may include a device that enables devices (e.g., electronic devices (100)) to connect using a relevant standard using Wi-Fi in a computer network.
[0041] In one embodiment, the AP (210) can relay data between a wireless device and a wired device on a network. However, the present invention is not limited thereto, and the AP can relay data between wired devices or between wireless devices. Meanwhile, the AP may also be referred to as a relay device. In one embodiment, the certificate verification device (220) can perform authentication of a device (e.g., an electronic device (100)) requesting communication with the IoT network (240). The certificate verification device (220) may include a certificate database (222) that stores information about a certificate, and a verification server (224) that processes a series of operations for verifying the certificate.
[0042] In one embodiment, the certificate verification device (220) can verify whether a certificate (e.g., a certificate of the electronic device (100)) is a valid certificate. The certificate verification device (220) can determine whether a certificate for which verification is requested is a valid certificate through communication with a certificate issuing authority (230). For example, the certificate verification device (220) can determine whether information regarding the corresponding certificate is included in the certificate DB (222) through the verification server (224). For example, if the certificate verification device (220) does not include information regarding the corresponding certificate in the certificate DB (222), the certificate verification device (220) can transmit a certificate verification request to the certificate issuing authority (230) to verify whether the corresponding certificate is a valid certificate. If the certificate verification device (220) receives a response from the certificate issuing authority (230) indicating that the corresponding certificate is a valid certificate, the certificate verification device (220) can determine that the corresponding certificate is valid, and if it receives a response indicating that the corresponding certificate is invalid, the certificate verification device (220) can determine that the corresponding certificate is invalid.
[0043] In one embodiment, the certificate issuing authority (230) may include a device that issues certificates installed in the electronic device (100). The certificate issuing authority (230) may issue certificates and sign them using a root certificate. Although only one certificate issuing authority (230) is illustrated in the drawing, the environment for authenticating the electronic device (100) may include multiple certificate issuing authorities.
[0044] In one embodiment, the IoT network (240) may include a network of devices for managing the electronic device (100). Various services may be provided to the electronic device (100) through the IoT network (240).
[0045] In one embodiment, the IoT network (240) can transmit data only to verified electronic devices (100). The IoT network (240) can receive information from the certificate verification device (220) regarding whether the certificate of the electronic device (100) is a valid certificate.
[0046] In one embodiment, although not shown in the drawing, the certificate verification device (220) may be implemented as a part of the electronic device (100). In other words, the certificate verification device (220) may be implemented as a part of the electronic device (100), rather than as a separate entity from the electronic device (100).
[0047] FIG. 3 illustrates a block configuration of an electronic device (100) according to one embodiment.
[0048] According to one embodiment, an electronic device (100) (e.g., the electronic device (100) of FIG. 1, the electronic device (100) of FIG. 2) may include a certificate extraction unit (310) and a certificate reading unit (320).
[0049] In one embodiment, the certificate extraction unit (310) can extract a certificate from a list of files installed in the electronic device (100).
[0050] In one embodiment, the certificate extraction unit (310) may identify a list of files in a release image of the electronic device (100). In one embodiment, the list of files may include all files stored in the electronic device (100). The release image may include image files of software and firmware installed in the electronic device (100). The release image may include data regarding the operating system and applications of the electronic device (100).
[0051] In one embodiment, the certificate extraction unit (310) can extract certificates from a file list. For example, the certificate extraction unit (310) can extract certificates from a file using a specific command (e.g., the openssl command).
[0052] In one embodiment, the certificate extraction unit (310) can extract string information from binary files in the file list. For example, the certificate extraction unit (310) can extract a specific pattern from a binary file through reversing. For example, the certificate extraction unit (310) can extract a specific pattern from a binary file through a specific command (e.g., the strings command in Linux).
[0053] In one embodiment, the certificate extraction unit (310) can convert a pattern into a string to determine whether certificate start information (e.g., BEGIN CERTIFICATE) exists. The certificate extraction unit (310) can analyze the string following the certificate start information to determine whether a string used in a certificate (e.g., a string starting with "") exists. If a string used in a certificate exists in the string following the certificate start information, the certificate extraction unit (310) can store the string in a buffer. If the certificate extraction unit (310) identifies certificate end information (e.g., END CERTIFICATE), it can store the string buffer it has stored so far as authentication information in a certificate file (e.g., a pem file).
[0054] In one embodiment, the certificate extraction unit (310) can extract a certificate from a generated certificate file. The certificate extraction unit (310) can extract a certificate by parsing the generated certificate file using a specific command (e.g., the openssl command). If the certificate is extracted normally, the certificate extraction unit (310) can determine that it is a normal certificate and store it in the electronic device (100). Otherwise, the certificate can be discarded.
[0055] In one embodiment, the certificate reading unit (320) can determine whether the extracted certificate is valid. If the extracted certificate is a new certificate, the certificate reading unit (320) can request a certificate verification device (e.g., certificate verification device (220)) to verify whether the certificate is valid. The certificate reading unit (320) can determine whether the validity period of the extracted certificate has expired. If the certificate reading unit (320) determines that the extracted certificate is a valid certificate, the certificate reading unit (320) can store the certificate in the electronic device (100).
[0056] FIG. 4 illustrates an operational flow of an electronic device according to one embodiment. The electronic device of FIG. 4 (e.g., the electronic device (100) of FIG. 1 or the electronic device (100) of FIG. 2) may include a device corresponding to the certificate verification device (220) of FIG. 2.
[0057] According to one embodiment, in operation 410, the electronic device (100) may extract a certificate.
[0058] In one embodiment, the electronic device (100) can extract a certificate from a list of files installed on the electronic device (100).
[0059] In one embodiment, the electronic device (100) can identify a file list for files stored in the electronic device (100) from a release image of the electronic device (100). The release image can include image files of software and firmware to be installed in the electronic device (100). The release image can include data regarding the operating system and applications of the electronic device (100).
[0060] In one embodiment, the electronic device (100) can extract a certificate from a list of files. For example, the electronic device (100) can extract a certificate from a file using a specific command (e.g., the openssl command).
[0061] In one embodiment, the electronic device (100) can extract string information from a binary file in a file list. For example, the electronic device (100) can extract a specific pattern from a binary file through reversing. For example, the electronic device (100) can extract a specific pattern from a binary file through a specific command (e.g., the strings command of Linux).
[0062] In one embodiment, the electronic device (100) can convert a pattern into a string to determine whether certificate start information (e.g., BEGIN CERTIFICATE) exists. The electronic device (100) can analyze the string following the certificate start information to determine whether a string used in a certificate (e.g., a string starting with "") exists. If a string used in a certificate exists in the string following the certificate start information, the electronic device (100) can store the string in a buffer. If the electronic device (100) identifies certificate end information (e.g., END CERTIFICATE), the electronic device (100) can store the string buffer stored so far as authentication information in a certificate file (e.g., a pem file).
[0063] In one embodiment, the electronic device (100) can extract a certificate from the generated certificate file. The electronic device (100) can extract the certificate by parsing the generated certificate file using a specific command (e.g., the openssl command). If the certificate is extracted normally, the electronic device (100) can determine that it is a normal certificate and store it in the electronic device (100). Otherwise, the electronic device can discard it.
[0064] According to one embodiment, in operation 420, the electronic device (100) may determine whether the certificate is a new certificate. The electronic device (100) may determine whether the certificate extracted through operation 410 corresponds to a certificate stored in a memory of the electronic device (100) (e.g., memory (120)) or a database storing certificates (e.g., DB (222)).
[0065] In one embodiment, if the certificate is determined to be a new certificate, the electronic device (100) may perform operation 430.
[0066] In one embodiment, if it is determined that the certificate is not a new certificate, the electronic device (100) may perform operation 440.
[0067] According to one embodiment, at operation 430, the electronic device (100) may determine whether the certificate is a valid certificate.
[0068] In one embodiment, the electronic device (100) can verify whether a certificate is a valid certificate. The electronic device (100) can determine whether information about the certificate is included in a database containing information about certificates within the electronic device (100). The electronic device (100) can request confirmation of whether the certificate is a valid certificate through communication with a certificate issuing authority (e.g., the certificate issuing authority (230) of FIG. 2) and transmit a response regarding whether the certificate is valid.
[0069] In one embodiment, the electronic device (100) may determine that a certificate is valid if the database contains information about the certificate. If the database does not contain information about the certificate, the electronic device (100) may determine that the certificate is invalid. If the electronic device (100) receives a response from the certificate issuing authority indicating that the certificate is valid, the electronic device (100) may determine that the certificate is valid. If the electronic device (100) receives a response from the certificate issuing authority indicating that the certificate is invalid, the electronic device (100) may determine that the certificate is invalid.
[0070] In one embodiment, if the certificate is determined to be valid, the electronic device (100) may perform operation 440. If the certificate is determined to be invalid, the electronic device (100) may discard the certificate at operation 470.
[0071] According to one embodiment, in operation 440, the electronic device (100) may determine whether the validity period of the certificate has expired. Even if the certificate is formally normal, if the expiration date has passed or the remaining validity period is less than a predetermined period, the electronic device (100) may determine that the validity period of the certificate has expired.
[0072] In one embodiment, although not depicted in the drawing, the electronic device (100) may determine that the certificate's validity period has expired if the certificate's algorithm does not correspond to a predetermined algorithm (e.g., if the certificate's algorithm is MD5, SHA1, etc.). If a certificate is generated using an algorithm other than the predetermined algorithm, the certificate may not be released as it is considered to have expired due to security concerns.
[0073] In one embodiment, if the validity period of the certificate has not expired, the electronic device (100) may perform operation 460. If the validity period of the certificate has expired, the electronic device (100) may perform operation 450.
[0074] In one embodiment, at operation 450, the electronic device (100) may determine whether a certificate is included in an exception list. The exception list is a list defined as an exception allowed among invalid certificates and may include data managed as a separate hash file of the electronic device (100). A certificate included in the exception list may be allowed to be used by the electronic device (100) even if its validity period has expired. If the validity period of the certificate has expired and the certificate is not included in the exception list, the electronic device (100) may discard (delete) the certificate in operation 470 because the certificate is an unnecessary certificate.
[0075] According to one embodiment, at operation 460, the electronic device (100) may decide to release the certificate. If the electronic device (100) decides to release the certificate, the electronic device (100) may store the certificate in the electronic device (100).
[0076] FIG. 5 illustrates an operational flow of an electronic device according to one embodiment. The operational flow described in FIG. 5 may relate to the operational content of operation 410 of FIG. 4.
[0077] According to one embodiment, in operation 510, an electronic device (e.g., electronic device (100) of FIG. 1, electronic device (100) of FIG. 2) may extract string information from files stored in the electronic device (100).
[0078] In one embodiment, the electronic device (100) can identify a file list regarding all files included in the electronic device (100) from a release image of the electronic device (100). The release image can include image files of software and firmware to be installed on the electronic device (100). The release image can include data regarding the operating system and applications of the electronic device (100).
[0079] In one embodiment, the electronic device (100) can extract a certificate from a list of files. For example, the electronic device (100) can extract a certificate from a file using a specific command (e.g., the openssl command).
[0080] In one embodiment, the electronic device (100) can extract string information from a binary file in a file list. For example, the electronic device (100) can extract a specific pattern from a binary file through reversing. For example, the electronic device (100) can extract a specific pattern from a binary file through a specific command (e.g., the strings command of Linux).
[0081] In one embodiment, the electronic device (100) can convert the pattern into string information.
[0082] According to one embodiment, in operation 520, the electronic device (100) can identify at least one piece of authentication information.
[0083] In one embodiment, the electronic device (100) can check whether certificate start information (e.g., BEGIN CERTIFICATE) exists. The electronic device (100) can analyze the string following the certificate start information to determine whether a string used in the certificate (e.g., a string starting with "") exists. If a string used in the certificate exists in the string following the certificate start information, the electronic device (100) can store the string in a buffer. If the electronic device (100) identifies certificate end information (e.g., END CERTIFICATE), the electronic device (100) can store the string buffer stored so far as authentication information in a certificate file (e.g., a pem file).
[0084] According to one embodiment, at operation 530, the electronic device (100) may extract a certificate from the authentication information.
[0085] In one embodiment, the electronic device (100) can extract a certificate from the generated certificate file. The electronic device (100) can extract the certificate by parsing the generated certificate file using a specific command (e.g., the openssl command). If the certificate is extracted normally, the electronic device (100) can determine that it is a normal certificate and store it in the electronic device (100). Otherwise, the electronic device can discard it.
[0086] The operations illustrated in FIGS. 4 and 5 may be operations performed by an electronic device (e.g., the electronic device (100) of FIG. 1, the electronic device (100) of FIG. 2) or a certificate verification device (e.g., the certificate verification device (220) of FIG. 2). In other words, although described as a structure that operates in a certificate verification device, they may be performed by the electronic device itself.
[0087] An operating method of an electronic device according to one embodiment of the present disclosure includes extracting a certificate from a file stored in the electronic device, in response to identifying that the certificate is a new certificate, transmitting a verification request of the certificate to a certificate issuing authority, in response to receiving a response from the certificate issuing authority that the certificate is valid, determining whether the validity period of the certificate has expired, if the validity period of the certificate has expired, determining whether the certificate is included in an exception list, and in response to determining that the certificate is included in the exception list, storing the certificate in a memory of the electronic device, wherein the exception list may include at least one certificate.
[0088] In one embodiment, the method of operating the electronic device may include an operation of identifying the extracted certificate as a new certificate when identifying that the extracted certificate is stored in a memory or database of the electronic device.
[0089] In one embodiment, the method of operating the electronic device may include, in response to identifying that the extracted certificate is not a new certificate, determining whether the validity period of the certificate has expired.
[0090] In one embodiment, the method of operating an electronic device may include, in response to identifying that the certificate is not included in the exception list, deleting the certificate from the electronic device.
[0091] In one embodiment, the method of operating the electronic device may include, in response to receiving a response from the certificate issuing authority that the certificate is invalid, deleting the certificate.
[0092] In one embodiment, a method of operating an electronic device may include an operation of identifying files stored in the electronic device, an operation of extracting string information from the files, an operation of identifying at least one authentication information from the string information, and an operation of extracting the certificate from the at least one authentication information.
[0093] In one embodiment, a method of operating an electronic device may include files of the electronic device including a release image of the electronic device.
[0094] In one embodiment, the method of operating the electronic device may include an operation of identifying certificate start information from the string information, an operation of identifying certificate end information, and an operation of extracting a string between the certificate start information and the certificate end information as the certificate.
[0095] In one embodiment, the release image may include data relating to software and firmware of the electronic device.
[0096] In one embodiment, the method of operating the electronic device may include transmitting a request for verification of the certificate to the certificate issuing authority through an access point (AP).
[0097] An electronic device according to one embodiment of the present disclosure includes a memory, and a processor electrically connected to the memory, wherein the processor is configured to extract a certificate from a file stored in the electronic device, and in response to identifying that the certificate is a new certificate, transmit an authentication request of the certificate to a certificate issuing authority, and in response to receiving a response from the certificate issuing authority that the certificate is valid, determine whether the validity period of the certificate has expired, and if the validity period of the certificate has expired, determine whether the certificate is included in an exception list, and in response to determining that the certificate is included in the exception list, store the certificate in the memory of the electronic device, wherein the exception list may include at least one certificate.
[0098] In one embodiment, the processor may identify the extracted certificate as a new certificate if it identifies that the extracted certificate is stored in the memory or database of the electronic device.
[0099] In one embodiment, the processor, in response to identifying that the extracted certificate is not a new certificate, may determine whether the validity period of the certificate has expired.
[0100] In one embodiment, the processor may, in response to identifying that the certificate is not included in the exception list, delete the certificate from the electronic device.
[0101] In one embodiment, the processor may delete the certificate in response to receiving a response from the certificate issuing authority that the certificate is invalid.
[0102] In one embodiment, the processor can identify files stored in the electronic device, extract string information from the files, identify at least one authentication information from the string information, and extract the certificate from the at least one authentication information.
[0103] In one embodiment, the processor may be configured such that the files of the electronic device include a release image of the electronic device.
[0104] In one embodiment, the processor can identify certificate start information, identify certificate end information, and extract a string between the certificate start information and the certificate end information as the certificate from the string information.
[0105] In one embodiment, the release image may include data relating to software and firmware of the electronic device.
[0106] In one embodiment, the processor may transmit a request for verification of the certificate to the certificate issuing authority via an access point (AP).
[0107] Electronic devices according to the various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, display devices, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to the embodiments of this document are not limited to the aforementioned devices.
[0108] The various embodiments of this document and the terminology used herein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. For example, a component expressed in the singular should be understood to include a concept including plural components unless the context clearly indicates only the singular. It should be understood that the term "and / or" used in this document encompasses any and all possible combinations of one or more of the listed items. The terms "comprise," "have," "consist of," and the like used in this disclosure are intended to specify only the presence of a feature, component, part, or combination thereof described in this disclosure, and the use of such terms does not exclude the presence or addition of one or more other features, components, parts, or combinations thereof. In this document, phrases such as "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can each include any one of the items listed together in that phrase, or all possible combinations thereof. Terms such as "first", "second", or "first" or "second" may be used merely to distinguish the corresponding element from other corresponding elements and do not limit the corresponding elements in any other respect (e.g., importance or order).
[0109] The terms "part" or "module" used in various embodiments of this document may include units implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. The "part" or "module" may be an integrally formed component or a minimum unit or part of the component that performs one or more functions. For example, according to one embodiment, the "part" or "module" may be implemented in the form of an application-specific integrated circuit (ASIC).
[0110] The term "if" as used in various embodiments of this document may be interpreted to mean "when" or "when" or "in response to determining" or "in response to detecting," depending on the context. Similarly, "if it is determined that" or "if it is detected" may be interpreted to mean "upon determining" or "in response to determining" or "upon detecting" or "in response to detecting," depending on the context.
[0111] The program executed by the server device (200) described in this document may be implemented as hardware components, software components, and / or a combination of hardware components and software components. The program may be executed by any system capable of executing computer-readable instructions.
[0112] Software may include a computer program, code, instructions, or a combination of one or more of these, which can configure a processing device to perform a desired operation or command the processing device, either independently or collectively. Software may be implemented as a computer program including instructions stored on a computer-readable storage medium. Examples of the computer-readable storage medium include magnetic storage media (e.g., read-only memory (ROM), random-access memory (RAM), floppy disks, hard disks, etc.) and optical reading media (e.g., CD-ROMs, digital versatile discs (DVDs)). The computer-readable storage medium may be distributed across network-connected computer systems so that the computer-readable code can be stored and executed in a distributed manner. Computer programs can be distributed online (e.g., by download or upload) through an application store (e.g., Play Store™) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.
[0113] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and placed in other components. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.
Claims
1. In the method of operating an electronic device, An action of extracting a certificate from a file stored in said electronic device; In response to identifying that the above certificate is a new certificate, the action of sending a verification request for the above certificate to the certificate issuing authority; In response to receiving a response from the certificate issuing authority that the certificate is valid, an action for determining whether the validity period of the certificate has expired; If the validity period of the above certificate has expired, an action to determine whether the above certificate is included in the exception list; In response to determining that said certificate is included in said exception list, comprising the action of storing said certificate in a memory of said electronic device; A method wherein the above exception list includes at least one certificate.
2. In claim 1, A method for identifying the certificate as a new certificate when it is identified that the extracted certificate is stored in the memory or database of the electronic device.
3. In claim 2, A method comprising: in response to identifying that the extracted certificate is not a new certificate, determining whether the validity period of the certificate has expired.
4. In claim 3, A method comprising: in response to identifying that said certificate is not included in said exception list, deleting said certificate from said electronic device.
5. In claim 1, A method comprising the action of deleting a certificate in response to receiving a response from the certificate issuing authority that the certificate is invalid.
6. In claim 1, The action of extracting a certificate from a file stored in the above electronic device is: An action to identify files contained in said electronic device; The action of extracting string information from the above files, An action to identify at least one authentication information from the above string information; A method comprising the action of extracting the certificate from the at least one piece of authentication information.
7. In claim 6, A method wherein the files of the electronic device include a release image of the electronic device.
8. In claim 6, In the above string information, an action to identify the certificate start information, Action to identify the end information of a certificate; A method comprising the action of extracting a string between the certificate start information and the certificate end information as the certificate.
9. In claim 7, A method wherein the release image includes data regarding software and firmware of the electronic device.
10. In claim 1 or claim 6, A method comprising an action of transmitting a verification request for the certificate to the certificate issuing authority through an AP (access point).
11. In electronic devices, memory; comprising a processor electrically connected to the above memory, The above processor: Extract the certificate from the file stored on the above electronic device, In response to identifying that the above certificate is a new certificate, a request for verification of the above certificate is sent to the certificate issuing authority, In response to receiving a response from the certificate issuing authority that the certificate is valid, determine whether the validity period of the certificate has expired, If the validity period of the above certificate has expired, determine whether the above certificate is included in the exception list, In response to determining that said certificate is included in said exception list, configured to store said certificate in a memory of said electronic device; The above exception list is an electronic device that includes at least one certificate.
12. In claim 11, The above processor: An electronic device configured to identify the certificate as a new certificate when identifying that the extracted certificate is stored in the memory or database of the electronic device.
13. In claim 12, The above processor: An electronic device configured to determine whether the validity period of the certificate has expired in response to identifying that the extracted certificate is not a new certificate.
14. In claim 13, The above processor: An electronic device configured to delete said certificate from the electronic device in response to identifying that said certificate is not included in said exception list.
15. In claim 11, The above processor: An electronic device configured to delete a certificate in response to receiving a response from the certificate issuing authority that the certificate is invalid.
Citation Information
Patent Citations
Application service authentication system and method thereof
KR1020120065145A
Authentication of digital broadcast data
KR1020180032559A
Reaction passivator, method for forming thin film using the same, semiconductor substrate and semiconductor device prepared therefrom
KR1020230120970A
System and method for verifying digital signatures on certificates
US20060095388A1
KR20200115759A