Electronic device that registers or recovers credential

The electronic device uses a multi-layer encryption process with protection and recovery keys to securely manage cryptographic keys, addressing confidentiality issues in the SRP protocol and ensuring secure credential transfer and recovery.

WO2026014714A1PCT designated stage Publication Date: 2026-01-15SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/007262
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-22
Filing Date
2025-05-28
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

Existing cryptographic key management systems, such as the SRP protocol, face challenges in ensuring the confidentiality and secure transfer of cryptographic keys, which are crucial for secure security services on electronic devices.

Method used

An electronic device employs a multi-layer encryption process using a protection key, recovery key, and wrapping key to encrypt and decrypt credentials, with re-encryption by a security device and server, ensuring secure key management through the SRP protocol.

Benefits of technology

The multi-layer encryption process enhances the security and confidentiality of cryptographic keys, enabling secure credential registration and recovery across multiple devices, while maintaining the integrity of security services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025007262_15012026_PF_FP_ABST
    Figure KR2025007262_15012026_PF_FP_ABST
Patent Text Reader

Abstract

This electronic device obtains unlocking information of the electronic device from a user, generates authentication information and a wrapping key on the basis of on the unlocking information, generates a credential stored in the electronic device and a protection key and a recovery key for encrypting and decrypting the authentication information, encrypts the authentication information, the credential and the protection key on the basis of keys of the electronic device including the protection key and the recovery key, and transmits the encrypted credential, the encrypted authentication information and the encrypted protection key to a server performing an SRP protocol with the electronic device.
Need to check novelty before this filing date? Find Prior Art

Description

An electronic device that registers or recovers credentials

[0001] An electronic device for registering or recovering credentials is disclosed.

[0002] To ensure secure security services on electronic devices, various cryptographic algorithms, such as symmetric key encryption, public key encryption, digital signatures, and hash algorithms, can be used. Cryptographic algorithms utilize cryptographic keys, and the security of security services ultimately depends on these keys. Therefore, it can be crucial to keep cryptographic keys confidential.

[0003] In the past, the SRP (secure remote password) protocol, a password-based authenticated key exchange (PAKE) technology, was used, in which a user registered his or her password on a server, and later proved to the server that he or she was a legitimate user without exposing the password, thereby sharing a session key between the user and the server.

[0004] The SRP protocol can be a two-way protocol operating between a user and a server. It can include a registration process and a login process. During the registration process, the user can register information related to their password with the server. During the login process, the user can prove their identity without exposing the registered password. If the user is a legitimate user, the user and the server can share the same session key generated based on the password.

[0005] The background technology described above is something that was possessed or acquired during the process of deriving the present disclosure, and cannot necessarily be said to have been disclosed to the general public prior to the filing of the present disclosure.

[0006] According to one aspect of the present disclosure, an electronic device may include a memory that stores instructions. The electronic device may include at least one processor. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to obtain unlock information of the electronic device from a user and generate authentication information and a wrapping key based on the unlock information. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to generate a protection key and a recovery key for encrypting and decrypting credentials and the authentication information stored in the electronic device. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to encrypt the authentication information, the credentials, and the protection key based on keys of the electronic device including the protection key and the recovery key. When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to transmit said encrypted credentials, said encrypted authentication information, and said encrypted protection key to a server performing an SRP protocol with said electronic device.

[0007] When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to encrypt said credential with said protection key to generate said encrypted credential. When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to encrypt said multi-encrypted protection key and said recovery key based on a public key of a security device communicating with said server to generate said encrypted protection key. When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to encrypt said authentication information with said recovery key to generate said encrypted authentication information.

[0008] When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to encrypt said protection key with said recovery key. When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to encrypt said protection key, encrypted with said recovery key, with said wrapping key, thereby generating said multi-encrypted protection key.

[0009] The server may store the encrypted credentials. The server may transmit the encrypted protection key and the encrypted authentication information to a security device communicating with the server for re-encryption.

[0010] The security device can decrypt the encrypted protection key with the private key of the security device to obtain a multi-encrypted protection key and the recovery key. The security device can re-encrypt the recovery key and the multi-encrypted protection key with the symmetric key of the security device to generate a first re-encrypted protection key. The security device can transmit the first re-encrypted protection key to the server. The server can store the first re-encrypted protection key.

[0011] The server may transmit the encrypted credentials to another electronic device based on the identification of the other electronic device as the user's device based on the SRP protocol.

[0012] The server may store encrypted credentials based on unlock information of the other electronic device used to determine whether the other electronic device is the user's device.

[0013] When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to perform said SRP protocol with said server to share a session key based on obtaining said command to recover said credentials. The command to recover said credentials may include said unlock information.

[0014] When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to obtain encrypted information from said server, decrypt said encrypted information based on said session key, and recover said credentials based on information decrypted based on said session key.

[0015] According to one aspect of the present disclosure, an electronic device may include a memory that stores instructions. The electronic device may include at least one processor. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to obtain unlock information used when storing credentials from a user, and to perform an SRP protocol with a server communicating with the electronic device to share a session key with the server. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to receive encrypted credentials stored in the server and a second re-encrypted protection key, information encrypted based on the session key, from the server. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to decrypt the information with the session key to obtain the encrypted credentials and the second re-encrypted protection key. When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to generate a wrapping key based on said unlocking information, and to decrypt said second re-encrypted protection key and said encrypted credential based on said wrapping key and keys stored in said electronic device to obtain said credential.

[0016] The server may transmit the first re-encrypted protection key stored in the server to a security device. The security device may decrypt the first re-encrypted protection key with a symmetric key of the security device to obtain a recovery key and a multi-encrypted protection key. The security device may encrypt the recovery key and the multi-encrypted protection key with the public key of the electronic device to generate the second re-encrypted protection key.

[0017] When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to decrypt said second re-encrypted protection key with a private key of said electronic device to obtain a multi-encrypted protection key and a recovery key. When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to decrypt said multi-encrypted protection key with the wrapping key and the recovery key to obtain a protection key. When said at least one processor individually or collectively executes said instructions, said instructions may cause said electronic device to decrypt said encrypted credential with the protection key to obtain said credential.

[0018] According to one aspect of the present disclosure, a method of operating an electronic device may include obtaining unlock information of the electronic device from a user. The method of operating the electronic device may include generating authentication information and a wrapping key based on the unlock information. The method of operating the electronic device may include generating a credential stored in the electronic device and a protection key and a recovery key for encrypting and decrypting the authentication information. The method of operating the electronic device may include encrypting the authentication information, the credential, and the protection key based on keys of the electronic device including the protection key and the recovery key. The method of operating the electronic device may include transmitting the encrypted credential, the encrypted authentication information, and the encrypted protection key to a server that performs an SRP protocol with the electronic device.

[0019] The operation of encrypting the authentication information, the credential, and the protection key may include an operation of encrypting the credential with the protection key to generate the encrypted credential. The operation of encrypting the authentication information, the credential, and the protection key may include an operation of encrypting a multi-encrypted protection key and the recovery key based on a public key of a security device communicating with the server to generate the encrypted protection key. The operation of encrypting the authentication information, the credential, and the protection key may include an operation of encrypting the authentication information with the recovery key to generate the encrypted authentication information.

[0020] The operation of encrypting the authentication information, the credential, and the protection key may include an operation of encrypting the protection key with the recovery key. The operation of encrypting the authentication information, the credential, and the protection key may include an operation of encrypting the protection key encrypted with the recovery key with the wrapping key to generate the multi-encrypted protection key.

[0021] The above method of operation may further include an operation of storing the encrypted credentials using the server. The above method of operation may further include an operation of transmitting the encrypted protection key and the encrypted authentication information to a security device communicating with the server for re-encryption.

[0022] The above operating method may further include an operation of decrypting the encrypted protection key with a private key of the security device using the security device to obtain a multi-encrypted protection key and the recovery key. The above operating method may further include an operation of re-encrypting the recovery key and the multi-encrypted protection key with a symmetric key of the security device using the security device to generate a first re-encrypted protection key. The above operating method may further include an operation of transmitting the first re-encrypted protection key to the server using the security device. The server may store the first re-encrypted protection key.

[0023] The above method of operation may include an operation of transmitting the encrypted credentials to the other electronic device using the server based on the other electronic device of the user being identified as the device of the user based on the SRP protocol.

[0024] The above method of operation may further include storing encrypted credentials based on unlock information of the other electronic device used to determine whether the other electronic device is the user's device using the server.

[0025] According to one aspect of the present disclosure, a method of operating an electronic device may include an operation of performing an SRP protocol with a server communicating with the electronic device based on obtaining unlock information used when storing credentials from a user to share a session key with the server. The method of operating the electronic device may include an operation of obtaining encrypted information from the server based on the session key, the encrypted credential and a second re-encrypted protection key stored in the server. The method of operating the electronic device may include an operation of decrypting the information with the session key to obtain the encrypted credential and the second re-encrypted protection key. The method of operating the electronic device may include an operation of generating a wrapping key based on the unlock information, and decrypting the second re-encrypted protection key and the encrypted credential based on the wrapping key and keys stored in the electronic device to obtain the credential.

[0026] According to one aspect of the present disclosure, a non-transitory computer-readable storage medium is provided that stores instructions that, when executed by at least one processor, cause the at least one processor to perform a method of operation.

[0027] The above and other aspects, features and advantages of specific embodiments of the present disclosure will become more apparent from the following detailed description taken in conjunction with the accompanying drawings, in which:

[0028] FIG. 1 is a block diagram of an electronic device within a network environment according to various embodiments.

[0029] FIG. 2 is a drawing for explaining an electronic device, a server, and a security device according to one embodiment.

[0030] Figure 3 is a flowchart illustrating a process for registering credentials according to one embodiment.

[0031] FIG. 4 is a flowchart illustrating operations between an electronic device, a server, and a security device for registering credentials according to one embodiment.

[0032] Figure 5 is a flowchart illustrating a process for restoring credentials according to one embodiment.

[0033] FIG. 6 is a flowchart illustrating operations between an electronic device, a server, and a security device for restoring credentials according to one embodiment.

[0034] FIGS. 7 and 8 illustrate screens of an electronic device for explaining registration and restoration of credentials according to one embodiment.

[0035] FIG. 9 is a diagram illustrating restoration of credentials in one of a plurality of electronic devices according to one embodiment.

[0036] FIGS. 10 and 11 are flowcharts illustrating registration and recovery of a quantum-resistant credential according to one embodiment.

[0037] Hereinafter, embodiments will be described in detail with reference to the attached drawings. In the description with reference to the attached drawings, identical components are assigned the same reference numerals regardless of the drawing numbers, and redundant descriptions thereof will be omitted.

[0038] FIG. 1 is a block diagram of an electronic device (101) within a network environment (100) according to various embodiments. Referring to FIG. 1, in the network environment (100), the electronic device (101) may communicate with the electronic device (102) via a first network (198) (e.g., a short-range wireless communication network), or may communicate with at least one of the electronic device (104) or the server (108) via a second network (199) (e.g., a long-range wireless communication network). In one embodiment, the electronic device (101) may communicate with the electronic device (104) via the server (108). According to one embodiment, the electronic device (101) may include a processor (120), a memory (130), an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a connection terminal (178), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197). In some embodiments, the electronic device (101) may omit at least one of these components (e.g., the connection terminal (178)), or may have one or more other components added. In some embodiments, some of these components (e.g., the sensor module (176), the camera module (180), or the antenna module (197)) may be integrated into one component (e.g., the display module (160)).

[0039] The processor (120) may, for example, execute software (e.g., a program (140)) to control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) and perform various data processing or operations. According to one embodiment, as at least a part of the data processing or operations, the processor (120) may store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in a volatile memory (132), process the commands or data stored in the volatile memory (132), and store result data in a non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or an auxiliary processor (123) (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor) that can operate independently or together with the main processor (121). For example, when the electronic device (101) includes the main processor (121) and the auxiliary processor (123), the auxiliary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a given function. The auxiliary processor (123) may be implemented separately from the main processor (121) or as a part thereof.

[0040] The auxiliary processor (123) may control at least a portion of functions or states associated with at least one component (e.g., a display module (160), a sensor module (176), or a communication module (190)) of the electronic device (101), for example, on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (123) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (180) or a communication module (190)). In one embodiment, the auxiliary processor (123) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, in the electronic device (101) itself where the artificial intelligence model is executed, or can be performed through a separate server (e.g., server (108)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include a plurality of artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.

[0041] The memory (130) can store various data used by at least one component (e.g., processor (120) or sensor module (176)) of the electronic device (101). The data can include, for example, software (e.g., program (140)) and input data or output data for commands related thereto. The memory (130) can include volatile memory (132) or non-volatile memory (134).

[0042] The program (140) may be stored as software in the memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0043] The input module (150) can receive commands or data to be used in a component of the electronic device (101) (e.g., a processor (120)) from an external source (e.g., a user) of the electronic device (101). The input module (150) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).

[0044] The audio output module (155) can output audio signals to the outside of the electronic device (101). The audio output module (155) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. In one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.

[0045] The display module (160) can visually provide information to an external party (e.g., a user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. According to one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.

[0046] The audio module (170) can convert sound into an electrical signal, or vice versa, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150), output sound through the sound output module (155), or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (101).

[0047] The sensor module (176) can detect the operating status (e.g., power or temperature) of the electronic device (101) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (176) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0048] The interface (177) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (101) with an external electronic device (e.g., the electronic device (102)). In one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0049] The connection terminal (178) may include a connector through which the electronic device (101) may be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0050] The haptic module (179) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. According to one embodiment, the haptic module (179) can include, for example, a motor, a piezoelectric element, or an electrical stimulation device.

[0051] The camera module (180) can capture still images and videos. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0052] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented as, for example, at least a part of a power management integrated circuit (PMIC).

[0053] A battery (189) may power at least one component of the electronic device (101). In one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0054] The communication module (190) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may operate independently from the processor (120) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Among these communication modules, the corresponding communication module can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules can be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can verify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) by using subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (196).

[0055] The wireless communication module (192) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in a high-frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), an external electronic device (e.g., the electronic device (104)), or a network system (e.g., the second network (199)). According to one embodiment, the wireless communication module (192) can support a peak data rate (e.g., 20 Gbps or more) for eMBB realization, a loss coverage (e.g., 164 dB or less) for mMTC realization, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for URLLC realization.

[0056] The antenna module (197) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). In one embodiment, the antenna module (197) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). In one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (198) or the second network (199), may be selected from the plurality of antennas, for example, by the communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device via the at least one selected antenna. In some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (197).

[0057] According to various embodiments, the antenna module (197) may form a mmWave antenna module. In one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high-frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high-frequency band.

[0058] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).

[0059] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) via a server (108) connected to a second network (199). Each of the external electronic devices (102 or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations executed in the electronic device (101) may be executed in one or more of the external electronic devices (102, 104, or 108). For example, when the electronic device (101) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (101) may, instead of or in addition to executing the function or service itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (101) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server utilizing machine learning and / or a neural network. According to one embodiment, the external electronic device (104) or the server (108) may be included in the second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.

[0060] FIG. 2 is a drawing for explaining an electronic device, a server, and a security device according to one embodiment.

[0061] Services provided within an electronic device (200) (e.g., the electronic device (101) of FIG. 1) may utilize the user's important information (e.g., certificates, login information, OTP (one-time password)) (i.e., credentials) to provide services to the user. Credentials may be information used to verify the user's identity and grant authorization. Credentials may be the initial key generated for each service or user to use the service. Therefore, protecting credentials may be a key to security.

[0062] Cryptographic algorithms can be used to securely protect credentials. Credentials may be encrypted using a cryptographic algorithm and stored in a secure location. Cryptographic algorithms can encrypt credentials using a cryptographic key. The cryptographic key can be generated based on a secure random number generator with sufficient entropy. Alternatively, the cryptographic key can be generated based on the credentials.

[0063] To use services simultaneously on multiple electronic devices, or to use the same services on a new electronic device due to loss or replacement of the electronic device, you may need to restore credentials from the previous device to the new one. Once the credentials stored on the previous device are restored, the user can use the services in the same way. For example, the user can log in to the new device using the same login information used on the previous device.

[0064] This disclosure describes a method for registering credentials with a server and restoring credentials.

[0065] Referring to FIG. 2, an electronic device (200), a server (210) (e.g., server (108) of FIG. 1), and a security device (220) are illustrated.

[0066] The roles and functions of each component described below in this disclosure may vary during the credential registration and restoration processes. The credential registration process may involve storing credentials and authentication information for the SRP protocol on a server (210). The credential restoration process may involve identifying whether a user is a legitimate user through the SRP protocol and restoring credentials stored on the server (210) to an electronic device (200).

[0067] According to one embodiment, the electronic device (200) may be a device that provides a service to a user. The electronic device (200) may include a framework (201), a client (203), a trust authority (TA) (205), and storage (207) (e.g., non-volatile memory (134) of FIG. 1 ). However, this is merely an example, and embodiments of the present disclosure are not limited thereto. The framework (201), the client (203), and the TA (205) may be implemented in software.

[0068] In one embodiment, the framework (201) may be an entity that receives unlocking information from a user during the credential registration and restoration process. The framework (201) may perform pre-computation for executing the SRP protocol. As described later in FIG. 4, the framework (201) may generate a key based on the unlocking information.

[0069] In one embodiment, the client (203) can establish a secure communication channel by performing the PAKE protocol with the server (210) during the credential restoration process. For convenience of explanation, the present disclosure assumes that the client (203) and the server (210) communicate via the SRP protocol among various PAKE protocols. However, this is merely an example, and the embodiments of the present disclosure are not limited thereto.

[0070] According to one embodiment, the TA (205) may perform encryption or decryption on keys used in the electronic device (200) during the registration or restoration process of credentials. The TA (205) may be an entity that stores, restores, and manages credentials.

[0071] According to one embodiment, the storage (207) can store various keys for encryption or decryption.

[0072] In one embodiment, the server (210) can communicate with the electronic device (200) and the security device (220). For example, the server (210) can communicate with the electronic device (200) and the security device (220) via a short-range wireless communication network (e.g., the first network (198) of FIG. 1) and / or a long-range wireless communication network (e.g., the second network (199) of FIG. 1). The server (210) can perform the PAKE protocol with the client (203). The server (210) can include storage (211). The storage (211) can store encrypted credentials.

[0073] According to one embodiment, the security device (220) may perform re-encryption on information received from the server (210) during the credential registration and restoration processes. The security device (220) may include storage (221). The storage (221) may store keys for re-encryption.

[0074] Below, we will explain in detail the credential registration process.

[0075] Figure 3 is a flowchart illustrating a process for registering credentials according to one embodiment.

[0076] In the following embodiments, the operations may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations may be changed, and at least two operations may be performed in parallel. Operations (310) to (350) may be performed by at least one component (e.g., the processor (120) of FIG. 1) of an electronic device (e.g., the electronic device (101) of FIG. 1 and the electronic device (200) of FIG. 2). For example, instructions stored in a memory (e.g., the memory (130) of FIG. 1) may be executed by at least one processor, and the instructions may cause the electronic device to perform the following operations (310) to (350).

[0077] According to one embodiment, in operation (310), the electronic device may receive unlock information of the electronic device from the user.

[0078] According to one embodiment, a client of an electronic device (e.g., client (203) of FIG. 2) may receive unlock information to register authentication information based on the SRP protocol with a server (e.g., server (210) of FIG. 2). The unlock information may be received from a user through a framework of the electronic device (e.g., framework (201) of FIG. 2). The unlock information may be information for unlocking the electronic device. The unlock information may include a pin, a pattern, a password, and facial recognition information.

[0079] According to one embodiment, in operation (320), the electronic device may generate authentication information and a wrapping key based on the unlocking information.

[0080] According to one embodiment, the framework of an electronic device can generate authentication information and a wrapping key for the SRP protocol based on unlocking information. The authentication information for the SRP protocol can be used for authentication between the electronic device and a server during a subsequent credential restoration process. The authentication information can include a verifier and a salt. The verifier can be generated based on an intermediate value described below. The salt can be random data for enhanced security. For example, the salt can include a 256-bit random number.

[0081] According to one embodiment, in operation (330), the electronic device may generate a protection key and a recovery key for encrypting and decrypting credentials and authentication information stored in the electronic device.

[0082] According to one embodiment, the client of the electronic device may transmit the generated authentication information and wrapping key to the TA (e.g., TA (205) of FIG. 2). The TA of the electronic device may randomly generate a recovery key and a protection key. The TA of the electronic device may generate the recovery key and the protection key using various key generation algorithms. The protection key may be used to encrypt the credential. The recovery key may be used to encrypt the protection key. The electronic device may store the recovery key and the protection key in storage (e.g., non-volatile memory (134) of FIG. 1 and storage (207) of FIG. 2). The storage may store the recovery key, the protection key, the public key of the TA, and the private key of the TA. For convenience of description in the present disclosure, the public key of the TA and the private key of the TA may be referred to as the public key of the electronic device and the private key of the electronic device, respectively.

[0083] According to one embodiment, in operation (340), the electronic device may encrypt authentication information, credentials, and protection keys based on keys of the electronic device, including a protection key and a recovery key.

[0084] According to one embodiment, the TA of the electronic device can encrypt authentication information, credentials, and protection keys based on keys of the electronic device, including a protection key and a recovery key. A method for encrypting authentication information, credentials, and protection keys is described below with reference to FIG. 4. The TA of the electronic device can generate encrypted authentication information, encrypted credentials, and encrypted protection keys based on keys of the electronic device, including a protection key and a recovery key.

[0085] According to one embodiment, in operation (350), the electronic device may transmit encrypted credentials, encrypted authentication information, and encrypted protection keys to a server (e.g., server (108) of FIG. 1 and server (210) of FIG. 2) that performs the SRP protocol with the electronic device.

[0086] In one embodiment, the server may perform the SRP protocol with the electronic device when restoring credentials to the electronic device. The server may communicate with a security device (e.g., security device (220) of FIG. 2). The server may store encrypted credentials and transmit encrypted authentication information and an encrypted protection key to the security device.

[0087] In one embodiment, the security device can re-encrypt encrypted authentication information and an encrypted protection key and transmit the re-encrypted authentication information and the re-encrypted protection key to the server. The operation of the security device that has obtained the encrypted authentication information and the encrypted protection key is described below in FIG. 4.

[0088] FIG. 4 is a flowchart illustrating operations between an electronic device, a server, and a security device for registering credentials according to one embodiment.

[0089] Referring to FIG. 4, a framework (401) (e.g., the framework (201) of FIG. 2), a client (403) (e.g., the client (203) of FIG. 2), and a TA (405) (e.g., the TA (205) of FIG. 2) of an electronic device (e.g., the electronic device (101) of FIG. 1 and the electronic device (200) of FIG. 2) are illustrated. Referring to FIG. 4, a server (410) (e.g., the server (108) of FIG. 1 and the server (210) of FIG. 2) and a security device (420) (e.g., the security device (220) of FIG. 2) are illustrated.

[0090] According to one embodiment, when instructions stored in a memory (e.g., memory (130) of FIG. 1) are executed by at least one processor (e.g., processor (120) of FIG. 1), the instructions may cause the framework (401), client (403) and TA (405) of the electronic device to perform the following operations.

[0091] According to one embodiment, in operation (431), the framework (401) provides authentication information and a wrapping key ( ) can be created.

[0092] According to one embodiment, the framework (401) receives unlock information ( ) based on the authentication information and wrapping key ( ) can be generated. The authentication information is provided by the verifier ( ) and salt ( ) may be included. The authentication information may be used for authentication between the server and the electronic device in the SRP protocol. The framework (401) may include the user's ID ( ), unlock information ( ) and salt ( ) based on the median ( ) can be generated. The framework (401) uses a hash algorithm to generate an intermediate value ( ) can be created.

[0093] In one embodiment, the user's ID ( ) may include unique information corresponding to the user, such as ID information for logging into the server (410) and the serial number of the electronic device. According to one embodiment, unlock information ( ) may include pin, pattern, password and facial recognition information as information for unlocking the electronic device. According to one embodiment, the salt ( ) can be random data to increase security. For example, salt( ) can contain a 256-bit random number.

[0094] According to one embodiment, the framework (401) comprises an intermediate value ( ) based on the verifier ( ) can be generated. For example, the framework (401) can generate an intermediate value ( ) through modular operations based on the verifier ( ) can be created.

[0095] According to one embodiment, the framework (401) comprises an intermediate value ( ) hash value( ) and unlock information ( ) based on the wrapping key ( ) can be generated. The framework (401) can generate an intermediate value ( ) hash value( ) and unlock information ( ) by applying an algorithm (e.g., PBKDF (password-based key derivation function) algorithm) to generate a cryptographic key to wrap the key ( ) can be created.

[0096] According to one embodiment, in operation (433), the framework (401) provides authentication information and a wrapping key ( ) can be transmitted to the client (403) (e.g., client (203) of FIG. 2).

[0097] According to one embodiment, in operation (435), the client (403) sends authentication information and a wrapping key ( ) can be transmitted to TA (405) (e.g., TA (205) of FIG. 2).

[0098] According to one embodiment, in operation (437), TA (405) credentials ( ) and a protection key (hereinafter referred to as a protection key) for encrypting and decrypting authentication information. ) and recovery key( ) and generate a protection key ( ) and recovery key( ) based on the keys of electronic devices including authentication information, credentials ( ) and protection key( ) can be encrypted.

[0099] According to one embodiment, in FIG. 4 is a symmetric key encryption (e.g., AES (advanced encryption standard), LEA (lightweight encryption algorithm)) that encrypts data ( ) as a cryptographic key ( ) can be shown to be encrypted. In Fig. 4 is a public key encryption (e.g. RSA (Rivest, Shamir, Adleman) - OAEP (optimal asymmetric encryption padding)) that encrypts data ( ) as a cryptographic key ( ) can be used to indicate that it is encrypted. Similarly, is used to encrypt data (e.g., AES, LE) using symmetric key encryption. ) as a cryptographic key ( ) can be expressed as decryption. is a public key encryption (e.g. RSA-OAEP) that encrypts data ( ) as a cryptographic key ( ) can be expressed as decryption.

[0100] According to one embodiment, TA (405) is a protection key ( ) and recovery key( ) can be randomly generated. TA (405) generates authentication information and credentials ( ) and protection key( ) can be encrypted. The keys of electronic devices are protected keys ( ), recovery key( ), wrapping key( ), the public key of the electronic device ( ) (i.e., the public key of TA (405)) and the private key of the electronic device ( ) (i.e., the private key of TA (405)).

[0101] According to one embodiment, TA (405) is a credential ( ) to protect the key( ) and encrypted credentials ( ) can be created.

[0102] According to one embodiment, TA (405) encrypts authentication information with a recovery key to encrypt the encrypted authentication information ( ) can be generated. TA (405) is a verifier of authentication information ( ) and salt ( ) is encrypted with the recovery key to obtain encrypted authentication information ( ) can be created.

[0103] According to one embodiment, TA (405) comprises a multi-encrypted protection key ( ) can be generated. TA (405) is a protection key ( ) to the recovery key( ) and encrypts it with the primary encrypted protection key ( ) to wrap the key( ) and re-encrypted with a multi-encrypted protection key ( ) can be created.

[0104] According to one embodiment, TA (405) communicates with a server (410) using a public key of a security device (420). ) based on a multi-encrypted protection key ( ) and recovery key( ) to encrypt the encrypted protection key ( ) can be created.

[0105] According to one embodiment, in operation (439), TA (405) encrypts credentials ( ), encrypted protection key( ) and encrypted authentication information ( ) can be transmitted to the client (403).

[0106] According to one embodiment, in operation (441), the client (403) transmits encrypted credentials ( ), encrypted protection key( ) and encrypted authentication information ( ) can be transmitted.

[0107] Since the encrypted information in this disclosure is transmitted to the server (410), the encrypted information can be robust against attacks.

[0108] According to one embodiment, in operation (443), the server (410) transmits encrypted credentials ( ) and save the encrypted protection key ( ) and encrypted authentication information ( ) can be transmitted to the security device (420). The server (410) can transmit an encrypted protection key ( ) and encrypted authentication information ( ) can be requested to the security device (420) for re-encryption.

[0109] According to one embodiment, in operation (445), the security device (420) encrypts the protection key ( ) and encrypted authentication information ( ) can be re-encrypted.

[0110] According to one embodiment, the security device (420) comprises an encrypted protection key ( ) of the private key of the security device (420) ) can be decrypted. The security device (420) uses an encrypted protection key ( ) to decrypt the recovery key ( ) and multi-encrypted protection keys ( ) can be obtained.

[0111] According to one embodiment, the security device (420) encrypts authentication information ( ) to the recovery key( ) can be decrypted. The security device (420) encrypts the authentication information ( ) to decrypt the verifier ( ) and salt ( ) can be obtained.

[0112] According to one embodiment, the storage of the security device (420) (e.g., the storage (221) of FIG. 2) contains a symmetric key ( ), the public key of the security device ( ) and the private key of the security device ( ) can be stored. The security device (420) stores salt ( ) as the symmetric key of the security device ( ) and re-encrypt it with the encrypted salt ( ) can be obtained. The security device (420) is a symmetric key of the security device ( ) with recovery key( ) and multi-encrypted protection keys ( ) to re-encrypt the first re-encrypted protection key ( ) can be obtained.

[0113] According to one embodiment, in operation (447), the security device (420) encrypts a first re-encrypted protection key ( ), encrypted salt( ) and verifier( ) can be transmitted to the server (410).

[0114] According to one embodiment, the server (410) receives a first re-encrypted protection key ( ), encrypted salt( ) and verifier( ) can be stored. Ultimately, the storage of the server (410) stores encrypted credentials ( ), the first re-encrypted protection key ( ), encrypted salt( ) and verifier( ) can be saved.

[0115] In one embodiment, the unlock information of the electronic device is encrypted and stored on the server (410). ) may be changed. Unlock information of electronic devices ( ) is changed, the credentials stored on the server by the above-described operation (431) to operation (447) ), the first re-encrypted protection key ( ), encrypted salt( ) and verifier( ) may be updated. However, the protection key used to encrypt the credentials ( ) and recovery key( ) is not regenerated, and the protection key ( stored in the storage of the electronic device) ) and recovery key( ) can be used to update.

[0116] During the credential registration process described above, the keys used to encrypt the credentials and encrypted credentials may be encrypted using keys unknown to the server (410). Therefore, even if information stored on the server (410) is leaked, decryption may be difficult. Therefore, the level of security can be high.

[0117] Below, we will explain the credential recovery process.

[0118] Figure 5 is a flowchart illustrating a process for restoring credentials according to one embodiment.

[0119] In the following embodiments, the operations may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations may be changed, and at least two operations may be performed in parallel. Operations (510) to (550) may be performed by at least one component (e.g., the processor (120) of FIG. 1) of an electronic device (e.g., the electronic device (101) of FIG. 1 and the electronic device (200) of FIG. 2). For example, instructions stored in a memory (e.g., the memory (130) of FIG. 1) may be executed by at least one processor, and the instructions may cause the electronic device to perform the following operations (510) to (550).

[0120] According to one embodiment, in operation (510), when the electronic device obtains unlock information used when storing credentials from the user, the electronic device may perform an SRP protocol with a server communicating with the electronic device to share a session key with the server.

[0121] In one embodiment, the electronic device may request the user to provide the unlocking information used when registering the credential with the server. If the unlocking information obtained from the user is identical to the unlocking information used when registering the credential with the server (e.g., server (108) of FIG. 1 and server (210) of FIG. 2), the electronic device may perform a credential recovery process.

[0122] In one embodiment, an electronic device can perform an SRP protocol with a server using unlock information obtained from the user. The electronic device can authenticate itself as a legitimate user by performing the SRP protocol with the server. Once the user is authenticated as a legitimate user, the electronic device and the server can share a session key.

[0123] According to one embodiment, in operation (520), the electronic device may receive encrypted information from the server based on the session key, including encrypted credentials stored on the server and a second re-encrypted protection key.

[0124] In one embodiment, the server may request re-encryption of the first re-encrypted protection key from a security device communicating with the server (e.g., security device (220) of FIG. 2 ). The security device may re-encrypt the first re-encrypted protection key to generate a second re-encrypted protection key. A method by which the security device generates the second re-encrypted protection key is described below in FIG. 6.

[0125] In one embodiment, the server may receive a second re-encrypted protection key from the security device. The server may encrypt the second re-encrypted protection key and encrypted credentials stored on the server with a session key to generate encrypted information. The server may transmit the encrypted information to the electronic device.

[0126] In one embodiment, at operation (530), the electronic device may decrypt information with the session key to obtain encrypted credentials and a second re-encrypted protection key.

[0127] According to one embodiment, in operation (540), the electronic device may generate a wrapping key based on the unlock information.

[0128] According to one embodiment, the electronic device can generate a wrapping key based on the unlocking information obtained in operation (510).

[0129] According to one embodiment, in operation (550), the electronic device can obtain the credential by decrypting the second re-encrypted protection key and the encrypted credential based on the wrapping key and the keys stored in the electronic device.

[0130] In other words, credentials can be restored. With restored credentials, users can use the same services they used on their previous electronic device on their current device. In other words, users can use services without having to re-register credentials. For example, users can log in to their new device using the same login information they used on their previous device.

[0131] FIG. 6 is a flowchart illustrating operations between an electronic device, a server, and a security device for restoring credentials according to one embodiment.

[0132] Referring to FIG. 6, a framework (601) (e.g., the framework (201) of FIG. 2 and the framework (401) of FIG. 4) of an electronic device (e.g., the electronic device (101) of FIG. 1 and the electronic device (200) of FIG. 2), a client (603) (e.g., the client (203) of FIG. 2 and the client (403) of FIG. 4) and a TA (605) (e.g., the TA (205) of FIG. 2 and the TA (405) of FIG. 4) are illustrated. Referring to FIG. 6, a server (610) (e.g., the server (108) of FIG. 1, the server (210) of FIG. 2 and the server (410) of FIG. 4) and a security device (620) (e.g., the security device (220) of FIG. 2 and the security device (420) of FIG. 4) are illustrated. The server (610) encrypts the credentials while the credentials are registered. ), the first re-encrypted protection key ( ), encrypted salt( ) and verifier( ) may be in a state of being saved.

[0133] According to one embodiment, when instructions stored in a memory (e.g., memory (130) of FIG. 1) are executed by at least one processor (e.g., processor (120) of FIG. 1), the instructions may cause the framework (601), client (603), and TA (605) of the electronic device to perform the following operations.

[0134] According to one embodiment, in operation (631), the client (603) and the server (610) exchange a session key ( ) can be shared.

[0135] According to one embodiment, the electronic device receives unlock information ( ) can be obtained. Unlock information obtained from the user ( ) is the unlock information used when storing credentials. ) may be. The electronic device may have unlock information ( ) can be used to perform the SRP protocol with the server. The electronic device can be authenticated as a legitimate user by performing the SRP protocol with the server. Once the legitimate user is authenticated, the electronic device and the server exchange a session key ( ) can be shared.

[0136] According to one embodiment, in operation (633), the server (610) encrypts a first re-encrypted protection key ( ) can be transmitted to the security device (620).

[0137] According to one embodiment, the server (610) transmits a first re-encrypted protection key ( ) can be transmitted to the security device (620) to request re-encryption.

[0138] According to one embodiment, in FIG. 6 is a symmetric key encryption (e.g. AES, LEA) that encrypts data ( ) as a cryptographic key ( ) can be shown to be encrypted. In Fig. 4 is a public key encryption (e.g. RSA-OAEP) that encrypts data ( ) as a cryptographic key ( ) can be used to indicate that it is encrypted. Similarly, is a symmetric key encryption (e.g. AES, LEA) that encrypts data ( ) as a cryptographic key ( ) can be used to represent decryption. is a public key encryption (e.g. RSA-OAEP) that encrypts data ( ) as a cryptographic key ( ) can be expressed as decryption.

[0139] According to one embodiment, in operation (635), the security device (620) encrypts a first re-encrypted protection key ( ) to re-encrypt the second re-encrypted protection key ( ) can be created.

[0140] According to one embodiment, the security device (620) comprises a first re-encrypted protection key ( ) of the security device (620) as a symmetric key ( ) can be decrypted. The security device (620) uses the first re-encrypted protection key ( ) to decrypt the multi-encrypted protection key ( ) and recovery key( ) can be obtained.

[0141] According to one embodiment, the security device (620) comprises a multi-encrypted protection key ( ) and recovery key( ) to the public key of the electronic device ( ) (i.e., the public key of TA (605)) and the second re-encrypted protection key ( ) can be created.

[0142] According to one embodiment, in operation (637), the security device (620) encrypts a second re-encrypted protection key ( ) can be transmitted to the server (610).

[0143] According to one embodiment, in operation (639), the server (610) transmits encrypted credentials ( ) and a second re-encrypted protection key ( ) to the session key ( ) can be encrypted.

[0144] According to one embodiment, the server (610) transmits encrypted credentials ( ) and a second re-encrypted protection key ( ) to encrypt the encrypted information ( ) can be generated. The server (610) can generate encrypted information ( ) can be transmitted to an electronic device.

[0145] According to one embodiment, in operation (641), the server (610) encrypts information ( ) can be transmitted to the client (603).

[0146] According to one embodiment, in operation (643), the client (603) transmits encrypted information ( ) and decrypt the wrapping key ( ) can be created.

[0147] According to one embodiment, the client (603) transmits encrypted information ( ) to the session key ( ) can be decrypted. The client (603) can decrypt the encrypted information ( ) to decrypt the encrypted credentials ( ) and a second re-encrypted protection key ( ) can be obtained.

[0148] According to one embodiment, the client (603) obtains unlock information ( ) based on the wrapping key ( ) can be generated. Unlock information ( ) is the session key ( ) may be information entered by the user when sharing. Wrapping key ( ) is described above in Fig. 4, so the description thereof is omitted.

[0149] According to one embodiment, in operation (645), the client (603) wraps a key ( ), encrypted credentials ( ) and a second re-encrypted protection key ( ) can be transmitted to TA (605).

[0150] According to one embodiment, in operation (647), the TA (605) can recover the credentials.

[0151] According to one embodiment, TA (605) is a private key of an electronic device ( ) using the second re-encrypted protection key ( ) can be decrypted. TA (605) decrypts the second re-encrypted protection key to obtain the multi-encrypted protection key ( ) and recovery key( ) can be obtained.

[0152] According to one embodiment, TA (605) comprises a multi-encrypted protection key ( ) to wrap the key( ) and decrypt the primary encrypted protection key ( ) can be obtained. TA (605) is a primary encrypted protection key ( ) to the recovery key( ) can be decrypted. TA (605) is the primary encrypted protection key ( ) to decrypt the protection key ( ) can be obtained.

[0153] According to one embodiment, TA (605) contains encrypted credentials ( ) to protect the key( ) to decrypt the credentials ( ) can be obtained.

[0154] In other words, credentials can be restored. With restored credentials, users can access the same services they used on their previous electronic device on their current device. In other words, users can use services without having to re-register credentials.

[0155] Additionally, the first re-encrypted protection key that was being stored on the server is encrypted with the public key of the electronic device in the security device ( ) (i.e., the public key of TA (605)) and then encrypted again with the session key ( ) is encrypted and double-protected, so security can be strengthened.

[0156] Additionally, end-to-end encryption can be applied during the process of registering and restoring credentials, thereby increasing security by not exposing any information to the server.

[0157] Below, we will explain the screens of electronic devices during the credential registration and restoration process.

[0158] FIGS. 7 and 8 illustrate screens of an electronic device for explaining registration and restoration of credentials according to one embodiment.

[0159] Referring to FIG. 7, screens (710, 720) of an electronic device (e.g., the electronic device (101) of FIG. 1 and the electronic device (200) of FIG. 2) are illustrated.

[0160] According to one embodiment, the screen (710) may be an execution screen of an application, program, or software (e.g., program (140) and application (146) of FIG. 1 ) that provides a credential registration service. Applications, programs, and software that provide a credential registration service may provide management services, such as credential registration and recovery. For example, applications, programs, and software that provide a credential registration service may provide management services for authentication information for website login.

[0161] In one embodiment, on screen (710), the electronic device may obtain a registration command to register credentials with a server (e.g., server (108) of FIG. 1 , server (210) of FIG. 2 , server (410) of FIG. 4 , and server (610) of FIG. 6 ). For example, the electronic device may obtain a selection command for “YES” on screen (710). Upon obtaining the registration command, the electronic device may display screen (720).

[0162] According to one embodiment, screen (720) may be a screen for receiving unlock information for an electronic device. The unlock information for the electronic device may vary depending on the current unlock method of the electronic device. For example, the unlock information for the electronic device may be determined as at least one of a PIN, a pattern, a password, and facial recognition information.

[0163] According to one embodiment, the electronic device can receive unlock information via the screen (720). If the unlock information received via the screen (720) matches the unlock information of the electronic device, the electronic device can register the credentials with the server. In other words, the electronic device can register the credentials with the server based on the operations described above in FIGS. 4 and 5 .

[0164] Referring to FIG. 8, screens (810, 820) of an electronic device (e.g., electronic device (101) of FIG. 1 and electronic device (200) of FIG. 2) are illustrated. The electronic device displaying the screens (810, 820) may be a device for recovering credentials.

[0165] According to one embodiment, the screen (810) may be an execution screen of an application, program, or software (e.g., program (140), application (146) of FIG. 1) that provides a credential recovery service.

[0166] According to one embodiment, the screen (810) may display a list of credentials registered with a server (e.g., server (108) of FIG. 1 , server (210) of FIG. 2 , server (410) of FIG. 4 , and server (610) of FIG. 6 ). The list may display registration information for the user's electronic devices registered with the server. In other words, if one or more credentials for one or more electronic devices are registered to the user's account, the list may include registration information for one or more electronic devices.

[0167] For example, if user A has two electronic devices (i.e., a first electronic device and a second electronic device) and credentials for each electronic device are registered on the server, the screen (810) may display registration information for each electronic device. The registration information may include the name of the electronic device and the date on which the credentials for the electronic device were updated (or the date on which they were registered).

[0168] According to one embodiment, when a plurality of registration information items are displayed in a list, the electronic device can obtain a selection command for any one of the plurality of registration information items from the user.

[0169] According to one embodiment, the screen (820) may be a screen for receiving unlock information of the electronic device.

[0170] In one embodiment, the electronic device can receive unlock information via the screen (820). In other words, the electronic device can obtain a command to recover credentials. Upon receiving unlock information via the screen (820), the electronic device can perform the SRP protocol with the server. If the electronic device is identified as a legitimate user via the SRP protocol, the electronic device can recover credentials using the method described above in FIGS. 5 and 6 .

[0171] FIG. 9 is a diagram illustrating restoration of credentials in one of a plurality of electronic devices according to one embodiment.

[0172] In one embodiment, credential recovery may be possible even across heterogeneous devices. For example, credential recovery may be possible across heterogeneous devices such as smartphones, smartwatches, tablet PCs (personal computers), and head-mounted displays (HMDs). For convenience of explanation, security devices (e.g., security device (220) of FIG. 2 , security device (420) of FIG. 4 , and security device (620) of FIG. 6 ) are omitted in FIG. 9 .

[0173] The first electronic device (900) of FIG. 9 (e.g., the electronic device (101) of FIG. 1 and the electronic device (200) of FIG. 2), the second electronic device (920), and the third electronic device (930) are devices registered to the account of user A, and are assumed to be heterogeneous devices. In other words, the first electronic device (900), the second electronic device (920), and the third electronic device (930) may be devices registered to the account of user A through an authentication procedure as belonging to user A.

[0174] According to one embodiment, the user ID and unlock information for each electronic device may be different. For example, the ID of the first electronic device (900) of user A may be and the unlock information is It can be. For example, the ID of the second electronic device (920) of user A is and the unlock information is It can be. For example, the ID of the third electronic device (930) of user A is and the unlock information is It could be.

[0175] According to one embodiment, the first electronic device (900) may be a device that registers credentials with a server (910) (e.g., server (108) of FIG. 1, server (210) of FIG. 2, server (410) of FIG. 4, and server (610) of FIG. 6).

[0176] The method of registering the credentials of the first electronic device (900) with the server (910) is described above with reference to FIGS. 3 and 4, and is thus omitted. The credentials of the first electronic device (900) may be encrypted and stored in the server (910) as encrypted credentials (940).

[0177] According to one embodiment, the server (910) may store credentials along with a user ID and / or device ID for the electronic device.

[0178] In one embodiment, the second electronic device (920) may be a different type of electronic device than the first electronic device (900). For example, if the first electronic device (900) is a smartphone, the second electronic device (920) may be a tablet PC.

[0179] According to one embodiment, the second electronic device (920) receives unlock information from the user ( ) can be received. The second electronic device (920) can receive a user ID ( ) and / or unlock information ( ) can perform the SRP protocol with the server (910). If the second electronic device (920) is identified as an electronic device owned by user A through the SRP protocol, the second electronic device (920) can obtain an encrypted credential (940). That is, if the second electronic device (920) is identified as an electronic device owned by user A, the server (910) can transmit the encrypted credential (940) to the second electronic device (920). The second electronic device (920) can decrypt the encrypted credential (940) to obtain the credential. In other words, the second electronic device (920) can recover the credential of the first electronic device (900).

[0180] The method by which the second electronic device (920) obtains the encrypted credentials and recovers the credentials is omitted as described above with reference to FIGS. 5 and 6.

[0181] According to one embodiment, the second electronic device (920) obtains the credentials and then unlocks the ) can be used to encrypt credentials and store the encrypted credentials on the server (910). Unlock information ( ) may be information used to determine whether the second electronic device (920) is the user's electronic device. In other words, the unlock information may be information used in the SRP protocol.

[0182] According to one embodiment, the second electronic device (920) unlocks the acquired credentials with unlock information ( ) can be used to generate an encrypted credential (970) and register it with the server (910). The method of registering the credential with the server (910) is described above with reference to FIGS. 3 and 4, and is thus omitted.

[0183] Similarly, the third electronic device (930) may be a different type of electronic device from the first electronic device (900). For example, if the first electronic device (900) is a smartphone, the second electronic device (920) may be an HMD. The method by which the third electronic device (930) recovers credentials and stores encrypted credentials (980) in the server (910) has been described above with respect to the second electronic device (920), and thus will be omitted.

[0184] FIGS. 10 and 11 are flowcharts illustrating registration and recovery of a quantum-resistant credential according to one embodiment.

[0185] Referring to FIG. 10, a framework (1001) (e.g., the framework (201) of FIG. 2, the framework (401) of FIG. 4, and the framework (601) of FIG. 6) of an electronic device (e.g., the electronic device (101) of FIG. 1, the electronic device (200) of FIG. 2, and the first electronic device (900) of FIG. 9)), a client (1003) (e.g., the client (203) of FIG. 2, the client (403) of FIG. 4, and the client (603) of FIG. 6)), and a TA (1005) (e.g., the TA (205) of FIG. 2, the TA (405) of FIG. 4, and the TA (605) of FIG. 6)) are illustrated. Referring to FIG. 10, a server (1010) (e.g., server (108) of FIG. 1, server (210) of FIG. 2, server (410) of FIG. 4, server (610) of FIG. 6, and server (910) of FIG. 9) and a security device (1020) (e.g., security device (220) of FIG. 2, security device (420) of FIG. 4, and security device (620) of FIG. 6) are illustrated.

[0186] According to one embodiment, when instructions stored in a memory (e.g., memory (130) of FIG. 1) are executed by at least one processor (e.g., processor (120) of FIG. 1), the instructions may cause the framework (401), client (403) and TA (405) of the electronic device to perform the following operations.

[0187] Since operations (1031) to (1035) can be applied in the same manner as operations (431) to (435) of FIG. 4, their descriptions are omitted.

[0188] According to one embodiment, in operation (1037), TA (1005) provides credentials ( ) and a protection key ( to encrypt and decrypt authentication information) ) and recovery key( ) and generate a protection key ( ) and recovery key( ) based on the keys of electronic devices including authentication information, credentials ( ) and protection key( ) can be encrypted.

[0189] According to one embodiment, in FIG. 10 is a symmetric key encryption (e.g. AES, LEA) that encrypts data ( ) as a cryptographic key ( ) can be shown as encrypted in Fig. 10. is a public key encryption (e.g. RSA-OAEP) that encrypts data ( ) as a cryptographic key ( ) can be used to indicate that it is encrypted. Similarly, is used to encrypt data (e.g., AES, LE) using symmetric key encryption. ) as a cryptographic key ( ) can be used to represent decryption. is a public key encryption (e.g. RSA-OAEP) that encrypts data ( ) as a cryptographic key ( ) can be expressed as decryption. And, is a public key (e.g., module-lattice-based key-encapsulation mechanism (ML-KEM)) that uses quantum computing-secure key encapsulation. ) may mean an algorithm that outputs a shared key corresponding to the corresponding key. Is In the reverse process and public key from private key (privkey) ) may be an algorithm that outputs a shared key corresponding to the corresponding key.

[0190] According to one embodiment, TA (1005) is a protection key ( ) and recovery key( ) can be generated. TA (1005) can generate a shared key ( ) and password ( ) can be generated. TA (1005) can generate the public key of the server (1010). ) based on a shared key with the server through key encapsulation ( ) and password ( ) can be created.

[0191] TA(1005) is encrypted authentication information( ), encrypted credentials ( ) and encrypted protection key( ) is described above in Fig. 4, so the description thereof is omitted.

[0192] According to one embodiment, TA (1005) is a shared key ( ) and password ( ) can additionally encrypt the encrypted protection key based on the shared key ( TA (1005) ) using an encrypted protection key ( ) by encrypting can generate a password ( )silver It can be said that. At this time, the protection key ( ) is the final encrypted form Is and may include an encrypted protection key ( ) can be called the first encrypted protection key. can be referred to as a second encrypted protection key with an additional encrypted protection key.

[0193] According to one embodiment, in operation (1039), TA (1005) , encrypted authentication information ( ) and encrypted credentials ( ) can be transmitted to the client (1003).

[0194] According to one embodiment, in operation (1041), the client (1003) , encrypted authentication information ( ) and encrypted credentials ( ) can be transmitted to the server (1010).

[0195] According to one embodiment, in operation (1043), the server (1010) Included in (i.e., the password ( )) and the server's private key( )cast Enter the shared key between the server (1010) and TA (1005) into the function. ) can be obtained.

[0196] According to one embodiment, in operation (1043), the server (1010) Included in Share the key( ) and decrypt it with the encrypted protection key ( ) can be obtained.

[0197] According to one embodiment, in operation (1043), the server (1010) transmits encrypted credentials ( ) can be saved.

[0198] According to one embodiment, in operation (1045), the server (1010) encrypts the protection key ( ) and encrypted authentication information ( ) can be transmitted to the security device (1020). The server (1010) can transmit an encrypted protection key ( ) and encrypted authentication information ( ) can be requested to the security device (420) for re-encryption.

[0199] According to one embodiment, in operation (1047), the security device (1020) encrypts the protection key ( ) and encrypted authentication information ( ) can be re-encrypted.

[0200] As for the action (1047), the explanation described above in Fig. 4 will be omitted.

[0201] According to one embodiment, in operation (1049), the security device (1020) encrypts a first re-encrypted protection key ( ), encrypted salt( ) and verifier( ) can be transmitted to the server (1010). The server (1010) receives the first re-encrypted protection key ( ), encrypted salt( ) and verifier( ) can be stored. Ultimately, the storage of the server (1010) (e.g., the storage (211) of FIG. 2) stores encrypted credentials ( ), the first re-encrypted protection key ( ), encrypted salt( ) and verifier( ) can be saved.

[0202] Below, we will explain the process of restoring credentials.

[0203] Referring to FIG. 11, a framework (1101) (e.g., the framework (201) of FIG. 2, the framework (401) of FIG. 4, the framework (601) of FIG. 6, and the framework (1001) of FIG. 10) of an electronic device (e.g., the electronic device (101) of FIG. 1, the electronic device (200) of FIG. 2, and the first electronic device (900) of FIG. 9)), a client (1103) (e.g., the client (203) of FIG. 2, the client (403) of FIG. 4, the client (603) of FIG. 6, and the client (1003) of FIG. 10)) and a TA (1105) (e.g., the TA (205) of FIG. 2, the TA (405) of FIG. 4, the TA (605) of FIG. 6, and the TA (1005) of FIG. 10)) are illustrated. Referring to FIG. 11, a server (1110) (e.g., server (108) of FIG. 1, server (210) of FIG. 2, server (410) of FIG. 4, server (610) of FIG. 6, server (910) of FIG. 9, and server (1010) of FIG. 10) and a security device (1120) (e.g., security device (220) of FIG. 2, security device (420) of FIG. 4, security device (620) of FIG. 6, and security device (1020) of FIG. 10) are illustrated.

[0204] Since the actions (1131) to (1137) can be applied in the same manner as the actions (631) to (637) of Fig. 6, their descriptions are omitted.

[0205] According to one embodiment, in FIG. 11 is a symmetric key encryption (e.g. AES, LEA) that encrypts data ( ) as a cryptographic key ( ) can be shown as encrypted in Fig. 11. is a public key encryption (e.g. RSA-OAEP) that encrypts data ( ) as a cryptographic key ( ) can be used to indicate that it is encrypted. Similarly, is used to encrypt data (e.g., AES, LE) using symmetric key encryption. ) as a cryptographic key ( ) can be used to represent decryption. is a public key encryption (e.g. RSA-OAEP) that encrypts data ( ) as a cryptographic key ( ) can be expressed as decryption. And, is a public key (e.g., module-lattice-based key-encapsulation mechanism (ML-KEM)) that uses quantum computing-secure key encapsulation. ) may mean an algorithm that outputs a shared key corresponding to the corresponding key. Is In the reverse process and public key (from private key (privkey)) ) may be an algorithm that outputs a shared key corresponding to the corresponding key.

[0206] According to one embodiment, in operation (1139), the server (1110) transmits encrypted credentials ( ) and a second re-encrypted protection key ( ) shares the session key with the client (1103). ) can be encrypted.

[0207] According to one embodiment, the server (1110) transmits encrypted credentials ( ) and a second re-encrypted protection key ( ) to encrypt the encrypted information ( ) can be created.

[0208] According to one embodiment, in operation (1139), the server (1110) receives the public key of the client (1103) ) using a shared key with the client (1103). ) and password ( ) can be created.

[0209] According to one embodiment, the server (1110) shares a shared key ( ) encrypted information ( ) by encrypting can generate a password ( )silver It can be said that. At this time, the second information is in an encrypted form in the server (1110). Is and may contain encrypted information ( ) can be said to be the first encrypted information. The first encrypted information can be referred to as second encrypted information, which is additionally encrypted information.

[0210] According to one embodiment, in operation (1141), the server (1110) can be transmitted to the client (1103).

[0211] According to one embodiment, in operation (1143), the client (1103) sends a cryptographic ) and the private key of the client (1103) ( )cast Enter the shared key between the client (1103) and the server (1110) into the function. ) can be obtained.

[0212] According to one embodiment, in operation (1143), the client (1103) uses a shared key ( ) using can be decrypted. The client (1103) Decrypt the encrypted information ( ) can be obtained.

[0213] According to one embodiment, in operation (1143), the client (1103) transmits encrypted information ( ) and decrypt the wrapping key ( ) can be created.

[0214] Encrypted information( ) and wrapping keys ( ) is described above in Fig. 6, so the description thereof will be omitted.

[0215] Since the actions (1145) and (1147) can be applied in the same manner as the actions (645) and (647) of Fig. 6, their descriptions are omitted.

[0216] Through actions (1131) to (1147), the electronic device can acquire credentials. In other words, the credentials can be restored. With the credentials restored, the user can use the same services they used on their previous electronic device on their current electronic device.

[0217] Figures 10 and 11 illustrate how information can be safely protected against attacks using quantum computers by utilizing encapsulation. In other words, information can be quantum-resistant.

[0218] According to one embodiment, an electronic device (e.g., the electronic device 101 of FIG. 1, the electronic device 200 of FIG. 2, and the first electronic device 900 of FIG. 9) may include a memory (e.g., the memory 130 of FIG. 1) that stores instructions. The electronic device may include at least one processor (e.g., the processor 120 of FIG. 1) that executes the instructions. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to receive (e.g., obtain) unlock information of the electronic device from a user and generate authentication information and a wrapping key based on the unlock information. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to generate a protection key and a recovery key for encrypting and decrypting credentials and authentication information stored in the electronic device. When at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to encrypt authentication information, credentials, and protection keys based on keys of the electronic device, including a protection key and a recovery key. When at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to transmit encrypted credentials (e.g., encrypted credentials (940) of FIG. 9), encrypted authentication information, and encrypted protection keys to a server that performs the SRP protocol with the electronic device (e.g., server (108) of FIG. 1, server (210) of FIG. 2, server (410) of FIG. 4, server (610) of FIG. 6, server (910) of FIG. 9, server (1010) of FIG. 10, and server (1110) of FIG. 11).

[0219] In one embodiment, when at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to generate an encrypted credential by encrypting a credential with a protection key. When at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to generate an encrypted protection key by encrypting a multi-encrypted protection key and a recovery key based on a public key of a security device (e.g., security device (220) of FIG. 2 , security device (420) of FIG. 4 , security device (620) of FIG. 6 , security device (1020) of FIG. 10 , and security device (1120) of FIG. 11 ) communicating with a server. When at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to generate encrypted authentication information by encrypting authentication information with a recovery key.

[0220] According to one embodiment, when at least one processor individually or collectively executes instructions, the instructions may cause the electronic device to generate a multi-encrypted protection key by encrypting a protection key with a recovery key and encrypting the protection key encrypted with the recovery key with a wrapping key.

[0221] In one embodiment, the server may store the encrypted credentials and transmit them to a secure device that communicates with the server to re-encrypt the encrypted protection key and encrypted authentication information.

[0222] According to one embodiment, the security device can decrypt a protection key encrypted with the private key of the security device to obtain a multi-encrypted protection key and a recovery key, and re-encrypt the recovery key and the multi-encrypted protection key with a symmetric key of the security device to generate a first re-encrypted protection key. The security device can transmit the first re-encrypted protection key to a server. The server can store the first re-encrypted protection key.

[0223] According to one embodiment, if another electronic device of the user is identified as the user's device based on the SRP protocol, encrypted credentials can be transmitted to the other electronic device.

[0224] In one embodiment, the server may store encrypted credentials based on unlock information of the other electronic device that is used to determine whether the other electronic device is the user's device.

[0225] In one embodiment, when at least one processor individually or collectively executes instructions, the instructions may cause the electronic device, upon receiving a command to recover credentials, to perform the SRP protocol with a server to share a session key. The command to recover credentials may include unlock information.

[0226] According to one embodiment, when at least one processor individually or collectively executes instructions, the instructions may cause the electronic device to receive encrypted information from a server. When at least one processor individually or collectively executes instructions, the instructions may cause the electronic device to decrypt the encrypted information based on a session key. When at least one processor individually or collectively executes instructions, the instructions may cause the electronic device to recover credentials based on the decrypted information based on the session key.

[0227] According to one embodiment, an electronic device may include a memory that stores instructions. The electronic device may include at least one processor that executes the instructions. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to obtain unlock information used when storing credentials from a user, and to perform an SRP protocol with a server communicating with the electronic device to share a session key with the server. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to receive encrypted credentials stored on the server and a second re-encrypted protection key, the encrypted information based on the session key, from the server. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to decrypt information with the session key to obtain the encrypted credentials and the second re-encrypted protection key. When at least one processor individually or collectively executes instructions, the instructions may cause the electronic device to generate a wrapping key based on the unlocking information, and to decrypt a second re-encrypted protection key and an encrypted credential based on the wrapping key and keys stored in the electronic device to obtain the credential.

[0228] In one embodiment, the server may transmit the first re-encrypted protection key stored on the server to the security device. The security device may decrypt the first re-encrypted protection key with the security device's symmetric key to obtain a recovery key and a multi-encrypted protection key. The security device may encrypt the recovery key and the multi-encrypted protection key with the electronic device's public key to generate a second re-encrypted protection key.

[0229] According to one embodiment, when at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to decrypt the second re-encrypted protection key with the private key of the electronic device to obtain a multi-encrypted protection key and a recovery key. When at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to decrypt the multi-encrypted protection key with the wrapping key and the recovery key to obtain the protection key. When at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to decrypt an encrypted credential with the protection key to obtain the credential.

[0230] According to one embodiment, an electronic device may include a memory that stores instructions. The electronic device may include at least one processor that executes the instructions. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to receive unlock information of the electronic device from a user and generate authentication information and a wrapping key based on the unlock information. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to generate a protection key and a recovery key for encrypting and decrypting credentials and authentication information stored in the electronic device. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to generate a shared key and a passphrase with a server through key encapsulation based on a public key of the server. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to encrypt authentication information, credentials, and the protection key based on the protection key and the recovery key to generate encrypted authentication information, encrypted credentials, and a first encrypted protection key. When at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to further encrypt the first encrypted protection key based on the shared key and the ciphertext to generate a second encrypted protection key. When at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to transmit the encrypted authentication information, the encrypted credentials, and the second encrypted protection key to a server.

[0231] According to one embodiment, an electronic device may include a memory that stores instructions. The electronic device may include at least one processor that executes the instructions. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to obtain unlock information used when storing credentials from a user, and to perform an SRP protocol with a server communicating with the electronic device to share a session key with the server. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to receive second encrypted information in which first encrypted information is further encrypted based on a shared key and a passphrase generated based on a public key of a client of the electronic device. The first encrypted information may be encrypted credentials and a second re-encrypted protection key encrypted based on the session key. When the at least one processor individually or collectively executes the instructions, the instructions may cause the electronic device to obtain first encrypted information based on the second encrypted information. When at least one processor individually or collectively executes the instructions, the instructions can cause the electronic device to decrypt the first encrypted information with the session key to obtain an encrypted credential and a second re-encrypted protection key. When at least one processor individually or collectively executes the instructions, the instructions can cause the electronic device to generate a wrapping key based on the unlock information, and decrypt the second re-encrypted protection key and the encrypted credential based on the wrapping key and keys stored in the electronic device to obtain the credential.

[0232] According to one embodiment, an operating method of an electronic device may include receiving unlock information of the electronic device from a user. The operating method may include generating authentication information and a wrapping key based on the unlock information. The operating method may include generating a protection key and a recovery key for encrypting and decrypting credentials and authentication information stored in the electronic device. The operating method may include encrypting authentication information, credentials, and the protection key based on keys of the electronic device including the protection key and the recovery key. The operating method may include transmitting the encrypted credentials, the encrypted authentication information, and the encrypted protection key to the electronic device and a server that performs an SRP protocol.

[0233] In one embodiment, the operation of encrypting authentication information, credentials, and protection keys may include an operation of encrypting the credentials with a protection key to generate an encrypted credential. The operation of encrypting authentication information, credentials, and protection keys may include an operation of encrypting a multi-encrypted protection key and a recovery key based on a public key of a security device communicating with the server to generate an encrypted protection key. The operation of encrypting authentication information, credentials, and protection keys may include an operation of encrypting authentication information with a recovery key to generate encrypted authentication information.

[0234] In one embodiment, the act of encrypting authentication information, credentials, and protection keys may include encrypting the protection key with a recovery key. The act of encrypting authentication information, credentials, and protection keys may include encrypting the protection key, which is encrypted with the recovery key, with a wrapping key to generate a multi-encrypted protection key.

[0235] In one embodiment, the server may store the encrypted credentials and transmit them to a secure device that communicates with the server to re-encrypt the encrypted protection key and encrypted authentication information.

[0236] According to one embodiment, the security device can decrypt a protection key encrypted with the private key of the security device to obtain a multi-encrypted protection key and a recovery key, re-encrypt the recovery key and the multi-encrypted protection key with a symmetric key of the security device to generate a first re-encrypted protection key, and transmit the first re-encrypted protection key to a server. The server can store the first re-encrypted protection key.

[0237] In one embodiment, the server may transmit encrypted credentials to another electronic device if the other electronic device is identified as the user's device based on the SRP protocol.

[0238] In one embodiment, the server may store encrypted credentials based on unlock information of the other electronic device that is used to determine whether the other electronic device is the user's device.

[0239] According to one embodiment, a computer-readable recording medium stores one or more computer programs, and the one or more computer programs may include instructions that, when individually and / or collectively executed by at least one processor, cause an electronic device to receive unlock information of the electronic device from a user, generate authentication information and a wrapping key based on the unlock information, generate a protection key and a recovery key for encrypting and decrypting credentials and authentication information stored in the electronic device, encrypt the authentication information, the credentials and the protection key based on keys of the electronic device including the protection key and the recovery key, and transmit the encrypted credentials, the encrypted authentication information and the encrypted protection key to the electronic device and a server performing an SRP protocol.

[0240] Electronic devices according to the various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to the embodiments of this document are not limited to the aforementioned devices.

[0241] The various embodiments of this document and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.

[0242] The term "module" used in various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0243] Various embodiments of the present document may be implemented as software (e.g., a program (140)) including one or more instructions stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101)). For example, a processor (e.g., a processor (120)) of the machine (e.g., an electronic device (101)) may call at least one instruction among the one or more instructions stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.

[0244] According to one embodiment, the method according to various embodiments disclosed in this document may be provided as a computer program product. The computer program product may be traded between sellers and buyers as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or may be provided through an application store (e.g., Play Store). TM ) or directly between two user devices (e.g., smart phones), online distribution (e.g., downloading or uploading). In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily created in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.

[0245] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and arranged in other components. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

[0246] The embodiments of the present invention disclosed in this specification and drawings are merely specific examples presented to easily explain the technical contents according to the embodiments of the present invention and to help understand the embodiments of the present invention, and are not intended to limit the scope of the embodiments of the present invention. Therefore, the scope of the various embodiments of the present invention should be interpreted as including all changes or modified forms derived based on the technical ideas of the various embodiments of the present invention in addition to the embodiments disclosed herein.

Claims

1. In electronic devices (101; 200; 900), Memory (130) for storing commands; and At least one processor (120) executing the above instructions Including, When the at least one processor (120) individually or collectively executes the instructions, the instructions cause the electronic device (101; 200; 900) to: Obtaining unlock information of an electronic device (101; 200; 900) from a user, generating authentication information and a wrapping key based on the unlock information, generating a credential stored in the electronic device (101; 200; 900) and a protection key and a recovery key for encrypting and decrypting the authentication information, and encrypting the authentication information, the credential and the protection key based on keys of the electronic device (101; 200; 900) including the protection key and the recovery key, and transmitting the encrypted credential (940), the encrypted authentication information and the encrypted protection key to a server (108; 210; 410; 610; 910; 1010) that performs an SRP protocol with the electronic device (101; 200; 900). To be transmitted to 1110), Electronic devices (101; 200; 900).

2. In paragraph 1, When the at least one processor (120) individually or collectively executes the instructions, the instructions cause the electronic device (101; 200; 900) to: Encrypting the above credentials with the protection key to generate the encrypted credentials (940), encrypting the multi-encrypted protection key and the recovery key based on the public key of a security device (220; 420; 620; 1020; 1120) communicating with the server (108; 210; 410; 610; 910; 1010; 1110) to generate the encrypted protection key, and encrypting the authentication information with the recovery key to generate the encrypted authentication information. Electronic devices (101; 200; 900).

3. In either of paragraphs 1 and 2, When the at least one processor (120) individually or collectively executes the instructions, the instructions cause the electronic device (101; 200; 900) to: Encrypting the protection key with the recovery key, and encrypting the protection key encrypted with the recovery key with the wrapping key to generate the multi-encrypted protection key. Electronic devices (101; 200; 900).

4. In any one of paragraphs 1 to 3, The above servers (108; 210; 410; 610; 910; 1010; 1110) Store the encrypted credentials (940) and transmit them to a security device (220; 420; 620; 1020; 1120) that communicates with the server (108; 210; 410; 610; 910; 1010; 1110) to re-encrypt the encrypted protection key and the encrypted authentication information. Electronic devices (101; 200; 900).

5. In any one of paragraphs 1 to 4, The above security devices (220; 420; 620; 1020; 1120) are Decrypting the encrypted protection key with the private key of the security device (220; 420; 620; 1020; 1120) to obtain a multi-encrypted protection key and the recovery key, re-encrypting the recovery key and the multi-encrypted protection key with the symmetric key of the security device (220; 420; 620; 1020; 1120) to generate a first re-encrypted protection key, and transmitting the first re-encrypted protection key to the server (108; 210; 410; 610; 910; 1010; 1110), The above servers (108; 210; 410; 610; 910; 1010; 1110) storing the first re-encrypted protection key, Electronic devices (101; 200; 900).

6. In any one of paragraphs 1 to 5, The above servers (108; 210; 410; 610; 910; 1010; 1110) Based on the SRP protocol, the other electronic device (101; 200; 900) of the user is identified as the device of the user, and the encrypted credential (940) is transmitted to the other electronic device (101; 200; 900). Electronic devices (101; 200; 900).

7. In any one of paragraphs 1 to 6, The above servers (108; 210; 410; 610; 910; 1010; 1110) Storing encrypted credentials (940) based on unlock information of said other electronic device (101; 200; 900) used to determine whether said other electronic device (101; 200; 900) is said to be said user's device, Electronic devices (101; 200; 900).

8. In any one of paragraphs 1 to 7, When the at least one processor (120) individually or collectively executes the instructions, the instructions cause the electronic device (101; 200; 900) to: Based on obtaining a command to recover the above credentials, perform the SRP protocol with the server to share the session key, The command to recover the above credentials is: including the above unlocking information, Electronic devices (101; 200; 900).

9. In any one of paragraphs 1 to 8, When the at least one processor (120) individually or collectively executes the instructions, the instructions cause the electronic device (101; 200; 900) to: Obtaining encrypted information from the server, decrypting the encrypted information based on the session key, and recovering the credential based on the information decrypted based on the session key. Electronic devices (101; 200; 900).

10. In the operating method of an electronic device (101; 200; 900), An action of obtaining unlock information of an electronic device (101; 200; 900) from a user; An action of generating authentication information and a wrapping key based on the above unlocking information; An operation of generating a protection key and a recovery key for encrypting and decrypting the credentials and authentication information stored in the electronic device (101; 200; 900); An operation of encrypting the authentication information, the credential and the protection key based on keys of the electronic device (101; 200; 900) including the protection key and the recovery key; and An operation of transmitting the encrypted credentials (940), the encrypted authentication information, and the encrypted protection key to the electronic device (101; 200; 900) and a server (108; 210; 410; 610; 910; 1010; 1110) performing the SRP protocol. including, How it works.

11. In paragraph 10, The operation of encrypting the above authentication information, the above credentials and the above protection key is, An operation of generating the encrypted credential (940) by encrypting the credential with the protection key; An operation of generating the encrypted protection key by encrypting the multi-encrypted protection key and the recovery key based on the public key of the security device (220; 420; 620; 1020; 1120) communicating with the server (108; 210; 410; 610; 910; 1010; 1110); and An action of generating encrypted authentication information by encrypting the authentication information with the recovery key. including, How it works.

12. In any one of paragraphs 10 and 11, The operation of encrypting the above authentication information, the above credentials and the above protection key is, An operation of encrypting the above protection key with the above recovery key; and An operation of generating the multi-encrypted protection key by encrypting the protection key encrypted with the recovery key with the wrapping key. including, How it works.

13. In any one of paragraphs 10 to 12, An operation of storing the encrypted credential (940) using the above server (108; 210; 410; 610; 910; 1010; 1110); and An operation of transmitting the encrypted protection key and the encrypted authentication information to a security device (220; 420; 620; 1020; 1120) communicating with the server (108; 210; 410; 610; 910; 1010; 1110) to re-encrypt the encrypted protection key and the encrypted authentication information. including more, How it works.

14. In any one of paragraphs 10 to 13, An operation of decrypting the encrypted protection key using the private key of the security device (220; 420; 620; 1020; 1120) to obtain a multi-encrypted protection key and the recovery key; An operation of re-encrypting the recovery key and the multi-encrypted protection key using a symmetric key of the security device (220; 420; 620; 1020; 1120) to generate a first re-encrypted protection key; and An operation of transmitting the first re-encrypted protection key to the server (108; 210; 410; 610; 910; 1010; 1110) using the security device (220; 420; 620; 1020; 1120). Including more, The above servers (108; 210; 410; 610; 910; 1010; 1110) storing the first re-encrypted protection key, How it works.

15. In any one of paragraphs 10 to 14, An operation of transmitting the encrypted credential (940) to the other electronic device (101; 200; 900) using the server (108; 210; 410; 610; 910; 1010; 1110) based on the identification of the other electronic device (101; 200; 900) of the user as the device of the user based on the SRP protocol. including, How it works.

Citation Information

Patent Citations

  • Energy-Control System through Energy Use Pattern Analysis

    KR102837281B1

  • Unlocking a storage device

    US20170206373A1

  • Secure remote password retrieval

    US20170279788A1

  • Methods for secure credential provisioning

    US20200021441A1

  • Electronic subscriber identity module transfer credential wrapping

    US20220399993A1