Electronic device, method, and storage medium for performing secure communication

By utilizing a security IC with a security chain certificate and key, electronic devices can establish secure communication channels between security circuits, addressing the challenge of lacking an HSM during manufacturing, thus ensuring secure data transmission.

WO2025244486A1PCT designated stage Publication Date: 2025-11-27SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/095158
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-02
Filing Date
2025-04-02
Publication Date
2025-11-27

AI Technical Summary

Technical Problem

Existing electronic devices face challenges in establishing secure communication channels between security circuits without the use of a hardware security module (HSM) that includes a root key, which is often not available during manufacturing or outsourcing.

Method used

The solution involves generating mutual authentication and shared secret values between first and second security circuits using a security IC that includes a security chain certificate and key, allowing secure communication without relying on an HSM by using a root key from an external device.

Benefits of technology

This approach enables secure communication channels to be established between security circuits, ensuring data integrity and security without the need for an HSM, thereby enhancing the security of electronic devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025095158_27112025_PF_FP_ABST
    Figure KR2025095158_27112025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are an electronic device, a method, and a storage medium for performing secure communication. The electronic device comprises: a communication interface including a first secure circuit; at least one processor including a second secure circuit; a secure IC; and memory for storing instructions executed by the at least one processor. The instructions stored in the memory cause the electronic device to generate a second secure communication private key and transmit data for certificate generation to the secure IC. The instructions cause the electronic device to sign data for certificate generation in the secure IC by using a secure chain private key, and transmit the signed data for certificate generation to the second secure circuit. The instructions may be configured to cause the electronic device to generate a second secure communication certificate. The instructions stored in the memory cause the electronic device to authenticate the second secure circuit and the first secure circuit. The instructions cause the electronic device to establish a secure communication channel between the first secure circuit and the second secure circuit, and perform secure communication.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic device, method and storage medium for performing secure communication

[0001] Embodiments of this document relate to electronic devices, methods and storage media, for example, to electronic devices, methods and storage media for performing secure communication.

[0002] Electronic devices can store software (or data). Software stored on electronic devices may include software requiring security. Software requiring security may be stored in a secure area (or secure circuit) of the processor or memory. Software requiring security may form a secure channel and be stored in the secure area.

[0003] For example, an NFC (near field communication) chip may include a security circuit (or secure area) of an embedded secure element (eSE), and the eSE may include a target security domain. Furthermore, the processor may include a trustzone. When a manufacturer of an electronic device installs, deletes, or personalizes a specific security domain and / or application within the target security domain, a secure channel may need to be established between the trustzone and the eSE. The electronic device may use a security key located in an HSM (hardware security module) of an external device to establish a certificate chain. The trustzone and the eSE may use the injected key to mutually verify the certificate chain and establish a secure channel using a calculated shared secret value. The electronic device may then establish a secure channel using the calculated shared secret value to install software requiring security within the eSE.

[0004] The above information may be provided solely as background information to aid in understanding the present disclosure. None of the above-described matters are claimed as prior art related to the present disclosure or can be used in determining prior art.

[0005] An electronic device according to various embodiments of the present disclosure may include a communication interface including a first security circuit. The first security circuit may include a root public key, a first secure communication certificate, and a first secure communication private key. The electronic device may include at least one processor including a second security circuit. The second security circuit may include a root public key. The electronic device may include a security IC including a security chain certificate and a security chain private key, and a memory storing instructions executed by the at least one processor. The instructions stored in the memory may be configured to cause the electronic device to generate a second secure communication private key in the second security circuit and transmit data for certificate generation to the security IC. The instructions stored in the memory may be configured to cause the electronic device to sign data for certificate generation using the security chain private key in the security IC and transmit data for generating the signed certificate to the second security circuit. The instructions stored in the memory may be configured to cause the electronic device to generate a second secure communication certificate based on the data for generating the signed certificate in the second security circuit. The instructions stored in the memory may be configured to cause the electronic device to authenticate the second security circuit based on a second secure communication certificate and the root public key received from the second security circuit in the first security circuit. The instructions stored in the memory may be configured to cause the electronic device to authenticate the first security circuit based on a first secure communication certificate and the root public key received from the first security circuit in the second security circuit. The instructions stored in the memory may be configured to cause the electronic device to establish a secure communication channel between the first security circuit and the second security circuit.The instructions stored in the memory may be configured to cause the electronic device to obtain a first shared secret value from the first security circuit based on the second secure communication certificate and the first secure communication private key. The instructions stored in the memory may be configured to cause the electronic device to obtain a second shared secret value from the second security circuit based on the first secure communication certificate and the second secure communication private key. The instructions stored in the memory may be configured to cause the electronic device to perform secure communication between the first security circuit and the second security circuit based on the first shared secret value and the second shared secret value.

[0006] According to various embodiments of the present document, a method for performing secure communication in an electronic device including a first security circuit, a second security circuit, and a security IC may include generating a second secure communication private key in the second security circuit and transmitting data for certificate generation to the security IC. The method may include signing data for certificate generation using the security chain private key in the security IC and transmitting data for generating the signed certificate to the second security circuit. The method may include generating a second secure communication certificate in the second security circuit based on the data for generating the signed certificate. The method may include authenticating the second security circuit based on the second secure communication certificate and the root public key received from the second security circuit in the first security circuit, and authenticating the first security circuit based on the first secure communication certificate and the root public key received from the first security circuit in the second security circuit, thereby forming a secure communication channel between the first security circuit and the second security circuit. The method may obtain a first shared secret value based on the second secure communication certificate and the first secure communication private key in the first security circuit. The method may obtain a second shared secret value based on the first secure communication certificate and the second secure communication private key in the second security circuit. The method may perform secure communication between the first security circuit and the second security circuit based on the first shared secret value and the second shared secret value.

[0007] A non-transitory computer-readable storage medium having recorded thereon a program for performing a method for performing secure communication in an electronic device including a first security circuit, a second security circuit, and a security IC according to various embodiments of the present document may include an operation for generating a second secure communication private key in the second security circuit and transmitting data for generating a certificate to the security IC. The storage medium may include an operation for signing data for generating the certificate using the security chain private key in the security IC and transmitting data for generating the signed certificate to the second security circuit. The storage medium may include an operation for generating a second secure communication certificate based on the data for generating the signed certificate in the second security circuit. The storage medium may include an operation for authenticating the second security circuit based on the second secure communication certificate and the root public key received from the second security circuit in the first security circuit, and authenticating the first security circuit based on the first secure communication certificate and the root public key received from the first security circuit in the second security circuit, thereby forming a secure communication channel between the first security circuit and the second security circuit. The storage medium may include an operation for obtaining a first shared secret value based on the second secure communication certificate and the first secure communication private key in the first security circuit. The storage medium may include an operation for obtaining a second shared secret value based on the first secure communication certificate and the second secure communication private key in the second security circuit. The storage medium may include an operation for performing secure communication between the first security circuit and the second security circuit based on the first shared secret value and the second shared secret value.

[0008] In connection with the description of the drawings, the same or similar reference numerals may be used for the same or similar components.

[0009] FIG. 1 is a block diagram of an electronic device within a network environment according to various embodiments.

[0010] FIG. 2 is a block diagram illustrating the configuration of an electronic device according to various embodiments.

[0011] FIG. 3 is a drawing illustrating operations performed in the production process of a security IC (integrated circuit) according to various embodiments.

[0012] FIG. 4 is a drawing illustrating operations performed in the production process of a security circuit according to various embodiments.

[0013] FIG. 5 is a drawing illustrating a security circuit and a security IC mounted on an electronic device according to various embodiments.

[0014] FIGS. 6A and 6B are drawings illustrating key chain forming operations according to various embodiments.

[0015] FIG. 7A and FIG. 7B are diagrams illustrating eSE authentication operations according to various embodiments.

[0016] FIG. 8a, FIG. 8b, and FIG. 8c are diagrams illustrating trustzone authentication operations according to various embodiments.

[0017] FIG. 9 is a diagram illustrating an operation of calculating a shared secret value according to various embodiments.

[0018] FIG. 10 is a flowchart illustrating a method for performing secure communication according to various embodiments.

[0019] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings so that those skilled in the art can easily implement the present disclosure. However, the present disclosure may be implemented in various different forms and is not limited to the embodiments described herein. In connection with the description of the drawings, the same or similar reference numerals may be used for identical or similar components. Furthermore, in the drawings and related descriptions, descriptions of well-known functions and configurations may be omitted for clarity and conciseness.

[0020] FIG. 1 is a block diagram of an electronic device (101) within a network environment (100) according to various embodiments. Referring to FIG. 1, in the network environment (100), the electronic device (101) may communicate with an electronic device (102) via a first network (198) (e.g., a short-range wireless communication network), or may communicate with at least one of an electronic device (104) or a server (108) via a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) via the server (108). According to one embodiment, the electronic device (101) may include a processor (120), a memory (130), an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a connection terminal (178), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197). In some embodiments, the electronic device (101) may omit at least one of these components (e.g., the connection terminal (178)), or may have one or more other components added. In some embodiments, some of these components (e.g., the sensor module (176), the camera module (180), or the antenna module (197)) may be integrated into one component (e.g., the display module (160)).

[0021] The processor (120) may, for example, execute software (e.g., a program (140)) to control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) and perform various data processing or calculations. According to one embodiment, as at least a part of the data processing or calculations, the processor (120) may store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in a volatile memory (132), process the commands or data stored in the volatile memory (132), and store result data in a non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or a secondary processor (123) (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor)) that can operate independently or together therewith. For example, if the electronic device (101) includes a main processor (121) and a secondary processor (123), the secondary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a specified function. The secondary processor (123) may be implemented separately from the main processor (121) or as a part thereof.

[0022] The auxiliary processor (123) may control at least a portion of functions or states associated with at least one component (e.g., a display module (160), a sensor module (176), or a communication module (190)) of the electronic device (101), for example, on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (123) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (180) or a communication module (190)). In one embodiment, the auxiliary processor (123) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, on the electronic device (101) itself where the artificial intelligence model is executed, or can be performed through a separate server (e.g., server (108)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include multiple artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.

[0023] The memory (130) can store various data used by at least one component (e.g., the processor (120) or the sensor module (176)) of the electronic device (101). The data can include, for example, software (e.g., the program (140)) and input data or output data for commands related thereto. The memory (130) can include a volatile memory (132) or a non-volatile memory (134). The non-volatile memory (134) can include at least one internal memory (136) and an external memory (138).

[0024] The program (140) may be stored as software in the memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0025] The input module (150) can receive commands or data to be used in a component of the electronic device (101) (e.g., a processor (120)) from an external source (e.g., a user) of the electronic device (101). The input module (150) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).

[0026] The audio output module (155) can output audio signals to the outside of the electronic device (101). The audio output module (155) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. In one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.

[0027] The display module (160) can visually provide information to an external party (e.g., a user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. In one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.

[0028] The audio module (170) can convert sound into an electrical signal, or vice versa, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150), output sound through the sound output module (155), or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (101).

[0029] The sensor module (176) can detect the operating status (e.g., power or temperature) of the electronic device (101) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (176) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0030] The interface (177) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (101) with an external electronic device (e.g., the electronic device (102)). In one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0031] The connection terminal (178) may include a connector through which the electronic device (101) may be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0032] A haptic module (179) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. In one embodiment, the haptic module (179) can include, for example, a motor, a piezoelectric element, or an electrical stimulation device.

[0033] The camera module (180) can capture still images and videos. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0034] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented, for example, as at least a part of a power management integrated circuit (PMIC).

[0035] A battery (189) may power at least one component of the electronic device (101). In one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0036] The communication module (190) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may operate independently from the processor (120) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Among these communication modules, the corresponding communication module can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules can be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can verify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) by using subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (196).

[0037] The wireless communication module (192) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in a high-frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), an external electronic device (e.g., the electronic device (104)), or a network system (e.g., the second network (199)). According to one embodiment, the wireless communication module (192) can support a peak data rate (e.g., 20 Gbps or more) for eMBB realization, a loss coverage (e.g., 164 dB or less) for mMTC realization, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for URLLC realization.

[0038] The antenna module (197) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). In one embodiment, the antenna module (197) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). In one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (198) or the second network (199), may be selected from the plurality of antennas by, for example, the communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device through the selected at least one antenna. In some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (197).

[0039] According to various embodiments, the antenna module (197) may form a mmWave antenna module. According to one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high frequency band.

[0040] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).

[0041] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) via a server (108) connected to a second network (199). Each of the external electronic devices (102 or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations executed in the electronic device (101) may be executed in one or more of the external electronic devices (102, 104, or 108). For example, when the electronic device (101) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (101) may, instead of or in addition to executing the function or service itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (101) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In one embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server using machine learning and / or a neural network. According to one embodiment, the external electronic device (104) or the server (108) may be included in the second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.

[0042] Electronic devices according to the various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to the embodiments of this document are not limited to the aforementioned devices.

[0043] FIG. 2 is a block diagram illustrating the configuration of an electronic device according to various embodiments.

[0044] Referring to FIG. 2, the electronic device (200) may include a communication interface (210), a processor (220), a security integrated circuit (IC) (230), and a memory (240).

[0045] The communication interface (210) (e.g., the communication module (190) of FIG. 1) may include a first security circuit (211) (e.g., an eSE). As an example, the communication interface (210) may include, but is not limited to, NFC (near field communication). The first security circuit (211) may include a root key, a first secure communication certificate, and a first secure communication key. As an example, the root key of the first security circuit (211) may include a root key (security IC), the first secure communication certificate may include an SCP11a certificate (first security circuit), and the first secure communication key may include an SCP11a key (first security circuit). For example, in the SCP11a certificate (first security circuit), the SCP11a certificate may indicate a type, and (the first security circuit) may indicate an initial location within the electronic device (200).

[0046] A processor (220) (e.g., processor (120) of FIG. 1) can control each component of an electronic device (200) (e.g., electronic device (101) of FIG. 1). The electronic device (200) can include one or more processors (220). For example, the processor (220) can correspond to a plurality of processors that collectively perform a plurality of functions by dividing them among the processors. The processor (220) can include a second security circuit (221) (e.g., trustzone). The second security circuit (221) can include a root key. As an example, the root key of the second security circuit (221) can include a root key (eSE).

[0047] The security IC (230) may include a security chain certificate and a security chain key. As an example, the security chain certificate may include a Sub CA (certificate authority) certificate (security IC), and the security chain key may include a Sub CA key (security IC).

[0048] For example, the keys and / or certificates included in the first security circuit (211), the second security circuit (221), and / or the security IC (230) may be input (or injected, transmitted, stored, installed) when the security circuit is produced or when the secure channel is created. The keys included in the first security circuit (211), the second security circuit (221), and / or the security IC (230) may include a private key and / or a public key.

[0049] The memory (240) (e.g., the memory (130) of FIG. 1) can store data, algorithms, programs, and instructions that perform functions of the electronic device (200). Instructions stored in the memory (240) can be loaded into the processor (220) and executed by the processor (220).

[0050] When a specific key and / or software is input into the first security circuit (211) during the manufacturing process of the electronic device (200), the electronic device (200) can generate (or calculate) a shared secret value (e.g., shared secret) in each of the first security circuit (211) and the second security circuit (221). The electronic device (200) can use the shared secret value to ensure that the communication channel generated between the first security circuit (211) and the second security circuit (221) is a channel capable of secure communication. To generate the shared secret value, a certificate and a key for certificate verification are required. For example, the electronic device (200) can use a root key located in an external security device, a hardware security module (HSM), to generate the certificate verification and / or shared secret value. As an example, the HSM may include a root key for signing a Sub CA certificate input when manufacturing the electronic device (200). The Sub CA certificate is a certificate for signing the SCP11a certificate, and the generated key chain (e.g., root key - Sub CA key - SCP11a key) can guarantee that the SCP11a certificate was signed by a trusted root key. However, if the HSM is not installed or cannot be installed (e.g., outsourced production), the electronic device (200) cannot input the root key, and cannot create a secure channel between the first security circuit (211) and the second security circuit (221), verify the certificate, and / or create a shared secret value.

[0051] This document can provide an electronic device, method and storage medium for mutual authentication and generating a shared secret value between a first security circuit (211) and a second security circuit (221) through a security IC (230).

[0052] For example, the processor (220) may perform a key chain generation operation. The processor (220) may generate a second secure communication key (e.g., SCP11a key (device)) in the second security circuit (221). The processor (220) may generate data for generating a second secure communication certificate (e.g., SCP11a certificate (device)) in the second security circuit (221). The processor (220) may transmit the data for generating the certificate to the security IC (230). The processor (220) may sign the data for generating the certificate using the security chain private key (e.g., Sub CA private key (security IC)) in the security IC (230) and transmit the data for generating the signed certificate to the second security circuit (221). The processor (220) may generate a second secure communication certificate (e.g., SCP11a certificate (device)) in the second security circuit (221) based on the data for generating the signed certificate.

[0053] For example, when a security IC (230) is produced, a security chain certificate (e.g., Sub CA certificate (security IC)) signed with a root key (e.g., Root Key (security IC)) may be mounted on the security IC (230). And, a security chain key (e.g., Sub CA key (security IC)) may be mounted on the security IC (230). The security chain certificate (e.g., Sub CA certificate (security IC)) may include information of a security chain public key (e.g., Sub CA public key (security IC)). For example, the security chain certificate (e.g., Sub CA certificate (security IC)) may be signed with a root key (e.g., Root Key (security IC)) and may include information of a security chain public key (e.g., Sub CA public key (security IC)). The second secure communication certificate (e.g., SCP11a certificate (device)) may be signed with a security chain private key (e.g., Sub CA private key (security IC)) and may include information of the second secure communication public key (e.g., SCP11a public key (device)). Accordingly, in the second security circuit (221), a key chain such as a root key (e.g., root key (security IC)) - security chain key (e.g., Sub CA key (security IC)) - second secure communication key (e.g., SCP11a key (device)) may be generated.

[0054] The processor (220) can create a secure channel between the first security circuit (211) and the second security circuit (221). For example, the processor (220) can authenticate the second security circuit (221) based on the second secure communication certificate (e.g., SCP11a certificate (device)) and the root key (e.g., root key (security IC)) in the first security circuit (211). For example, the processor (220) can transfer the security chain certificate (e.g., Sub CA certificate (security IC)) from the security IC (230) to the second security circuit (221). The processor (220) can transfer the security chain certificate (e.g., Sub CA certificate (security IC)) and the second secure communication certificate (e.g., SCP11a certificate (device)) from the second security circuit (221) to the first security circuit (211). The processor (220) can authenticate the second security circuit (221) by verifying a certificate chain between a security chain certificate (e.g., a Sub CA certificate (security IC)) and a second secure communication certificate (e.g., an SCP11a certificate (device)) with a root public key (e.g., a root public key (security IC)) in the first security circuit (211). The processor (220) can obtain a second secure communication public key (e.g., an SCP11a public key (device)) from the second secure communication certificate (e.g., an SCP11a certificate (device)).

[0055] For example, the processor (220) can authenticate the first security circuit (211) based on the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) and the root key (e.g., root key (first secure circuit)) in the second security circuit (221). The processor (220) can authenticate the first security circuit (211) by verifying the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) with the root public key (e.g., root public key (first secure circuit)) in the second security circuit (221). The processor (220) can obtain the first secure communication public key (e.g., SCP11a public key (first secure circuit)) from the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)).

[0056] The processor (220) can create a secure communication channel between the first security circuit (211) and the second security circuit (221). The processor (220) can obtain a shared secret value from each of the first security circuit (211) and the second security circuit (221).

[0057] For example, the processor (220) may obtain the first shared secret value based on the second secure communication certificate (e.g., SCP11a certificate (device)) and the first secure communication key (e.g., SCP11a key (device)) from the first secure circuit (211). As an example, when the first secure circuit (211) is produced, the first secure communication key (e.g., SCP11a key (device)) may be input into the first secure circuit (211). The first secure communication key (e.g., SCP11a key (device)) may include the first secure communication private key (e.g., SCP11a private key (device)). The second secure communication public key (e.g., SCP11a public key (device)) may be obtained from the secure communication certificate (e.g., SCP11a certificate (device)) in the first secure circuit (211). The processor (220) can obtain a first shared secret value from the first security circuit (211) based on a first secure communication private key (e.g., SCP11a private key (device)) and a second secure communication public key (e.g., SCP11a public key (device)).

[0058] For example, the processor (220) may obtain a second shared secret value based on a first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) and a second secure communication key (e.g., SCP11a key (device)) from the second secure circuit (221). As an example, during the production process of the electronic device (200), the second secure communication key (e.g., SCP11a key (device)) may be generated from the second secure circuit (221). The second secure communication key (e.g., SCP11a key (device)) may include a second secure communication private key (e.g., SCP11a private key (device)). The first secure communication public key (e.g., SCP11a public key (first secure circuit)) may be obtained from the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) from the second secure circuit (221). The processor (220) can obtain a second shared secret value from the second security circuit (221) based on a second secure communication private key (e.g., SCP11a private key (device)) and a first secure communication public key (e.g., SCP11a public key (first security circuit)). The processor (220) can perform secure communication between the first security circuit and the second security circuit based on the first shared secret value and the second shared secret value.

[0059] Various embodiments of the present document can generate mutual authentication and shared secret values ​​between a first security circuit (211) and a second security circuit (221) even without an HSM including a root key. For example, various embodiments of the present document can generate a secure channel and perform secure communication between the first security circuit (211) and the second security circuit (221) using a security IC (230) including a security chain certificate (e.g., a Sub CA certificate (security IC)) and a security chain key (Sub CA key (security IC)).

[0060] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.

[0061] FIG. 3 is a drawing explaining operations performed in the production process of a security IC according to various embodiments.

[0062] Referring to FIG. 3, an HSM (11) and a security IC (230) are illustrated. During the manufacturing process of the security IC (230), a security chain certificate (e.g., Sub CA certificate (security IC)) and a security chain key (e.g., Sub CA key (security IC)) verified using a root key included in the HSM (11) can be input into the security IC (230). For example, a root key (e.g., root key (security IC)) included in the HSM (11) can be used as the root of the key chain of the first security circuit (211). When manufacturing the security IC (230), the HSM (11) can generate a security chain certificate (e.g., Sub CA certificate (security IC)) and a security chain key (e.g., Sub CA key (security IC)) signed with a root private key (e.g., root private key (security IC)). The security chain key can include a security chain private key and a security chain public key. HSM (11) can input the generated security chain certificate (e.g., Sub CA certificate (security IC)) and security chain key (e.g., Sub CA key (security IC)) into the security IC (230).

[0063] For example, a security chain certificate may include a Sub CA certificate (security IC), and a security chain key may include a Sub CA key (security IC). The Sub CA certificate (security IC) may represent a Sub CA certificate located in the security IC (230), and the Sub CA key (security IC) may represent a Sub CA key located in the security IC (230).

[0064] FIG. 4 is a drawing illustrating operations performed in the production process of a security circuit according to various embodiments.

[0065] Referring to FIG. 4, a first security circuit vendor (13) and a first security circuit (211) are illustrated. The first security circuit vendor (13) can receive a root certificate (e.g., root certificate (security IC)) from a security IC vendor (or, HSM (11)). The first security circuit vendor (13) can verify the received root certificate (e.g., root certificate (security IC)). If there is no problem with the root certificate (e.g., root certificate (security IC)), the first security circuit vendor (13) can extract a root public key (e.g., root public key (security IC)) from the root certificate (e.g., root certificate (security IC)). The first security circuit vendor (13) can input the extracted root public key (e.g., root public key (security IC)) into the first security circuit (211). In addition, the first security circuit vendor (13) can input a first security communication key (e.g., SCP11a key (first security circuit)) and a first security communication certificate (e.g., SCP11a certificate (first security circuit)) into the target security domain (2111) of the first security circuit (211) that forms a security channel with the second security circuit (221). For example, the first security communication key can include a first security communication private key and a first security communication public key.

[0066] FIG. 5 is a drawing illustrating a security circuit and a security IC mounted on an electronic device according to various embodiments.

[0067] Referring to FIG. 5, a first security circuit (211), a second security circuit (221), and a security IC (230) are illustrated. When an electronic device (200) is manufactured, the first security circuit (211) and the security IC (230) may be mounted. In addition, the second security circuit (221) may be mounted on a processor (220).

[0068] As described in FIG. 3, the security IC (230) may include a security chain certificate (e.g., Sub CA certificate (security IC)) and a security chain key (e.g., Sub CA key (security IC)). For example, the security chain certificate (e.g., Sub CA certificate (security IC)) may be used to verify a second secure communication certificate (e.g., SCP11a certificate (device)). The security chain private key (e.g., Sub CA private key (security IC)) may be used to sign the second secure communication certificate (e.g., SCP11a certificate (device)).

[0069] As described in FIG. 4, the target security domain (2111) of the first security circuit (211) may include a root public key (e.g., root public key (security IC)), a first secure communication key (e.g., SCP11a key (first secure circuit)), and a first secure communication certificate (e.g., SCP11a certificate (first secure circuit)). For example, the first secure communication key may include a first secure communication private key and a first secure communication public key. The root public key (e.g., root public key (security IC)) may be used for verification of a certificate chain (or key chain). The first secure communication key (e.g., SCP11a key (first secure circuit)) and the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) may be used for secure channel communication between the first security circuit (211) and the second security circuit (221).

[0070] The manufacturer of the electronic device (200) can receive a root certificate (e.g., root certificate (first security circuit)) from the first security circuit vendor (13). The manufacturer of the electronic device (200) can verify the root certificate (e.g., root certificate (first security circuit)) and, if there is no problem, can extract a root public key (e.g., root public key (security IC)) from the root certificate (e.g., root certificate (first security circuit)). The manufacturer of the electronic device (200) can input the extracted root public key (e.g., root public key (security IC)) into the second security circuit (221). For example, the root public key (e.g., root public key (security IC)) can be used to verify the first secure communication certificate (e.g., SCP11a certificate (first security circuit)) when creating a secure channel between the first security circuit (211) and the second security circuit (221).

[0071] FIGS. 6A and 6B are drawings illustrating key chain forming operations according to various embodiments.

[0072] Referring to FIG. 6a, the operation of the second security circuit (221) and the security IC (230) when the electronic device (200) is produced is illustrated. Referring to FIG. 6b, a timing diagram explaining the operation of the second security circuit (221) and the security IC (230) is illustrated. The description will be made with reference to FIG. 6a and FIG. 6b together.

[0073] In the following examples, the operations may be performed sequentially, but are not necessarily sequential. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.

[0074] According to one embodiment, steps 610 to 650 may be understood to be performed in a processor (e.g., processor (120) of FIG. 1 or processor (220) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1 or electronic device (200) of FIG. 2).

[0075] As described in FIG. 5, when the first security circuit (211) and the security IC (230) are mounted on the electronic device (200), the second security circuit (221) may include a root public key (e.g., root public key (security IC)). The security IC (230) may include a security chain certificate (e.g., Sub CA certificate (security IC)) and a security chain key (e.g., Sub CA key (security IC)).

[0076] In the production process of the electronic device (200), the second security circuit (221) can generate a second security communication key (e.g., SCP11a key (device)) (610). In addition, the second security circuit (221) can generate data for generating a certificate. For example, the data for generating the certificate can include data for generating a second security communication certificate (e.g., SCP11a certificate (device)).

[0077] The second security circuit (221) can transmit the generated data to the security IC (230) (620). The security IC (230) can sign the transmitted data with a security chain private key (e.g., Sub CA private key (security IC)) (630). The security IC (230) can transmit the signed data to the second security circuit (221) (640).

[0078] The second security circuit (221) can generate a second secure communication certificate (e.g., SCP11a certificate (device)) using the received signed data (650). For example, a security chain certificate (e.g., Sub CA certificate (security IC)) may be signed with a root private key (e.g., root private key (security IC)) and include information of a security chain public key (e.g., Sub CA public key (security IC)). The second secure communication certificate (e.g., SCP11a certificate (device)) may be signed with a security chain private key (e.g., Sub CA private key (security IC)) and include information of a second secure communication public key (e.g., SCP11a public key (device)). In the second security circuit (221), a key chain of a root key (e.g., root key (security IC)) - a security chain key (e.g., Sub CA key (security IC)) - a second secure communication key (e.g., SCP11a key (device)) may be formed. As an example, in the second security circuit (221), a certificate chain of a root certificate (e.g., root certificate (security IC)) - a security chain certificate (e.g., Sub CA certificate (security IC)) - a second security communication certificate (e.g., SCP11a certificate (device)) can be formed.

[0079] FIG. 7A and FIG. 7B are diagrams illustrating eSE authentication operations according to various embodiments.

[0080] Referring to FIG. 7a, the operation of the second security circuit (221) and the first security circuit (211) is illustrated when the electronic device (200) is produced. Referring to FIG. 7b, a timing diagram explaining the operation of the second security circuit (221) and the first security circuit (211) is illustrated. The description will be made with reference to FIG. 7a and FIG. 7b together.

[0081] In the following examples, the operations may be performed sequentially, but are not necessarily sequential. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.

[0082] According to one embodiment, steps 710 to 740 may be understood to be performed in a processor (e.g., processor (120) of FIG. 1 or processor (220) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1 or electronic device (200) of FIG. 2).

[0083] As described in FIG. 5, when the first security circuit (211) and the security IC (230) are mounted on the electronic device (200), the target security domain (2111) of the first security circuit (211) may include a root public key (e.g., root public key (security IC)), a first security communication key (e.g., SCP11a key (first security circuit)), and a first security communication certificate (e.g., SCP11a certificate (first security circuit)).

[0084] The second security circuit (221) can request data (e.g., Get data command) from the first security circuit (211) (710). The first security circuit (211) can transmit a first secure communication certificate (e.g., SCP11a certificate (first security circuit)) to the second security circuit (221) at the request of the second security circuit (221) (720).

[0085] The second security circuit (221) can verify the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) received with the root public key (e.g., root public key (first secure circuit)) (730). If the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) is not abnormal, the second security circuit (221) can extract the first secure communication public key (e.g., SCP11a public key (first secure circuit)) from the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) (740). The second security circuit (221) can authenticate the first security circuit (211) through the above-described process.

[0086] FIG. 8a, FIG. 8b, and FIG. 8c are diagrams illustrating trustzone authentication operations according to various embodiments.

[0087] Referring to FIG. 8a, the operation of the security IC (230), the second security circuit (221), and the first security circuit (211) when the electronic device (200) is produced is illustrated. Referring to FIG. 8b, the operation of the first security circuit (211) is illustrated. Referring to FIG. 8c, a timing diagram explaining the operation of the security IC (230), the second security circuit (221), and the first security circuit (211) is illustrated. The description will be made with reference to FIGS. 8a, 8b, and 8c together.

[0088] In the following examples, the operations may be performed sequentially, but are not necessarily sequential. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.

[0089] According to one embodiment, steps 810 to 840 may be understood to be performed in a processor (e.g., processor (120) of FIG. 1 or processor (220) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1 or electronic device (200) of FIG. 2).

[0090] The security IC (230) can transmit a security chain certificate (e.g., Sub CA certificate (security IC)) to the second security circuit (221) (810). The second security circuit (221) can transmit a secure communication execution command to the first security circuit (211). As an example, the secure communication execution command may be a Perform Security Operation command, and the Perform Security Operation command may be a command for SCP11 defined in Global Platform Card Specification Amendment F. When the second security circuit (221) transmits the secure communication execution command to the first security circuit (211), a security chain certificate (e.g., Sub CA certificate (security IC)) and a second secure communication certificate (e.g., SCP11a certificate (device)) may be transmitted together (820).

[0091] The first security circuit (211) can verify a certificate chain (e.g., root certificate (e.g., root certificate (security IC)) - security chain certificate (e.g., Sub CA certificate (security IC)) - second secure communication certificate (e.g., SCP11a certificate (device))) using a root public key (e.g., root public key (security IC)) (830), and can extract a second secure communication public key (e.g., SCP11a public key (device)) from the second secure communication certificate (e.g., SCP11a certificate (device)) (840).

[0092] For example, the first security circuit (211) can verify a security chain certificate (e.g., a Sub CA certificate (security IC)) with a root public key (e.g., a root public key (security IC)) and extract a security chain public key (e.g., a Sub CA public key (security IC))) from the security chain certificate (e.g., a Sub CA certificate (security IC)). The first security circuit (211) can verify a second secure communication certificate (e.g., an SCP11a certificate (device)) with the extracted security chain public key (e.g., a Sub CA public key (security IC))) and extract a second secure communication public key (e.g., an SCP11a public key (device)) from the second secure communication certificate (e.g., an SCP11a certificate (device)). The first security circuit (211) can authenticate the second security circuit (221) through the above-described process.

[0093] FIG. 9 is a diagram illustrating an operation of calculating a shared secret value according to various embodiments.

[0094] Referring to FIG. 9, the second security circuit (221) may include a second security communication key (e.g., SCP11a key (device)) and a first security communication public key (e.g., SCP11a public key (first security circuit)). The second security communication key may include a second security communication private key and a second security communication public key. The first security circuit (211) may include a first security communication key (e.g., SCP11a key (first security circuit)) and a second security communication public key (e.g., SCP11a public key (device)). The first security communication key may include a first security communication private key and a first security communication public key.

[0095] For example, a second secure communication key (e.g., SCP11a key (device)) may be generated in a second secure circuit (221), as described in FIG. 2. A first secure communication private key (e.g., SCP11a private key (first secure circuit)) may be extracted from a first secure communication certificate (e.g., SCP11a certificate (first secure circuit)), as described in FIG. 7a. The first secure communication key (e.g., SCP11a key (first secure circuit)) may be input by a first secure circuit vendor (13), as described in FIG. 4. A second secure communication public key (e.g., SCP11a public key (device)) may be extracted from a second secure communication certificate (e.g., SCP11a certificate (device)), as described in FIG. 8b.

[0096] The first security circuit (211) can obtain a first shared secret value based on a first secure communication private key (e.g., SCP11a private key (first security circuit)) and a second secure communication public key (e.g., SCP11a public key (device)). The second security circuit (221) can obtain a second shared secret value based on the second secure communication private key (e.g., SCP11a private key (device)) and the first secure communication public key (e.g., SCP11a public key (first security circuit)). The electronic device (200) can perform secure communication between the first security circuit and the second security circuit based on the first shared secret value and the second shared secret value. For example, the electronic device (200) can calculate a secure session key using each of the first shared secret value and the second shared secret value. If the secure session keys match, the electronic device (200) can perform secure channel communication between the first security circuit (211) and the second security circuit (221).

[0097] FIG. 10 is a flowchart illustrating a method for performing secure communication according to various embodiments.

[0098] In the following examples, the operations may be performed sequentially, but are not necessarily sequential. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.

[0099] According to one embodiment, steps 1010 to 1070 may be understood to be performed in a processor (e.g., processor (120) of FIG. 1 or processor (220) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1 or electronic device (200) of FIG. 2).

[0100] Referring to FIG. 10, the second security circuit (221) can generate a second secure communication private key (e.g., SCP11a private key (device)) and transmit data for certificate generation to the security IC (230) (1010). For example, the data for certificate generation can include data for generating a second secure communication certificate (e.g., SCP11a certificate (device)).

[0101] The security IC (230) can sign data for certificate generation using a security chain private key (e.g., Sub CA private key (security IC)). Then, the security IC (230) can transmit data for signed certificate generation to the second security circuit (221) (1020).

[0102] The second security circuit (221) can generate a second secure communication certificate (e.g., SCP11a certificate (device)) based on data for generating a signed certificate (1030).

[0103] The first security circuit (211) and the second security circuit (221) can form a mutually secure communication channel (1040).

[0104] For example, the first security circuit (211) can receive a second secure communication certificate (e.g., SCP11a certificate (device)) from the second security circuit (221). The first security circuit (211) can authenticate the second security circuit (221) based on the received second secure communication certificate (e.g., SCP11a certificate (device)) and the root public key (e.g., root public key (security IC)). As an example, the first security circuit (211) can verify a certificate chain using the root public key (e.g., root public key (security IC)). In addition, the first security circuit (211) can extract the second secure communication public key (e.g., SCP11a public key (device)) from the second secure communication certificate (e.g., SCP11a certificate (device)). The key and certificate of the first security circuit (211) can be included in the target security domain.

[0105] For example, the second security circuit (221) can receive a first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) from the first security circuit (211). The second security circuit (221) can authenticate the first security circuit (211) based on the received first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) and the root public key (e.g., root public key (first secure circuit)). As an example, the second security circuit (221) can verify the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) with the root public key (e.g., root public key (first secure circuit)). In addition, the second security circuit (221) can extract the first secure communication public key (e.g., SCP11a public key (first secure circuit)) from the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)). Through the above-described process, the first security circuit (211) and the second security circuit (221) can form a secure communication channel.

[0106] The first security circuit (211) can obtain a first shared secret value based on a second secure communication certificate (e.g., SCP11a certificate (device)) and a first secure communication private key (e.g., SCP11a private key (first security circuit)) (1050). For example, the first security circuit (211) can extract a second secure communication public key (e.g., SCP11a public key (device)) from the second secure communication certificate (e.g., SCP11a certificate (device)) and obtain a first shared secret value using the extracted second secure communication public key (e.g., SCP11a public key (device)) and the first secure communication private key (e.g., SCP11a private key (first security circuit)).

[0107] The second security circuit (221) can obtain a second shared secret value based on a first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) and a second secure communication private key (e.g., SCP11a private key (device)) (1060). For example, the second security circuit (221) can extract a first secure communication public key (e.g., SCP11a public key (first secure circuit)) from the first secure communication certificate (e.g., SCP11a certificate (first secure circuit)) and obtain a second shared secret value using the extracted first secure communication public key (e.g., SCP11a public key (first secure circuit)) and the second secure communication private key (e.g., SCP11a private key (device)).

[0108] The electronic device (200) can perform secure communication between the first security circuit and the second security circuit based on the first shared secret value and the second shared secret value (1070). For example, the electronic device (200) can determine whether a security session key calculated using the first shared secret value matches a security session key calculated using the second shared secret value. If the security session keys match, the electronic device (200) can perform secure channel communication between the first security circuit (211) and the second security circuit (221).

[0109] As an example, an electronic device (200) may include a communication interface (210) including a first security circuit (211). The first security circuit (211) may include a root public key, a first secure communication certificate, and a first secure communication private key. The electronic device (200) may include at least one processor (221) including a second security circuit (221). The second security circuit (221) may include a root public key. The electronic device (200) may include a security IC (230) including a security chain certificate and a security chain private key, and a memory (240) storing instructions executed by the at least one processor (220). The instructions stored in the memory (240) may be configured to cause the electronic device (200) to generate a second secure communication private key in the second security circuit (221) and to transmit data for certificate generation to the security IC (230). The command stored in the memory (240) may be configured to cause the electronic device (200) to sign data for generating the certificate using the security chain private key in the security IC (230) and transmit the data for generating the signed certificate to the second security circuit (221). The command stored in the memory (240) may be configured to cause the electronic device (200) to generate a second secure communication certificate based on the data for generating the signed certificate in the second security circuit (221). The command stored in the memory (240) may be configured to cause the electronic device (200) to authenticate the second security circuit (221) based on the second secure communication certificate and the root public key received from the second security circuit (221) in the first security circuit (211).The command stored in the memory (240) may be configured to cause the electronic device (200) to authenticate the first security circuit (211) based on the first secure communication certificate and the root public key received from the first security circuit (211) in the second security circuit (221). The command stored in the memory (240) may be configured to cause the electronic device (200) to establish a secure communication channel between the first security circuit (211) and the second security circuit (221). The command stored in the memory (240) may be configured to cause the electronic device (200) to obtain a first shared secret value based on the second secure communication certificate and the first secure communication private key in the first security circuit (211). The command stored in the memory (240) may be configured to cause the electronic device (200) to obtain a second shared secret value based on the first secure communication certificate and the second secure communication private key from the second security circuit (221). The command stored in the memory (240) may be configured to cause the electronic device (200) to perform secure communication between the first security circuit (211) and the second security circuit (221) based on the first shared secret value and the second shared secret value.

[0110] As an example, the command stored in the memory (240) may be configured to cause the electronic device (200) to receive the security chain certificate from the security IC in the second security circuit (221). The command stored in the memory (240) may be configured to cause the electronic device (200) to receive the security chain certificate and the second secure communication certificate from the second security circuit (221) in the first security circuit (211), authenticate the second security circuit by verifying the certificate chain between the security chain certificate and the second secure communication certificate with the root public key, and obtain a second secure communication public key from the second secure communication certificate.

[0111] As an example, the command stored in the memory (240) may be configured to cause the electronic device (200) to obtain the first shared secret value based on the first secure communication private key and the second secure communication public key from the first security circuit (211).

[0112] As an example, the command stored in the memory (240) may be configured to cause the electronic device (200) to authenticate the first security circuit by verifying the first secure communication certificate with the root public key in the second security circuit (221), and to obtain the first secure communication public key from the first secure communication certificate.

[0113] As an example, the command stored in the memory (240) may be configured to cause the electronic device (200) to obtain the second shared secret value based on the second secure communication private key and the first secure communication public key from the second security circuit (221).

[0114] As an example, the security chain certificate may be generated by signing the root private key and the security chain private key in the security device (11) and stored in the security IC (230).

[0115] As an example, the root public key included in the first security circuit (211) can be obtained from a root certificate received from the security device (11).

[0116] As an example, the root public key, the first secure communication certificate, and the first secure communication private key of the first security circuit (211) may be included in the target security domain of the first security circuit (211).

[0117] As an example, a method for performing secure communication in an electronic device (200) including a first security circuit (211), a second security circuit (221), and a security IC (230) may include generating a second secure communication private key in the second security circuit (221) and transmitting data for certificate generation to the security IC (230). The method may include signing data for certificate generation using the security chain private key in the security IC (230) and transmitting data for signed certificate generation to the second security circuit (221). The method may include generating a second secure communication certificate based on the data for signed certificate generation in the second security circuit (221). The method may authenticate the second security circuit (221) based on the second secure communication certificate and the root public key received from the second security circuit in the first security circuit (211), and may authenticate the first security circuit (211) based on the first secure communication certificate and the root public key received from the first security circuit (211) in the second security circuit (221), thereby forming a secure communication channel between the first security circuit (211) and the second security circuit (221). The method may obtain a first shared secret value based on the second secure communication certificate and the first secure communication private key in the first security circuit (211). The method may obtain a second shared secret value based on the first secure communication certificate and the second secure communication private key in the second security circuit (221). The above method can perform secure communication between the first security circuit (211) and the second security circuit (221) based on the first shared secret value and the second shared secret value.

[0118] As an example, the operation of forming the secure communication channel may include receiving the security chain certificate from the security IC (230) in the second security circuit (221), receiving the security chain certificate and the second secure communication certificate from the second security circuit (221) in the first security circuit (211), authenticating the second security circuit (221) by verifying a certificate chain between the security chain certificate and the second secure communication certificate with the root public key, and obtaining a second secure communication public key from the second secure communication certificate.

[0119] As an example, the operation of obtaining the first shared secret value may obtain the first shared secret value based on the first secure communication private key and the second secure communication public key in the first security circuit (211).

[0120] As an example, the operation of forming the secure communication channel may authenticate the first security circuit (211) by verifying the first secure communication certificate with the root public key in the second security circuit (221), and obtain the first secure communication public key from the first secure communication certificate.

[0121] As an example, the operation of obtaining the second shared secret value may obtain the second shared secret value based on the second secure communication private key and the first secure communication public key in the second security circuit (221).

[0122] As an example, the security chain certificate may be generated by signing the root private key and the security chain private key in the security device (11) and stored in the security IC (230).

[0123] As an example, the root public key included in the first security circuit (211) can be obtained from a root certificate received from the security device (11).

[0124] As an example, the root public key, the first secure communication certificate, and the first secure communication private key of the first security circuit (211) may be included in the target security domain of the first security circuit (211).

[0125] As an example, a non-transitory computer-readable storage medium having recorded thereon a program for performing a method for performing secure communication in an electronic device (200) including a first security circuit (211), a second security circuit (221), and a security IC (230) may include an operation for generating a second secure communication private key in the second security circuit (221) and transmitting data for certificate generation to the security IC (230). The storage medium may include an operation for signing data for certificate generation using the security chain private key in the security IC (230) and transmitting data for signed certificate generation to the second security circuit (221). The storage medium may include an operation for generating a second secure communication certificate based on the data for signed certificate generation in the second security circuit (221). The storage medium may include an operation for authenticating the second security circuit (221) based on the second secure communication certificate and the root public key received from the second security circuit (221) in the first security circuit (211), and for authenticating the first security circuit (211) based on the first secure communication certificate and the root public key received from the first security circuit (211) in the second security circuit (221), thereby forming a secure communication channel between the first security circuit (211) and the second security circuit (221). The storage medium may include an operation for obtaining a first shared secret value based on the second secure communication certificate and the first secure communication private key in the first security circuit (211). The storage medium may include an operation for obtaining a second shared secret value based on the first secure communication certificate and the second secure communication private key in the second security circuit (221).The above storage medium may include an operation for performing secure communication between the first security circuit (211) and the second security circuit (221) based on the first shared secret value and the second shared secret value.

[0126] As an example, the operation of forming the secure communication channel may include receiving the security chain certificate from the security IC (230) in the second security circuit (221), receiving the security chain certificate and the second secure communication certificate from the second security circuit (221) in the first security circuit (211), authenticating the second security circuit (221) by verifying a certificate chain between the security chain certificate and the second secure communication certificate with the root public key, and obtaining a second secure communication public key from the second secure communication certificate.

[0127] As an example, the operation of obtaining the first shared secret value may obtain the first shared secret value based on the first secure communication private key and the second secure communication public key in the first security circuit (211).

[0128] As an example, the operation of forming the secure communication channel may authenticate the first secure circuit by verifying the first secure communication certificate with the root public key in the second security circuit (221), and obtain the first secure communication public key from the first secure communication certificate.

[0129] The various embodiments of this document and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.

[0130] The term "module" used in various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0131] Various embodiments of the present document may be implemented as software (e.g., a program (140)) including one or more instructions stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101)). For example, a processor (e.g., a processor (120)) of the machine (e.g., an electronic device (101)) may call at least one instruction among the one or more instructions stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.

[0132] According to one embodiment, the method according to various embodiments disclosed in this document may be provided as a computer program product. The computer program product may be traded between sellers and buyers as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or may be provided through an application store (e.g., Play Store). TM ) or directly between two user devices (e.g., smart phones), online distribution (e.g., downloading or uploading). In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily created in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.

[0133] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and arranged in other components. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

[0134] The effects of this document are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the above description.

Claims

1. In electronic devices, A communication interface comprising a first security circuit, the first security circuit comprising a root public key, a first secure communication certificate, and a first secure communication private key; At least one processor comprising a second security circuit, the second security circuit comprising the root public key; A security IC containing a security chain certificate and a security chain private key; and a memory storing instructions executed by at least one processor; The instructions stored in the above memory cause the electronic device to: In the second security circuit, a second security communication private key is generated, and data for certificate generation is transmitted to the security IC. The security IC signs the data for generating the certificate using the security chain private key, and transmits the data for generating the signed certificate to the second security circuit. Generating a second secure communication certificate based on the data for generating the signed certificate in the second security circuit, Authenticate the second security circuit based on the second security communication certificate and the root public key received from the second security circuit in the first security circuit, In the second security circuit, the first security circuit is authenticated based on the first security communication certificate and the root public key received from the first security circuit, Forming a secure communication channel between the first security circuit and the second security circuit, Obtaining a first shared secret value based on the second secure communication certificate and the first secure communication private key in the first secure circuit; In the second security circuit, a second shared secret value is obtained based on the first security communication certificate and the second security communication private key, An electronic device configured to perform secure communication between the first security circuit and the second security circuit based on the first shared secret value and the second shared secret value.

2. In paragraph 1, The instructions stored in the above memory cause the electronic device to: Receive the security chain certificate from the security IC in the second security circuit; An electronic device configured to receive the security chain certificate and the second secure communication certificate from the second security circuit in the first security circuit, authenticate the second security circuit by verifying the certificate chain between the security chain certificate and the second secure communication certificate with the root public key, and obtain a second secure communication public key from the second secure communication certificate.

3. In paragraph 2, The instructions stored in the above memory cause the electronic device to: An electronic device configured to obtain the first shared secret value based on the first secure communication private key and the second secure communication public key in the first secure circuit.

4. In paragraph 1, The instructions stored in the above memory cause the electronic device to: An electronic device configured to authenticate the first security circuit by verifying the first secure communication certificate with the root public key in the second security circuit, and to obtain the first secure communication public key from the first secure communication certificate.

5. In paragraph 4, The instructions stored in the above memory cause the electronic device to: An electronic device configured to obtain the second shared secret value based on the second secure communication private key and the first secure communication public key in the second secure circuit.

6. In paragraph 1, The above security chain certificate is, An electronic device generated by signing with a root private key and the security chain private key in a security device and stored in the security IC.

7. In paragraph 1, The root public key included in the above first security circuit is, An electronic device obtained from a root certificate received from a security device.

8. In paragraph 1 The root public key, the first secure communication certificate and the first secure communication private key of the above first secure circuit are, An electronic device included in the target security domain among the above first security circuits.

9. A method for performing secure communication in an electronic device including a first security circuit, a second security circuit, and a security IC, An operation of generating a second secure communication private key in the second secure circuit and transmitting data for certificate generation to the secure IC; An operation of signing data for generating the certificate using the security chain private key in the security IC and transmitting the data for generating the signed certificate to the second security circuit; An operation of generating a second secure communication certificate based on data for generating the signed certificate in the second secure circuit; An operation of authenticating the second security circuit based on a second secure communication certificate received from the second security circuit and a root public key included in the second security circuit in the first security circuit, and authenticating the first security circuit based on the first secure communication certificate received from the first security circuit and the root public key in the second security circuit, thereby forming a secure communication channel between the first security circuit and the second security circuit; An operation of obtaining a first shared secret value based on the second secure communication certificate and the first secure communication private key included in the first secure circuit in the first secure circuit; An operation of obtaining a second shared secret value based on the first secure communication certificate and the second secure communication private key in a second secure circuit; and A method comprising: performing secure communication between the first security circuit and the second security circuit based on the first shared secret value and the second shared secret value.

10. In paragraph 9, The action of forming the above secure communication channel is: Receive the security chain certificate from the security IC in the second security circuit; A method for authenticating a second security circuit by receiving the security chain certificate and the second secure communication certificate from the second security circuit in the first security circuit, verifying a certificate chain between the security chain certificate and the second secure communication certificate with the root public key, and obtaining a second secure communication public key from the second secure communication certificate.

11. In paragraph 10, The operation of obtaining the above first shared secret value is: A method for obtaining the first shared secret value based on the first secure communication private key and the second secure communication public key in the first secure circuit.

12. In paragraph 9, The action of forming the above secure communication channel is: A method for authenticating the first security circuit by verifying the first secure communication certificate with the root public key in the second security circuit, and obtaining the first secure communication public key from the first secure communication certificate.

13. In paragraph 12, The action of obtaining the second shared secret value is: A method configured to obtain the second shared secret value based on the second secure communication private key and the first secure communication public key in the second secure circuit.

14. In paragraph 9, The above security chain certificate is, A method of generating a security device by signing with a root private key and the security chain private key, and storing the security IC.

15. A non-transitory computer-readable storage medium having recorded thereon a program for performing a method of performing secure communication in an electronic device including a first security circuit, a second security circuit, and a security IC, An operation of generating a second secure communication private key in the second secure circuit and transmitting data for certificate generation to the secure IC; An operation of signing data for generating the certificate using the security chain private key in the security IC and transmitting the data for generating the signed certificate to the second security circuit; An operation of generating a second secure communication certificate based on data for generating the signed certificate in the second secure circuit; An operation of authenticating the second security circuit based on a second secure communication certificate received from the second security circuit and a root public key included in the second security circuit in the first security circuit, and authenticating the first security circuit based on the first secure communication certificate received from the first security circuit and the root public key in the second security circuit, thereby forming a secure communication channel between the first security circuit and the second security circuit; An operation of obtaining a first shared secret value based on the second secure communication certificate and the first secure communication private key included in the first secure circuit in the first secure circuit; An operation of obtaining a second shared secret value based on the first secure communication certificate and the second secure communication private key in a second secure circuit; and A non-transitory computer-readable storage medium having recorded thereon a program for performing a method, the method comprising: performing secure communication between the first security circuit and the second security circuit based on the first shared secret value and the second shared secret value.

Citation Information

Patent Citations

  • Linking apparatus based on the ceritification security device and method thereof

    KR1020180052414A

  • Elevator Cage

    KR1020230039003A

  • Display device and method of fabricating the same

    KR1020230174767A

  • Method and apparatus for transformation 3D model

    KR1020240116603A

  • Distributed trusted platform module key management protection for roaming data

    US20230066427A1