Method and apparatus for cryptogram matching process
By assigning access credential IDs and using temporary public keys for encryption, the cryptogram matching process is optimized, addressing inefficiencies in existing systems and improving user experience.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- SAMSUNG ELECTRONICS CO LTD
- Filing Date
- 2024-10-28
- Publication Date
- 2026-05-07
AI Technical Summary
The existing methods for cryptogram matching in digital key systems are inefficient, leading to increased time required for matching cryptograms, especially when readers store hundreds of cryptograms, which affects user experience and convenience.
A method and apparatus for cryptogram matching that involves assigning an access credential ID during the matching process, using temporary public keys for encryption and decryption of cryptograms, and verifying cryptogram matching values to reduce matching time.
The proposed solution efficiently performs cryptogram matching by reducing the time required for authentication, thereby enhancing user convenience and system performance.
Smart Images

Figure KR2024016505_07052026_PF_FP_ABST
Abstract
Description
Method and apparatus for cryptogram matching process
[0001] The present disclosure relates to a method and apparatus for a cryptogram matching process.
[0002] With the proliferation of personalized electronic devices such as terminals and tablet PCs, technologies are being developed to perform security and authentication using digitized virtual keys, or digital keys. As one approach to such digital key technology, a technology is being developed that integrates digital keys into electronic devices, such as terminals, using wireless communication technology.
[0003] By inserting a digital key into an electronic device, the user of the electronic device can open and close the door using the digital key, which replaces the physical key. Additionally, as the functionality of the digital key is further expanded, the user of the electronic device can use the digital key for access to and control of the device.
[0004] While the use of digital keys can bring significant improvements in user convenience and industrial impact, readers receiving digital key data can store hundreds of cryptograms in a single reader. When matching the cryptograms of the reader with those of the terminal, the time required to match each cryptogram may increase.
[0005] The present disclosure provides a method and apparatus for a cryptogram matching process.
[0006] A method of a user device according to one embodiment of the present disclosure for achieving the above objective may include: receiving a matching ID from a credential issuer server for identifying a cryptogram matching value (kpersistent); mapping the matching ID to a reader group sub ID assigned to the user device; receiving an authentication command (AUTH0 command) from a reader that includes a temporary public key (Reader.ePK) generated for each transaction and a reader ID; encrypting the matching ID using the temporary public key (Reader.ePK); and transmitting an authentication response (AUTH0 response) to the reader that includes the encrypted matching ID and a cryptogram associated with the reader group sub ID.
[0007] A method of a reader according to one embodiment of the present disclosure for achieving the above objective may include: receiving a second matching ID from a credential issuer server for identifying a cryptogram matching value (kpersistent); transmitting an authentication command (AUTH0 command) to a user device that includes a temporary public key (Reader.ePK) generated for each transaction and a reader ID; receiving an authentication response (AUTH0 response) from the user device that includes a first matching ID and a cryptogram encrypted using the temporary public key (Reader.ePK); if the first matching ID and the second matching ID match, verifying the cryptogram matching value (kpersistent) corresponding to the second matching ID; and verifying the cryptogram using the cryptogram matching value (kpersistent).
[0008] A user device according to one embodiment of the present disclosure for achieving the above objective comprises a transmitting and receiving unit and a control unit, wherein the control unit is configured to receive a matching ID for identifying a cryptogram matching value (kpersistent) from a credential issuer server, map the matching ID to a reader group sub ID assigned to the user device, receive an authentication command (AUTH0 command) from a reader comprising a temporary public key (Reader.ePK) generated for each transaction and a reader ID, encrypt the matching ID using the temporary public key (Reader.ePK), and transmit an authentication response (AUTH0 response) comprising the encrypted matching ID and a cryptogram associated with the reader group sub ID to the reader.
[0009] A reader according to one embodiment of the present disclosure for achieving the above objective may include a transmitting and receiving unit and a control unit, wherein the control unit may be configured to include the steps of receiving a second matching ID for identifying a cryptogram matching value (kpersistent) from a credential issuer server, transmitting an authentication command (AUTH0 command) including a temporary public key (Reader.ePK) and a reader ID generated for each transaction to a user device, receiving an authentication response (AUTH0 response) from the user device including a first matching ID and a cryptogram encrypted using the temporary public key (Reader.ePK), and if the first matching ID and the second matching ID match, verifying the cryptogram matching value (kpersistent) corresponding to the second matching ID, and verifying the cryptogram using the cryptogram matching value (kpersistent).
[0010] A method and apparatus according to one embodiment of the present disclosure may include a method for a cryptogram matching process. The present disclosure may provide a method and apparatus for efficiently performing a cryptogram matching process. A method and apparatus for a cryptogram matching process may reduce the matching time by assigning an access credential ID during the matching process of a reader for decoding a cryptogram.
[0011] FIG. 1 is a block diagram illustrating an embodiment of a device for transmitting a cryptogram.
[0012] FIG. 2 is a flowchart illustrating one example of a procedure for transmitting a cryptogram.
[0013] FIG. 3a is a flowchart illustrating an example of an access credential identifier.
[0014] FIG. 3b is a flowchart illustrating an example of a connection credential ID.
[0015] FIG. 4 is a block diagram illustrating an example of a connection credential ID.
[0016] FIG. 5 is a block diagram illustrating an embodiment for transmitting a connection credential ID.
[0017] FIG. 6 is a flowchart illustrating an embodiment for transmitting a connection credential ID.
[0018] FIG. 7a is a flowchart illustrating an example of a grouping identifier.
[0019] FIG. 7b is a flowchart illustrating an example of a grouping ID.
[0020] FIG. 8 is a flowchart illustrating embodiments for transmitting a grouping ID.
[0021] FIG. 9 is a block diagram illustrating an embodiment for transmitting a grouping ID.
[0022] FIG. 10 is a flowchart illustrating an embodiment for transmitting a grouping ID.
[0023] FIG. 11 is a block diagram illustrating a user device according to one embodiment of the present disclosure.
[0024] FIG. 12 is a block diagram illustrating a reader according to one embodiment of the present disclosure.
[0025] Hereinafter, an embodiment of the present disclosure will be described in detail with reference to the attached drawings.
[0026] In describing the present disclosure, technical details that are well known in the technical field to which the present disclosure belongs and are not directly related to the present disclosure are omitted. This is intended to convey the essence of the present disclosure more clearly without obscuring it by omitting unnecessary explanations. Furthermore, the terms described below are defined considering their functions within the present disclosure, and these definitions may vary depending on the intentions or practices of the user or operator. Therefore, their definitions should be based on the content throughout this specification.
[0027] For the same reason, some components in the attached drawings have been exaggerated, omitted, or schematically depicted. Additionally, the dimensions of each component do not entirely reflect their actual dimensions. Identical or corresponding components in each drawing have been assigned the same reference numbers.
[0028] Hereinafter, a base station (BS) is an entity that performs resource allocation for terminals and may be at least one of gNode B, eNode B, Node B (or xNode B (where x is an alphabet including g and e)), a radio access unit, a base station controller, a satellite, an airborn, or a node on a network. A terminal (user equipment: UE) may include a Mobile Station (MS), a Vehicular, a satellite, an airborn, a cellular phone, a smartphone, a computer, or a multimedia system capable of performing communication functions. In this disclosure, a downlink (DL) refers to a radio transmission path for a signal transmitted by a base station to a terminal, and an uplink (UL) refers to a radio transmission path for a signal transmitted by a terminal to a base station. Additionally, a sidelink (SL) may exist, which refers to a radio transmission path for a signal transmitted by a terminal to another terminal.
[0029] In addition, while LTE, LTE-A, or 5G systems may be described below as examples, embodiments of the present disclosure may also be applied to other communication systems having similar technical backgrounds or channel types. For example, 5G-Advance or NR-Advance or 6th generation mobile communication technology (6G) developed after 5G mobile communication technology (or new radio, NR) may be included, and the 5G below may be a concept that includes existing LTE, LTE-A, and other similar services. Furthermore, the present disclosure may be applied to other communication systems with some modifications made at the discretion of a person with skilled technical knowledge, without significantly departing from the scope of the present disclosure.
[0030] At this point, it will be understood that each block of the process flow diagrams and combinations of the flow diagrams can be executed by computer program instructions. Since these computer program instructions can be loaded into the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, the instructions executed through the processor of the computer or other programmable data processing equipment create means to perform the functions described in the flow diagram block(s). Since these computer program instructions can also be stored in computer-available or computer-readable memory that can be directed toward the computer or other programmable data processing equipment to implement the function in a specific way, the instructions stored in computer-available or computer-readable memory can also produce a manufactured item containing instruction means to perform the function described in the flow diagram block(s). Since computer program instructions can be loaded onto a computer or other programmable data processing equipment, instructions that perform a series of operation steps on the computer or other programmable data processing equipment to create a process executed by the computer can also provide steps for executing the functions described in the flowchart block(s).
[0031] Additionally, each block may represent a module, segment, or part of code containing one or more executable instructions for executing a specific logical function(s). It should also be noted that in some alternative execution examples, the functions mentioned in the blocks may occur out of order. For example, two blocks described in succession may actually be executed substantially simultaneously, or the blocks may sometimes be executed in reverse order according to their corresponding functions.
[0032] In this embodiment, the term "part" refers to a software or hardware component such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit), and the "part" performs certain roles. However, the meaning of "part" is not limited to software or hardware. The "part" may be configured to reside in an addressable storage medium or configured to run one or more processors. Thus, as an example, the "part" includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and "parts" may be combined into a smaller number of components and "parts" or further separated into additional components and "parts." In addition, the components and 'parts' may be implemented to utilize one or more CPUs within the device or secure multimedia card. Also, in the embodiments, 'parts' may include one or more processors.
[0033] 3GPP, which is responsible for cellular mobile communication standards, has named a new core network structure "5G Core" (5GC) and is proceeding with standardization to facilitate the evolution from 4G LTE systems to 5G systems. Compared to the Evolved Packet Core (EPC), the network core for 4G, 5GC supports the following differentiated features.
[0034] Network Slice functionality is introduced in 5GC. As a requirement for 5G, 5GC must support various types of terminals and services; e.g., enhanced Mobile Broadband (eMBB), Ultra Reliable Low Latency Communications (URLC), and Massive Machine Type Communications (mMTC). Each of these terminals / services has different requirements for the core network. For instance, eMBB services may require high data rates, while URLLC services may require high stability and low latency. Network Slice technology has been proposed to satisfy these diverse service requirements.
[0035] Network slicing refers to a method of creating multiple logical networks (e.g., network slices) by virtualizing a single physical network. An active network slice can be referred to as a network slice instance, and each network slice instance (NSI) can have different characteristics. Mobile operators can satisfy various service requirements for terminals / services by configuring network functions (NFs) suited to the characteristics of each NSI. For example, mobile operators can efficiently support various 5G services (e.g., eMBB, URLLC, or mMTC) by allocating an NSI that matches the characteristics of the service required by each terminal.
[0036] 5GC facilitates support for network virtualization paradigms by separating mobility management functions and session management functions. In 4G LTE, all terminals can receive services from the network through signaling exchanges with a single core entity called the Mobility Management Entity (MME), which is responsible for registration, authentication, mobility management, and session management functions. In 5G, as the number of terminals (e.g., MTC terminals) increases explosively and the mobility and traffic / session characteristics that must be supported vary depending on the terminal type, having a single entity (e.g., MME) support all functions inevitably leads to reduced scalability, which requires adding entities for specific functions. Therefore, to improve scalability in terms of the functional / implementation complexity and signaling load of the core entity responsible for the control plane, various functions are being developed based on a structure that separates mobility management functions and session management functions.
[0037] FIG. 1 is a block diagram illustrating an embodiment of a device for transmitting a cryptogram.
[0038] Referring to FIG. 1, a user device (110) and a reader (120) can transmit and receive a reader ID (reader identifier). The reader (120) can transmit the reader ID to the user device (110). The reader ID may include at least one of a reader group ID (identifier) and a reader group sub ID. The user device (110) can receive the reader ID transmitted by the reader (120).
[0039] The user device (110) can be implemented as various types of devices capable of performing a cryptogram matching process with a reader (120). For example, the user device (110) can be implemented as user equipment (UE), a portable communication device, a computer device, a portable multimedia device, a portable medical device, a wearable device, a home appliance, a wireless earphone, or earbuds. The user device (110) according to the embodiments of the present disclosure is not limited to the aforementioned devices.
[0040] The reader (120) can be implemented as various types of devices capable of performing a cryptogram matching process with the user device (110). For example, the reader (120) can be implemented as at least one gate.
[0041] The user device (110) may include at least one of a reader group ID (identifier) (111), a reader pubkey (113), or a reader group sub ID (115). The reader group sub ID (115) may include at least one of a kpersistent or a cryptogram payload. A kpersistent may refer to a value containing parameters obtained through transmission and reception between the user device (110) (e.g., UE) and the reader (120). A kpersistent may include a hash value for the parameter values obtained through transmission and reception between the user device (110) (e.g., UE) and the reader (120). A kpersistent may be referred to as a cryptogram matching value.
[0042] A reader group ID (111) may include at least one reader public key (113) or at least one reader group sub ID (115). The reader group ID may include at least one of the reader public key (113) or the reader group sub ID (115). The reader group ID (111) may include information for identifying a reader group that includes at least one reader. The reader group sub ID (115) may include at least one of kpersistent or a cryptogram payload. In this disclosure, kpersistent may refer to a matching value verified at each of the user device (110) and the reader (120) for a cryptogram matching process performed between the user device (110) and the reader (120). In this disclosure, kpersistent may also be referred to as a cryptogram matching value. kpersistent may include a value output through a function of data transmitted and received between the user device (110) and the reader (120). kpersistent may include a value calculated through a hash function of data transmitted and received between the user device (110) and the reader (120).
[0043] For example, if the first kpersistent (or first cryptogram matching value) provided by the user device (110) matches the second kpersistent (or second cryptogram matching value) provided by the reader (120), the reader (120) can verify (or decrypt) the cryptogram (or cryptogram payload) corresponding to the second kpersistent (or second cryptogram matching value). For example, if the first kpersistent (or first cryptogram matching value) provided by the user device (110) does not match the second kpersistent (or second cryptogram matching value) provided by the reader (120), the reader (120) may not verify (or decrypt) the cryptogram (or cryptogram payload) corresponding to the second kpersistent (or second cryptogram matching value).
[0044] The reader public key (113) may mean a key that can be used publicly by at least one reader included in the reader group ID. Different reader group IDs may include the same or different reader public keys. In other words, the first reader group ID may include the first reader public key. The second reader group ID may include the second reader public key. The reader public key (113) may include a reader group sub ID (115). The reader group sub ID (115) may include at least one of a kpersistent or a cryptogram payload. For example, the kpersistent may include kpersistent A. kpersistent A may mean a kpersistent for the user device (110).
[0045] The reader group sub-ID (115) may include at least one reader ID for the reader group ID (111). The reader group sub-ID (115) may include at least one of a kpersistent or a cryptogram payload.
[0046] A reader (120) may include a reader ID (121) or at least one kpersistent (125). The reader ID (121) may include information for identifying the reader (120). The reader ID may include at least one kpersistent (125). For example, at least one kpersistent (125) may include kpersistent Z, kpersistent C, kpersistent M, kpersistent A, etc.
[0047] The user device (110) can perform a standard transaction. The user device (110) can generate kpersistent through a standard transaction line. In other words, the user device (110) can generate kpersistent based on data transmitted and received by the user device (110) and the reader (120) in the AUTH1 step. The user device (110) and the reader (120) can perform the AUTH1 step. The AUTH1 step may include the step of the user device (110) and the reader (120) transmitting and receiving an AUTH1 command or an AUTH1 response.
[0048] The user device (110) can generate a cryptogramSK (cryptogram Secure Key). In other words, the user device (110) can generate a cryptogramSK based on the data transmitted and received between the user device (110) and the reader (120) during the AUTH1 stage. The cryptogramSK may refer to a Cryptogram Private Key. The cryptogramSK may be referred to as a private key.
[0049] cryptogramSKEnc may imply that a specific value has been encrypted with cryptogramSK. cryptogramSKEnc may imply that kpersistent has been encrypted with cryptogramSK.
[0050] The cryptogram payload may include schedule or time information that the reader utilizes when granting access to the user device. The cryptogram payload may include credential_signed_timestamp (20 bytes) or revocation_signed_timestamp (20 bytes). credential_signed_timestamp may represent the validity time of the credentials for the cryptogram. revocation_signed_timestamp may represent the release time for the cryptogram.
[0051] The user device (110) can generate a Cryptogram. The user device (110) can generate a CryptogramSK using kpersistent. The user device (110) can encrypt a Cryptogram payload using the CryptogramSK. The encrypted Cryptogram payload may be referred to as a Cryptogram. In other words, the user device (110) can generate a Cryptogram using the CryptogramSK. The Cryptogram payload may include schedule information, etc.
[0052] A user device (110) can transmit a cryptogram to a reader (120). The cryptogram transmitted by the user device may include a cryptogramSK. The cryptogram transmitted by the user device may be referred to as a first cryptogram. The cryptogramSK transmitted by the user device may be referred to as a first cryptogramSK. The reader (120) can receive the cryptogram transmitted by the user device (110).
[0053] The reader (120) can obtain kpersistents. The reader (120) can obtain kpersistents through standard transactions. The reader (120) can check each kpersistent stored in the reader (120) and calculate a cryptogramSK for each kpersistent. In other words, the reader (120) can generate a cryptogramSK using kpersistents. At least one kpersistent stored in the reader may be referred to as a second kpersistent. The cryptogramSK calculated by the reader (120) may be referred to as a second cryptogramSK. The reader (120) can decrypt a first cryptogram transmitted by a user device (110) using the second cryptogramSK. When decrypting the first cryptogram, if the decrypted value is a valid value, the reader (120) can determine that the first cryptogramSK and the second cryptogramSK values match. The reader (120) can generate information by decrypting the cryptogram. The reader (120) can verify the cryptogram payload through the decrypted information. The reader (120) can determine access information by verifying the cryptogram payload. The reader can determine whether the access information is a valid value. When the reader (120) decrypts the cryptogram transmitted by the user device (110), if the decrypted value is not a valid value, the reader (120) can check the second kpersistent stored in the reader (120) and calculate the second cryptogramSK.
[0054] FIG. 2 is a flowchart illustrating one example of a procedure for transmitting a cryptogram.
[0055] Referring to FIG. 2, the user device (210) and / or reader (220) may perform at least one of a standard transaction (S210) procedure, a step-up transaction (S220) or a fast transaction (S230) procedure. The user device (210) and / or reader (220) may perform a standard transaction to generate kpersistent. The user device (210) and / or reader (220) may perform at least one standard transaction to generate kpersistent.
[0056] The user device (210) and / or the reader (220) may perform a standard transaction (S210) procedure. The standard transaction (S210) procedure may be as follows. The reader (220) may generate an AUTH0 command for authentication between the user device (210) and the reader (220). The reader (220) may transmit the AUTH0 command to the user device (210) (S211). The AUTH0 command may include authorization command information for the user device. The AUTH0 command may include at least one of a reader ID or reader.ePK. The AUTH0 command may be referred to as an authentication command.
[0057] The user device (210) can receive an AUTH0 command transmitted by the reader (220). The user device (210) can generate an AUTH0 response (response, rsp) corresponding to the AUTH0 command. The user device (210) can transmit the AUTH0 response to the reader (220) (S212). The AUTH0 response may include user device.ePK. For fast transactions, the AUTH0 response may include a cryptogram. The reader (220) can receive the AUTH0 response transmitted by the user device (210). The AUTH0 response may be referred to as an authentication response.
[0058] The reader (220) can generate an AUTH1 command for authentication between the user device (210) and the reader (220). The AUTH1 command may include at least one of a reader signature or a reader PK. The reader (220) can transmit the AUTH1 command to the user device (210) (S213). The AUTH1 command may include authorization command information for the user device (210). The AUTH1 command may be a subsequent command transmitted after at least one AUTH0 command and AUTH0 response have been exchanged between the user device (210) and the reader (220).
[0059] The user device (210) can receive an AUTH1 command transmitted by the reader (220). The user device (210) can generate an AUTH1 response corresponding to the AUTH1 command. The AUTH1 response may include a user device signature or a user device PK. The user device (210) can transmit the AUTH1 response to the reader (220) (S214). The user device (210) can generate a kpersistent. The reader (220) can receive the AUTH1 response transmitted by the user device (210). The reader (220) can generate a kpersistent.
[0060] The reader (220) can generate an exchange command. The reader (220) can transmit the exchange command to the user device (210) (S215). The user device (210) can receive the exchange command transmitted by the reader (220). The user device (210) can transmit an exchange response to the reader (220) (S216). The reader (220) can receive the exchange response transmitted by the user device (210).
[0061] The user device (210) and / or the reader (220) can perform a step-up transaction (S220) procedure. The reader (220) can generate an envelope. The reader (220) can transmit the envelope to the user device (210) (S221). The user device (210) can receive the envelope transmitted by the reader (220). The user device (210) can transmit a GET RESPONSE to the reader (220). The reader (220) can receive the GET RESPONSE transmitted by the user device (210) (S222).
[0062] The user device (210) and / or the reader (220) can perform a fast transaction (S230) procedure. The fast transaction (S230) can be performed after at least one standard transaction procedure has been performed. The reader (220) can generate an AUTH0 command. The reader (220) can transmit the AUTH0 command to the user device (210) (S231). The AUTH0 command may include authorization command information for the user device. The AUTH0 command may include a cryptogram request. The reader (220) can request a cryptogram from the user device (210) via the AUTH0 command.
[0063] The user device (210) can receive an AUTH0 command transmitted by the reader (220). The user device (210) can generate an AUTH0 response using the AUTH0 command. The user device (210) can transmit the AUTH0 response to the reader (220) (S212). The AUTH0 response may include a cryptogram. The user device (210) can transmit the cryptogram to the reader (220) through the AUTH0 response. The reader (220) can receive the AUTH0 response transmitted by the user device (210).
[0064] When performing the expedited-fast phase, the reader (220) can verify the cryptogram through trial and error using the value of kpersistent. If the reader does not find a value (kpersistent) that matches the cryptogram of the terminal, the reader (220) can perform the standard transaction phase again. The expedited-fast transaction procedure may include the expedited-fast phase.
[0065] FIG. 3a is a flowchart illustrating an example of an access credential identifier.
[0066] FIG. 3b is a flowchart illustrating an example of a connection credential ID.
[0067] Referring to FIGS. 3a and 3b, when the reader (320) or user device (310) is used in an office or building, the reader (320) can store hundreds or more cryptograms. When the reader (320) or user device (310) is used in an office or building, the reader (320) can store hundreds or more kpersistents. In other words, in a single-family home, the reader (320) can store at least one cryptogram. In a single-family home, the reader (320) can store at least one kpersistent. The reader (320) can provide fast gate passage to the user through an expedited-fast phase of the standard transaction procedure. There may be limitations to the reader (320) providing a user experience (UX) that includes fast gate passage. The reader (320) can match a cryptogram (e.g., kpersistent) stored within the reader (320) with a cryptogram received from a terminal. In other words, the reader (320) can match a cryptogram (e.g., kpersistent) stored within the reader (320) with a cryptogram received from a user device (310). The time required to match a cryptogram (e.g., kpersistent) stored within the reader (320) with a cryptogram received from a terminal may be increased. In other words, the time required to match a cryptogram (e.g., kpersistent) stored within the reader (320) with a cryptogram received from a user device (310) may be increased. If no matching occurs for a specific period of time, the reader (320) may perform a standard transaction. The user device (310) may include a partner application.Partner applications may include applications for partner companies that have entered into a contract with the user device (310). The user device (310) may add a wallet to provide services on its own without the partner application. The user device (310) may include information received from partners or partner companies. In other words, the wallet added by the user device may include information received from partners or partner companies. The information added to the wallet may include the UI (user interface) of a card received from a partner or partner company. The UI of a card received from a partner company may include the card color displayed on the screen of the user device (310). The information received from partners or partner companies may be referred to as first information. The user device (310) may request credentials from the user device server (312) (S303). The user device server (312) may receive the credential request transmitted by the user device (310).
[0068] The Option 2 procedure may be performed by at least one of the credential issuance server (316), the user device server (312), or the user device (310). The credential issuance server (316) may perform a provisioning procedure triggered by the credential issuance server (316) (S305). The credential issuance server (316) may transmit the provisioning MMS (multimedia messaging service) / Email to the user device server (312) (S307). The user device server (312) may receive the provisioning MMS / Email transmitted by the credential issuance server (316). The user device server (312) may transmit the provisioning MMS / Email to the user device (310) (S309). The user device (310) may receive the provisioning MMS / Email transmitted by the user device server (312). The user device (310) can add a wallet (S311). The user device (310) may include a partner application. The partner application may include applications for partner companies that have contracted with the user device (310). The user device (310) may add a wallet to provide services on its own without a partner application. The user device (310) may include information received from a partner or partner company. In other words, the wallet added by the user device may include information received from a partner or partner company. The information added to the wallet may include the UI (user interface) of a card received from a partner or partner company. The UI of a card received from a partner company may include the card color displayed on the screen of the user device (310). The information received from a partner or partner company may be referred to as the first information. The user device (310) may request credentials from the user device server (312) (S311).The user device server (312) can receive a credential request sent by the user device (310).
[0069] The user device server (312) may request credentials from the credential issuance server (316) (S313). The user device server (312) may generate a session ID. The user device server (312) may transmit the session ID to the credential issuance server (316). The credential issuance server (316) may receive the credential request transmitted by the user device server (312). The credential issuance server (316) may receive the session ID transmitted by the user device server (312).
[0070] The credential issuance server (316) can request a reader pubkey from the reader system issuer server (318) (S315). The reader system issuer server (318) can receive the reader pubkey request sent by the credential issuance server (316).
[0071] The reader system publisher server (318) can request a reader public key from the reader (320) (S317). The reader (320) can receive the reader public key request transmitted by the reader system publisher server (318).
[0072] The reader (320) can send a reader pubkey response to the reader system publisher server (318) in response to a reader public key request (S319). The reader pubkey response may include a public key for the reader (320). The reader system publisher server (318) can receive the reader pubkey response sent by the reader (320).
[0073] The reader system issuer server (318) can transmit the reader public key response to the credential issuance server (316) (S321). The credential issuance server (316) can receive the reader public key response transmitted by the reader system issuer server (318).
[0074] The credential issuing server (316) can transmit credential information to the user device server (312) (S323). The credential information may include at least one of a reader pubkey or a reader ID. The reader pubkey may be referred to as reader pubk. The user device server (312) can receive the credential information transmitted by the credential issuing server (316).
[0075] The user device (310) can receive credential information transmitted by the user device server (312).
[0076] The user device server (312) can transmit credential information to the user device (310) (S325). The user device (310) can receive the credential information transmitted by the user device server (312).
[0077] The user device (310) can transmit credentials to the credential manager server (314) (S327). The credential manager server (314) can receive the credentials transmitted by the user device (310).
[0078] The credential manager server (314) can generate access credential information. The credential manager server (314) can transmit the access credential information to the user device (310) (S329). The user device (310) can receive the access credential information transmitted by the credential manager server (314).
[0079] The user device (310) can generate connection credentials (S331). In other words, the user device (310) can generate a space called connection credentials.
[0080] The user device (310) can transmit the public key of the access credential information to the user device server (312) (S333). The user device server (312) can receive the public key of the access credential transmitted by the user device (310).
[0081] The user device server (312) can transmit the public key of the connection credentials to the credential issuing server (316) (S335). The credential issuing server (316) can receive the public key of the connection credentials transmitted by the user device (310).
[0082] The credential issuing server (316) can transmit an access credential ID to the user device server (312) (S337). The user device server (312) can receive the access credential ID transmitted by the credential issuing server (316).
[0083] The user device server (312) can transmit a connection credential ID to the user device (310) (S339). The user device (310) can receive the connection credential ID transmitted by the user device server (312).
[0084] The user device (310) can assign the access credential ID to a reader group sub ID (S341). The user device (310) can map the access credential ID to the reader group sub ID. In other words, the user device (310) can map the matching ID to the reader group sub ID.
[0085] The user device (310) may request an access document from the credential manager server (314) (S343). The access document may include personal credential information. The personal credential information may include credential information for the user device (310). The credential manager server (314) may receive a request for an access document transmitted by the user device (310).
[0086] The credential manager server (314) can generate a personal access document. The credential manager server (314) can transmit the personal access document to the user device (310) (S345).
[0087] The credential issuing server (316) may transmit at least one of a reader parameter, an access credential pubkey, or an access credential ID to the reader system publisher server (318) (S347). The reader system publisher server (318) may receive at least one of the reader parameter, the access credential pubkey, or the access credential ID transmitted by the credential issuing server (316). The reader system publisher server (318) may transmit at least one of the reader parameter, the access credential pubkey, or the access credential ID to the reader (320) (S349). The reader (320) may receive at least one of the reader parameter, the access credential pubkey, or the access credential ID transmitted by the reader system publisher server (318). The reader (320) can bind the connection credential ID to the connection credential public key stored within the reader (320) (S351). In other words, the reader (320) can make the connection credential ID belong to the connection credential public key stored within the reader (320).
[0088] The reader (320) can generate an AUTH0 command. The reader (320) can transmit the AUTH0 command to the user device (310) (S353). The AUTH0 command may include authorization command information for the user device. The AUTH0 command may include a reader ID.
[0089] The user device (310) can receive an AUTH0 command transmitted by the reader (320). The user device (310) can generate an AUTH0 response using the AUTH0 command. The user device (310) can transmit the AUTH0 response to the reader (320) (S355). The reader (320) can receive the AUTH0 response transmitted by the user device (310).
[0090] The reader (320) can generate an AUTH1 command. The reader (320) can transmit the AUTH1 command to the user device (310) (357). The AUTH1 command may include authorization command information for the user device (210). The AUTH1 command may include a reader ID. The user device (310) can receive the AUTH1 command transmitted by the reader (320).
[0091] The user device (310) can bind kpersistent to a reader group sub ID or a connection credential ID (S359). In other words, the user device (310) can link kpersistent to a reader group sub ID or a connection credential ID.
[0092] The user device (310) can generate an AUTH1 response using an AUTH1 command. The AUTH1 response may include a public key for access credentials. The user device (310) can transmit the AUTH1 response to a reader (320) (S361). The reader (320) can receive the AUTH1 response transmitted by the user device (310).
[0093] The reader (320) can bind the generated kpersistent to a connection credential ID (S363). In other words, the reader (320) can link the generated kpersistent to a connection credential ID. The reader (320) can map a matching ID to the kpersistent.
[0094] FIG. 4 is a block diagram illustrating an example of a connection credential ID.
[0095] Referring to FIG. 4, the reader (420) can perform a provisioning procedure. The provisioning procedure may include a procedure for the reader and the user device to exchange data necessary to perform standard transactions. The reader (420) can obtain a connection credential ID. In other words, the reader (420) can receive a connection credential ID from a credential issuing server. The reader (420) can generate a reader ID. The reader (420) can generate a reader.ePK or a reader.eSK. The reader.ePK (ephemeral public key) and the reader.eSK (ephemeral secure key) may represent corresponding keys. The reader.ePK may represent a temporary public key generated by the reader (420). The reader.eSK may represent a temporary secure key generated by the reader (420). The reader (420) can generate a reader.ePK for every transaction. reader.ePK may be referred to as a temporary public key. The reader (420) may generate reader.eSK for every transaction. reader.eSK may be referred to as a temporary private key. In other words, reader.ePK may be newly generated for every transaction between the user device and the reader. The reader pubkey may refer to a value that is stored continuously once generated.
[0096] The reader (420) can transmit an AUTHO command (command, cmd) to the user device (410). The AUTHO command may include at least one of a reader ID or a reader.ePK. The user device (410) can receive the AUTH0 transmitted by the reader (420).
[0097] The user device (410) may include at least one of a reader group ID (411), a reader public key (413), or a reader group sub ID (415). The reader group sub ID (415) may include at least one of a kpersistent, a cryptogram payload, or an access credential ID.
[0098] The reader group ID (411) may include at least one reader ID or at least one reader group sub ID (415). The reader group ID may include information for identifying a reader group that includes at least one reader. The reader group ID may include at least one of a reader public key (413) or a reader group sub ID (415). The reader group sub ID (415) may include at least one of a kpersistent, a cryptogram payload, or an access credential ID.
[0099] The reader public key (413) may mean a key that can be used publicly by at least one reader included in the reader group ID. Different reader group IDs may include the same or different reader public keys. In other words, the first reader group ID may include the first reader public key. The second reader group ID may include the second reader public key. The reader public key (413) may include a reader group sub ID (415). The reader group sub ID (415) may include at least one of kpersistent, cryptogram payload, or access credential ID. For example, kpersistent may include kpersistent A. kpersistent A may mean kpersistent for the user device (410). For example, the access credential ID may include access credential ID 9.
[0100] The reader group sub-ID (415) may include at least one reader ID for the reader group ID (411). The reader group sub-ID (415) may include at least one of kpersistent, cryptogram payload, or access credential ID.
[0101] The user device (410) can generate an AUTH0 response. The user device (410) can transmit the AUTH0 response to the reader (420). For example, the AUTH0 response can be represented as shown in Table 1.
[0102]
[0103] The user device (410) can acquire a cryptogram. The user device (410) can generate a cryptogram. The user device (410) can receive a cryptogram. The user device (410) can acquire a kpersistent. The user device (410) can generate a kpersistent. The user device (410) can receive a kpersistent. The kpersistent stored in the user device (410) may be referred to as the first kpersistent. The user device (410) can acquire a connection credential ID. The user device (410) can generate a connection credential ID. The user device (410) can receive a connection credential ID. The connection credential ID stored in the user device (410) may be referred to as the first connection credential ID.
[0104] The user device (410) can transmit an AUTH0 response (response, rsp) to the reader (420). The AUTH0 response may include at least one of an access credential public key (access credential ePubK), a cryptogram, or an access credential ID. The access credential ID may be encrypted using a temporary public key (reader.ePK). In other words, the user device (410) may encrypt the matching ID using the temporary public key (reader.ePK). The cryptogram may be encrypted using the temporary public key (reader.ePK). If the access credential includes a kpersistent value for matching with a reader group sub ID, the access credential ID may be transmitted to the reader (420).
[0105] Reader.ePK can be paired with reader.eSK. The Reader.ePK / reader.eSK key pair can represent a value newly generated for each transaction. The Reader.ePK / reader.eSK key pair can prevent repetitive attacks. A cryptogram can include cryptogramSKEnc.
[0106] The reader (420) can receive an AUTH0 response transmitted by the user device (410). The reader (420) may include a reader ID (421). The reader (420) may generate at least one kpersistent (425). The reader (420) may include at least one kpersistent (425). The reader (420) may include at least one access credential ID. The reader ID (421) may include information for identifying the reader (420). For example, at least one kpersistent (425) may include kpersistent Z, kpersistent C, kpersistent M, kpersistent A, etc. For example, at least one access credential ID may include access credential ID 1, access credential ID 6, access credential ID 7, access credential ID 9, etc.
[0107] The kpersistent stored in the reader (420) may be referred to as the second kpersistent. The reader (420) may link the second kpersistent with an access credential ID. For example, the reader (420) may link access credential ID 1 to kpersistent Z. The reader (420) may receive an access credential ID included in AUTH0 and match it with the access credential ID stored in the reader (420). The access credential ID transmitted by the user device (410) may be referred to as the first access credential ID. The access credential ID stored in the reader (420) may be referred to as the second access credential ID. The reader (420) may check whether the first access credential ID and the second access credential ID match. In other words, the reader (420) can determine whether the first access credential ID and the second access credential ID match. The reader (420) can decrypt the first access credential ID using reader.eSK. The reader (420) can find the matching second access credential ID using the decrypted first access credential ID. If the first access credential ID and the second access credential ID match, the reader (420) can determine that the kpersistent of the user device (410) and the kpersistent of the reader (420) match.
[0108] FIG. 5 is a block diagram illustrating an embodiment for transmitting a connection credential ID.
[0109] Referring to FIG. 5, the user device can directly generate an Access Credential ID. The user device can transmit the directly generated Access Credential ID to the reader. The user device can use an AUTH1 response, an EXCHANGE response, or a GET response to transmit the Access Credential ID to the reader. After transmitting the AUTH1 response, the user device can generate a kpersistent. The user device can associate the Access Credential ID with the kpersistent. After receiving the AUTH1 response, the reader can generate a kpersistent. The reader can associate the Access Credential ID with the kpersistent. When the reader requests a cryptogram from the user device, the user device can transmit the Access Credential ID along with the cryptogram. The reader can decrypt only a specific kpersistent using the Access Credential ID transmitted by the user device.
[0110] The reader (520) can transmit at least one of an AUTH1 command, an EXCHANGE command, or an ENVELOPE to the user device (510). The user device (510) can transmit at least one of an AUTH1 response (rsp), an EXCHANGE response, or a GET response to the reader (520). The user device may include a terminal or a reader. A terminal may refer to a device that transmits and receives data with another terminal. The reader (520) may include a terminal or a user device (510).
[0111] The user device (510) can receive at least one of an AUTH1 command, an EXCHANGE command, or an ENVELOPE transmitted by the reader (520). At least one of the AUTH1 command, the EXCHANGE command, or the ENVELOPE may include a reader ID.
[0112] The user device (510) may include at least one of a reader group ID (511), a reader public key (513), or a reader group sub ID (515). The reader group sub ID (515) may include at least one of a kpersistent, a cryptogram payload, or an access credential ID. The access credential ID included in the user device (510) may be referred to as the first access credential ID. The access credential ID included in the user device (510) may include an access credential ID 9.
[0113] The user device (510) can generate a kpersistent. The kpersistent may include kpersistent A. kpersistent A may represent the kpersistent for the user device (510). The user device (510) can obtain an access credential ID. In other words, the user device (510) can receive an access credential ID from a credential issuing server. The user device (510) can generate an access credential ID directly. An access credential ID generated directly by the user device (510) may be referred to as the first access credential ID. The access credential ID may include access credential ID 9.
[0114] The reader group sub-ID (515) may include at least one reader ID for the reader group ID (511). The reader group sub-ID (515) may include at least one of kpersistent, cryptogram payload, or access credential ID.
[0115] The user device (510) may transmit at least one of an AUTH1 response, an EXCHANGE response, or a GET response to the reader (520). At least one of the AUTH1 response, the EXCHANGE response, or the GET response may include a cryptogram or a connection credential ID (a first connection credential ID). The GET response may be transmitted via a step-up secure channel. For example, at least one of the AUTH1 response, the EXCHANGE response, or the GET response may include information such as that shown in Table 2.
[0116]
[0117] The reader (520) may receive at least one of an AUTH1 response, an EXCHANGE response, or a GET response transmitted by the user device (510). The reader (520) may receive a cryptogram or an access credential ID. In other words, the reader (520) may obtain an access credential ID. The reader (520) may obtain an access credential ID in a standard transaction procedure. The reader (520) may receive an access credential ID from the user device (510). An access credential ID stored by the reader may be referred to as a second access credential ID. An access credential ID generated by the reader (520) may be referred to as a second access credential ID. The second access credential ID may include at least one access credential ID. For example, the second access credential ID may include access credential ID 1, access credential ID 6, access credential ID 7, access credential ID 9, etc.
[0118] The reader (520) may include a reader ID (521). The reader (520) may include at least one kpersistent (525). The reader (520) may include at least one access credential ID. The reader ID (521) may include information for identifying the reader (520). A kpersistent generated by the reader may be referred to as a second kpersistent. A kpersistent stored in the reader may be referred to as a second kpersistent. At least one second kpersistent may include kpersistent Z, kpersistent C, kpersistent M, kpersistent A, etc.
[0119] The reader can perform the following procedures in the fast transaction procedure. The fast transaction procedure can be performed after the standard transaction procedure.
[0120] The reader (520) can receive a connection credential ID or cryptogram transmitted by the user device (510). In a fast transaction procedure, the connection credential ID transmitted by the user device may be referred to as the first connection credential ID. The reader (520) can find the second connection credential ID using the first connection credential ID (e.g., connection credential ID 9). In other words, if the first connection credential ID and the second connection credential ID match, the reader (520) can find the kpersistent (e.g., kpersistent A) connected to the second connection credential ID.
[0121] The reader (520) can extract a CryptogramSK from a specific kpersistent (e.g., kpersistent A). The CryptogramSK extracted by the reader (520) may be referred to as the second CryptogramSK. The reader (520) can decrypt the first cryptogram using the second CryptogramSK. The reader (520) can perform validation on the decrypted first cryptogram.
[0122] In other words, the reader (520) can receive and store the access credential ID included in AUTH0. The access credential ID transmitted by the user device (510) may be referred to as the first access credential ID. The access credential ID stored in the reader (520) may be referred to as the second access credential ID. The user device (510) may combine the first access credential ID with a cryptogram and transmit it to the reader (520). The first access credential ID and / or cryptogram transmitted by the user device (510) may be encrypted. The reader (520) can check whether the first access credential ID and the second access credential ID match. In other words, the reader (520) can determine whether the first access credential ID and the second access credential ID match. The reader (520) can decrypt the first access credential ID using reader.eSK. The reader (520) can find a matching second access credential ID using the decrypted first access credential ID. If the first access credential ID and the second access credential ID match, the reader (520) can determine that the kpersistent of the user device (510) and the kpersistent of the reader (520) match. In other words, if the first access credential ID and the second access credential ID match, the reader (520) can extract a crypogramSK from the second kpersistent associated with the second access credential ID.If the first access credential ID and the second access credential ID match, the reader (520) can calculate a crypogramSK from the kpersistent associated with the second access credential ID. The crypogramSK calculated by the reader (520) may be referred to as the second crypogramSK. The reader (520) can decrypt the first cryptogram using the second crypogramSK. In other words, the reader (520) can check whether the first cryptogram is decrypted using the second crypogramSK. The reader (520) can validate the information of the decrypted first cryptogram. In other words, the reader (520) can decrypt the first cryptogram to obtain the cryptogram payload. The reader (520) can validate the information included in the cryptogram payload by considering the time information. The reader (520) can obtain a first kpersistent by decrypting the first cryptogram. The reader (520) can determine whether the first kpersistent matches the second kpersistent using the first kpersistent.
[0123] FIG. 6 is a flowchart illustrating an embodiment for transmitting a connection credential ID.
[0124] Referring to FIG. 6, a user device (610) and a reader (620) can perform a transaction procedure. The user device (610) can generate a connection credential ID. In the transaction procedure, the user device (610) can send an AUTH1 response to the reader (620) (S611). The AUTH1 response may include a connection credential ID. After sending the AUTH1 to the reader, the user device (610) can generate kpersistent. The reader (620) can receive the AUTH1 response sent by the user device (610). After receiving the AUTH1 from the user device, the reader (620) can generate kpersistent.
[0125] In the transaction procedure, the user device (610) can send an exchange response to the reader (620) (S613). The exchange response may include a connection credential ID. The reader (620) can receive the exchange response sent by the user device (610).
[0126] In a transaction procedure, the user device (610) can send a GET response to the reader (620) (S615). The GET response may include a connection credential ID. The reader (620) can receive the GET response sent by the user device (610).
[0127] The connection credential ID can be transmitted and received by a transaction procedure between the user device and the reader. The values in Table 2 can be transmitted to the reader (620) via at least one of an AUTH1 response, an EXCHANGE response, or a GET response. The reader (620) can store the connection credential ID received from the user device (610) by concatenating it with the Kpersistent generated in AUTH1.
[0128] When the user device (610) generates a value of kpersistent, it can connect a connection credential ID to kpersistent.
[0129] The reader (620) can generate a kpersistent. When the reader (620) generates a value of the kpersistent, it can link a connection credential ID to the kpersistent. The second kpersistent may include the kpersistent generated by the reader (620). The second kpersistent may include the kpersistent stored in the reader (620).
[0130] FIG. 7a is a flowchart illustrating an example of a grouping identifier.
[0131] FIG. 7b is a flowchart illustrating an example of a grouping ID.
[0132] Referring to FIGS. 7a and 7b, a user device (710) and / or a reader (720) can perform grouping. Grouping may mean grouping for kpersistents. The user device (710) and / or the reader (720) may set a representative ID for at least one kpersistent for grouping. The grouping ID may be matched with at least one kpersistent. The representative ID may mean a grouping ID. The user device (710) and / or the reader (720) may set a connection credential ID as the grouping ID.
[0133] The grouping ID may include at least one of the Vendor ID or an Offset within the Vendor Specific Field. The grouping ID may be transmitted to a reader. In other words, the grouping ID may be transmitted to the reader by a user device, a credential issuance server, a UE, or another reader. The grouping ID may be transmitted to the reader by a provisioning procedure. The grouping ID may be transmitted to the reader by an AUTH1 response, an EXCHANGE, or a GET response. The grouping ID may be transmitted to the user device by a provisioning procedure.
[0134] When a user device creates a kpersistent, it can associate the group ID with the kpersistent. When a reader creates a kpersistent, it can associate the group ID with the kpersistent.
[0135] The reader can locate kpersistents contained within a grouping ID stored in the reader using the grouping ID transmitted by the user device. The reader can determine whether the found kpersistents match the crypogram transmitted by the user device. The reader can perform a trial-and-error procedure on the kpersistents contained in the grouping ID.
[0136] FIGS. 7a and 7b may include at least one of a user device (710), a user device server (712), a credential manager server (SKMS) (714), a credential issuer server (716), a reader system issuer server (718), or a reader (720).
[0137] The present disclosure may perform the Option 1 procedure and / or Option 2 procedure to generate a credential ID.
[0138] The Option 1 procedure can be performed by the user device (710) or the user device server (712). The user device (710) can perform the Provisioning Triggered via Partner App procedure (S701). The user device (710) can add to wallet (S703). The user device (710) can request credentials from the user device server (712) (S703). The user device server (712) can receive the credential request sent by the user device (710).
[0139] The Option 2 procedure may be performed by at least one of the credential issuance server (716), the user device server (712), or the user device (710). The credential issuance server (716) may perform a provisioning procedure triggered by the credential issuance server (716) (S705). The credential issuance server (716) may transmit the provisioning MMS (multimedia messaging service) / Email to the user device server (712) (S707). The user device server (712) may receive the provisioning MMS / Email transmitted by the credential issuance server (716). The user device server (712) may transmit the provisioning MMS / Email to the user device (710) (S709). The user device (710) may receive the provisioning MMS / Email transmitted by the user device server (712). The user device (710) can add a wallet (S711). The user device (710) can request credentials from the user device server (712) (S711). The user device server (712) can receive the credentials request sent by the user device (710).
[0140] The user device server (712) may request credentials from the credential issuance server (716) (S713). The user device server (712) may generate a session ID. The user device server (712) may transmit the session ID to the credential issuance server (716). The credential issuance server (716) may receive the credential request transmitted by the user device server (712). The credential issuance server (716) may receive the session ID transmitted by the user device server (712).
[0141] The credential issuance server (716) can request a reader pubkey from the reader system issuer server (718) (S715). The reader system issuer server (718) can receive the reader pubkey request sent by the credential issuance server (716).
[0142] The reader system publisher server (718) can request a reader public key from the reader (720) (S717). The reader (720) can receive the reader public key request transmitted by the reader system publisher server (718).
[0143] The reader (720) can send a reader pubkey response to the reader system publisher server (718) in response to a reader public key request (S719). The reader pubkey response may include a public key for the reader (720). The reader system publisher server (718) can receive the reader pubkey response sent by the reader (720).
[0144] The reader system issuer server (718) can transmit the reader public key response to the credential issuance server (716) (S721). The credential issuance server (716) can receive the reader public key response transmitted by the reader system issuer server (718).
[0145] The credential issuing server (716) can transmit credential information to the user device server (712) (S723). The credential information may include at least one of a reader pubkey or a reader ID. The reader pubkey may be referred to as reader pubk. The user device server (712) can receive the credential information transmitted by the credential issuing server (716).
[0146] The user device (710) can receive credential information transmitted by the user device server (712).
[0147] The user device server (712) can transmit credential information to the user device (710) (S725). The user device (710) can receive the credential information transmitted by the user device server (712).
[0148] The user device (710) can transmit credentials to the credential manager server (714) (S727). The credential manager server (714) can receive the credentials transmitted by the user device (710).
[0149] The credential manager server (714) can generate access credential information. The credential manager server (714) can transmit the access credential information to the user device (710) (S729). The user device (710) can receive the access credential information transmitted by the credential manager server (714).
[0150] The user device (710) can generate connection credentials (S731). In other words, the user device (710) can generate a space called connection credentials.
[0151] The user device (710) can transmit the access credential pubkey to the user device server (712) (S733). The user device server (712) can receive the access credential pubkey transmitted by the user device (710).
[0152] The user device server (712) can transmit the public key of the connection credentials to the credential issuing server (716) (S735). The credential issuing server (716) can receive the public key of the connection credentials transmitted by the user device (710).
[0153] The credential issuance server (716) can generate a grouping ID. The credential issuance server (716) can transmit the grouping ID to the user device server (712) (S737). The user device server (712) can receive the connection grouping ID transmitted by the credential issuance server (716).
[0154] The user device server (712) can transmit a grouping ID to the user device (710) (S739). The user device (710) can receive the grouping ID transmitted by the user device server (712).
[0155] The user device (710) can assign a grouping ID to a reader group sub ID (S741). The user device (710) can map a grouping ID to a reader group sub ID. In other words, the user device (710) can map a matching ID to a reader group sub ID.
[0156] The user device (710) may request an access document from the credential manager server (714) (S743). The access document may include personal credential information. The personal credential information may include at least one of credential information or a grouping ID for the user device (710). The credential manager server (714) may receive a request for an access document transmitted by the user device (710).
[0157] The credential manager server (714) can generate a personal access document. The credential manager server (714) can transmit the personal access document to the user device (710) (S745).
[0158] The credential issuing server (716) may transmit at least one of a reader parameter, an access credential pubkey, or a grouping ID to the reader system publisher server (718) (S747). The reader system publisher server (718) may receive at least one of the reader parameter, the access credential pubkey, or the grouping ID transmitted by the credential issuing server (716). The reader system publisher server (718) may transmit at least one of the reader parameter, the access credential pubkey, or the grouping ID to the reader (720) (S749). The reader (720) may receive at least one of the reader parameter, the access credential pubkey, or the grouping ID transmitted by the reader system publisher server (718). The reader (720) can bind the grouping ID to the public key of the access credentials stored within the reader (720) (S751). In other words, the reader (720) can make the grouping ID belong to the public key of the access credentials stored within the reader (720).
[0159] The reader (720) can generate an AUTH0 command. The reader (720) can transmit the AUTH0 command to the user device (710) (S753). The AUTH0 command may include authorization command information for the user device. The AUTH0 command may include a reader ID.
[0160] The user device (710) can receive an AUTH0 command transmitted by the reader (720). The user device (710) can generate an AUTH0 response using the AUTH0 command. The user device (710) can transmit the AUTH0 response to the reader (720) (S755). The reader (720) can receive the AUTH0 response transmitted by the user device (710).
[0161] The reader (720) can generate an AUTH1 command. The reader (720) can transmit the AUTH1 command to the user device (710) (757). The AUTH1 command may include authorization command information for the user device (210). The AUTH1 command may include a reader ID. The user device (710) can receive the AUTH1 command transmitted by the reader (720).
[0162] The user device (710) can bind kpersistent to a reader group sub ID or grouping ID (S759). In other words, the user device (710) can link kpersistent to a reader group sub ID or grouping ID.
[0163] The user device (710) can generate an AUTH1 response using an AUTH1 command. The AUTH1 response may include a public key for access credentials. The user device (710) can transmit the AUTH1 response to a reader (720) (S761). The reader (720) can receive the AUTH1 response transmitted by the user device (710).
[0164] The reader (720) can bind the generated kpersistent to a grouping ID (S763). In other words, the reader (720) can link the generated kpersistent to a grouping ID.
[0165] FIG. 8 is a flowchart illustrating embodiments for transmitting a grouping ID.
[0166] Referring to FIG. 8, the reader (820) can perform a provisioning procedure. The provisioning procedure may include a procedure for the reader and the user device to exchange data necessary to perform standard transactions. The reader (820) can generate a reader ID. The reader (820) can obtain a connection credential ID. In other words, the reader (820) can receive a connection credential ID from a credential issuing server. The reader (820) can generate a reader ID. The reader (820) can generate a reader.ePK or a reader.eSK. The reader.ePK (ephemeral public key) and the reader.eSK (ephemeral secure key) may represent corresponding keys. The reader.ePK may represent a temporary public key generated by the reader (820). The reader.eSK may represent a temporary secure key generated by the reader (820). The reader (820) can transmit an AUTHO command (command, cmd) to the user device (810). The AUTHO command may include at least one of a reader ID or a reader.ePK. The user device (810) can receive the AUTH0 transmitted by the reader (820).
[0167] The user device (810) may include at least one of a reader group ID (811), a reader public key (813), or a reader group sub ID (815). The reader group sub ID (815) may include at least one of a kpersistent, a cryptogram payload, or an access credential ID.
[0168] The reader group ID (811) may include at least one reader ID or at least one reader group sub ID (815). The reader group ID may include information for identifying a reader group that includes at least one reader. The reader group ID may include at least one of a reader public key (813) or a reader group sub ID (815). The reader group sub ID (815) may include at least one of a kpersistent, a cryptogram payload, or an access credential ID.
[0169] The reader public key (813) may mean a key that can be used publicly by at least one reader included in the reader group ID. Different reader group IDs may include the same or different reader public keys. In other words, the first reader group ID may include the first reader public key. The second reader group ID may include the second reader public key. The reader public key (813) may include a reader group sub ID (815). The reader group sub ID (815) may include at least one of kpersistent, cryptogram payload, or access credential ID. For example, kpersistent may include kpersistent A. kpersistent A may mean kpersistent for the user device (810). For example, the access credential ID may include access credential ID 9.
[0170] The reader group sub-ID (815) may include at least one reader ID for the reader group ID (811). The reader group sub-ID (815) may include at least one of kpersistent, cryptogram payload, or access credential ID.
[0171] The user device (810) can generate an AUTH0 response. The user device (810) can transmit the AUTH0 response to the reader (820). For example, the AUTH0 response can be represented as shown in Table 3.
[0172]
[0173] The user device (810) can acquire a cryptogram. The user device (810) can generate a cryptogram. The user device (810) can receive a cryptogram. The user device (810) can acquire a kpersistent. The user device (810) can generate a kpersistent. The user device (810) can receive a kpersistent. The kpersistent stored in the user device (810) may be referred to as the first kpersistent. The user device (810) can acquire a grouping ID. The user device (810) can generate a grouping ID. The user device (810) can receive a grouping ID. The grouping ID stored in the user device (810) may be referred to as the first connection grouping ID.
[0174] The user device (810) may send an AUTH0 response (response, rsp) to the reader (820). The AUTH0 response may include information such as that shown in Table 3. The AUTH0 response may include at least one of an access credential public key (access credential ePubK), a cryptogram, or a grouping ID. The grouping ID may be encrypted using a temporary public key (reader.ePK). If the user device's Access Credential space has a Kpersistent value that matches the reader subgroup ID, the user device (810) may send the grouping (Grouping ID) to the reader. Reader.ePK may be paired with reader.eSK. The Reader.ePK / reader.eSK key pair may represent a value that is newly generated for each transaction. The Reader.ePK / reader.eSK key pair may prevent repeated attacks. The cryptogram may include cryptogramSKEnc.
[0175] The reader (820) can receive an AUTH0 response transmitted by the user device (810). The reader (820) may include a reader ID (821). The reader (820) may generate at least one kpersistent (825). The reader (820) may include at least one kpersistent (825). The reader (820) may include at least one grouping ID. The reader ID (821) and at least one kpersistent (825) may include kpersistent Z, kpersistent C, kpersistent M, kpersistent A, etc. The reader may include at least one grouping ID. The grouping ID may be associated with at least one kpersistent. For example, the reader (820) may include grouping ID A or grouping ID B. For example, grouping ID A may include at least one of kpersistent Z or kpersistent A. grouping ID B may include at least one of kpersistent M or kpersistent C.
[0176] The kpersistent stored in the reader (820) may be referred to as the second kpersistent. The reader (820) may associate the second kpersistent with a grouping ID. For example, the reader (820) may associate grouping ID A with kpersistent Z. The reader (820) may receive the grouping ID included in AUTH0 and match it with the grouping ID stored in the reader (820). The grouping ID transmitted by the user device (810) may be referred to as the first grouping ID. The grouping ID stored in the reader (820) may be referred to as the second grouping ID. The reader (820) may check whether the first grouping ID and the second grouping ID match. In other words, the reader (820) may determine whether the first grouping ID and the second grouping ID match. The reader (820) can decrypt the first grouping ID using reader.eSK. The reader (820) can find a matching second grouping ID using the decrypted first grouping ID. If the first grouping ID and the second grouping ID match, the reader (820) can determine that the kpersistent of the user device (810) and the kpersistent included in the grouping ID of the reader (820) match.
[0177] FIG. 9 is a block diagram illustrating an embodiment for transmitting a grouping ID.
[0178] Referring to FIG. 9, the user device can directly generate a Grouping ID. The user device can transmit the directly generated Grouping ID to the reader. The user device can use an AUTH1 response, an EXCHANGE response, or a GET response to transmit the Grouping ID to the reader. After transmitting the AUTH1 response, the user device can generate a kpersistent. The user device can associate the Grouping ID with the kpersistent. After receiving the AUTH1 response, the reader can generate a kpersistent. The reader can associate the Grouping ID with the kpersistent. When the reader requests a cryptogram from the user device, the user device can transmit the Grouping ID along with the cryptogram. The reader can decrypt only a specific kpersistent using the Grouping ID transmitted by the user device.
[0179] The reader (920) can transmit at least one of an AUTH1 command, an EXCHANGE command, or an ENVELOPE to the user device (910). The user device (910) can transmit at least one of an AUTH1 response (rsp), an EXCHANGE response, or a GET response to the reader (920). The user device may include a terminal or a reader. A terminal may refer to a device that transmits and receives data with another terminal. The reader (920) may include a terminal or a user device (910).
[0180] The user device (910) can receive at least one of an AUTH1 command, an EXCHANGE command, or an ENVELOPE transmitted by the reader (920). At least one of the AUTH1 command, the EXCHANGE command, or the ENVELOPE may include a reader ID.
[0181] The user device (910) may include at least one of a reader group ID (911), a reader public key (913), or a reader group sub ID (915). The reader group sub ID (915) may include at least one of a kpersistent, a cryptogram payload, or a grouping ID. The grouping ID included in the user device (910) may be referred to as the first grouping ID. The grouping ID included in the user device (910) may include grouping ID A.
[0182] The user device (910) can generate kpersistent. Kpersistent may include kpersistent A. kpersistent A may represent kpersistent for the user device (910). The user device (910) can obtain grouping ID A. In other words, the user device (910) can receive grouping ID A from a credential issuance server. The user device (910) can generate grouping ID A directly. The grouping ID generated directly by the user device (910) may be referred to as the first grouping ID. The grouping ID may include Grouping ID A.
[0183] The reader group sub-ID (915) may include at least one reader ID for the reader group ID (911). The reader group sub-ID (915) may include at least one of kpersistent, cryptogram payload, or grouping ID.
[0184] The user device (910) may transmit at least one of an AUTH1 response, an EXCHANGE response, or a GET response to the reader (920). At least one of the AUTH1 response, the EXCHANGE response, or the GET response may include a cryptogram or a grouping ID (a first grouping ID). The GET response may be transmitted via a step-up secure channel. For example, at least one of the AUTH1 response, the EXCHANGE response, or the GET response may include information such as that in Table 4.
[0185]
[0186] The reader (920) may receive at least one of an AUTH1 response, an EXCHANGE response, or a GET response transmitted by the user device (910). The reader (920) may receive a cryptogram or a grouping ID. The reader (920) may obtain a grouping ID. The reader (920) may receive a grouping ID from the user device (910). The reader (920) may receive a grouping ID from a credential issuance server. The reader (920) may obtain a grouping ID through a standard transaction. A grouping ID stored by the reader may be referred to as a second grouping ID. A grouping ID generated by the reader (920) may be referred to as a second grouping ID. The second grouping ID may include at least one Grouping ID. For example, the second grouping ID may include Grouping ID A, Grouping ID B, etc.
[0187] The reader (920) may include a reader ID (921). The reader (920) may include at least one kpersistent (925). The reader (920) may include at least one grouping ID. The reader ID (921) may include information for identifying the reader (920). A kpersistent generated by the reader may be referred to as a second kpersistent. A kpersistent stored in the reader may be referred to as a second kpersistent. At least one second kpersistent may include kpersistent Z, kpersistent C, kpersistent M, kpersistent A, etc.
[0188] The reader can perform the following procedures in the fast transaction procedure. The fast transaction procedure can be performed after the standard transaction procedure.
[0189] The reader (920) can find a specific kpersistent (e.g., kpersistent A) corresponding to a grouping ID (e.g., Grouping ID A) in the second kpersistent.
[0190] The reader (920) can receive a grouping ID or cryptogram transmitted by the user device (910). In a fast transaction procedure, the grouping ID transmitted by the user device may be referred to as the first grouping ID. The reader (920) can find the second grouping ID using the first grouping ID (e.g., grouping ID 9). In other words, if the first grouping ID and the second grouping ID match, the reader (920) can find the kpersistent (e.g., kpersistent A) connected to the second grouping ID.
[0191] The reader (920) can extract a CryptogramSK from a specific kpersistent (e.g., kpersistent A). The CryptogramSK extracted by the reader (920) may be referred to as the second CryptogramSK. The reader (920) can decrypt the first cryptogram using the second CryptogramSK. The reader (920) can perform validation on the decrypted first cryptogram.
[0192] In other words, the reader (920) can receive and store the Grouping ID included in AUTH0. The Grouping ID transmitted by the user device (910) may be referred to as the first Grouping ID. The Grouping ID stored in the reader (920) may be referred to as the second Grouping ID. The user device (910) may combine the first Grouping ID with a cryptogram and transmit it to the reader (920). The first Grouping ID and / or cryptogram transmitted by the user device (910) may be encrypted. The reader (920) can check whether the first Grouping ID and the second Grouping ID match. In other words, the reader (920) can determine whether the first Grouping ID and the second Grouping ID match. The reader (920) can decrypt the first Grouping ID using reader.eSK. The reader (920) can find a matching second grouping ID using the decrypted first grouping ID. If the first grouping ID and the second grouping ID match, the reader (920) can determine that the kpersistent of the user device (910) and the kpersistent of the reader (920) match. In other words, if the first grouping ID and the second grouping ID match, the reader (920) can extract a crypogramSK from the second kpersistent connected to the second grouping ID. If the first grouping ID and the second grouping ID match, the reader (920) can calculate a crypogramSK from the kpersistent connected to the second grouping ID. The crypogramSK calculated by the reader (920) can be referred to as the second crypogramSK. The reader (920) can decrypt the first cryptogram using the second crypogramSK.In other words, the reader (920) can check whether the first cryptogram is decrypted using the second cryptogramSK. The reader (920) can verify the validity of the information of the decrypted first cryptogram. In other words, the reader (920) can decrypt the first cryptogram to obtain the cryptogram payload. The reader (920) can verify the validity by considering the time information included in the cryptogram payload. The reader (920) can decrypt the first cryptogram to obtain the first kpersistent. The reader (920) can determine whether it matches the second kpersistent using the first kpersistent.
[0193] FIG. 10 is a flowchart illustrating an embodiment for transmitting a grouping ID.
[0194] Referring to FIG. 10, a user device (1010) and a reader (1020) can perform a transaction procedure. The user device (1010) can generate a grouping ID. In the transaction procedure, the user device (1010) can send an AUTH1 response to the reader (1020) (S1011). The AUTH1 response may include a connection credential ID. After sending the AUTH1 to the reader, the user device (1010) can generate a kpersistent. The reader (1020) can receive the AUTH1 response sent by the user device (1010). After receiving the AUTH1 from the user device, the reader (1020) can generate a kpersistent.
[0195] In a transaction procedure, the user device (1010) can transmit an exchange response to the reader (1020) (S1013). The exchange response may include a grouping ID. The reader (1020) can receive the exchange response transmitted by the user device (1010).
[0196] In a transaction procedure, the user device (1010) can send a GET response to the reader (1020) (S1015). The GET response may include a grouping ID. The reader (1020) can receive the GET response sent by the user device (1010).
[0197] The grouping ID can be transmitted and received by a transaction procedure between the user device and the reader. The value of Table 4 can be transmitted to the reader (1020) via at least one of an AUTH1 response, an EXCHANGE response, or a GET response. The reader (1020) can store the grouping ID received from the user device (1010) by concatenating it with the Kpersistent generated in AUTH1.
[0198] A user device (1010) can generate a kpersistent. When the user device (1010) generates a value of the kpersistent, it can associate a grouping ID with the kpersistent. A reader (1020) can generate a kpersistent. When the reader (1020) generates a value of the kpersistent, it can associate a grouping ID with the kpersistent. A second kpersistent may include a kpersistent generated by the reader (1020). A second kpersistent may include a kpersistent stored in the reader (1020).
[0199] A user device may receive a matching ID from a credential issuer server to identify a cryptogram matching value (kpersistent). The user device may map the matching ID to a reader group sub ID assigned to the user device. In other words, the user device may map a first matching ID to a reader group sub ID assigned to the user device. The user device may receive an authentication command (AUTH0 command) from a reader that includes a temporary public key (Reader.ePK) and a reader ID generated for each transaction. The user device may encrypt the matching ID using the temporary public key (Reader.ePK). The user device may include the step of transmitting an authentication response (AUTH0 response) to the reader that includes a cryptogram associated with an encrypted matching ID and a reader group sub-ID.
[0200] A matching ID may include at least one of an access credential identifier for identifying a single cryptogram matching value (kpersistent) or a grouping ID for identifying at least two cryptogram matching values (kpersistents). In other words, the first matching ID may include at least one of an access credential identifier for identifying a single cryptogram matching value (kpersistent) or a grouping ID for identifying at least two cryptogram matching values (kpersistents).
[0201] A cryptogram may include a payload encrypted using a private key (CryptogramSK). In other words, a first cryptogram may include a payload encrypted using a private key (CryptogramSK). A user device may generate a cryptogram matching value (kpersistent) capable of deriving the private key (CryptogramSK).
[0202] The reader ID may include a reader group sub ID and a reader group ID.
[0203] A reader may receive a second matching ID from a credential issuer server to identify a cryptogram matching value (kpersistent). The reader may send an authentication command (AUTH0 command) to a user device that includes a temporary public key (Reader.ePK) generated for each transaction and a reader ID. The reader may receive an authentication response (AUTH0 response) from the user device that includes a first matching ID and a cryptogram encrypted using the temporary public key (Reader.ePK). If the first matching ID and the second matching ID match, the reader may verify the cryptogram matching value (kpersistent) corresponding to the second matching ID. The reader may include a step of verifying the cryptogram using the cryptogram matching value (kpersistent).
[0204] Each of the first matching ID and the second matching ID may include at least one of an access credential identifier for identifying one cryptogram matching value (kpersistent) or a grouping ID for identifying at least two cryptogram matching values (kpersistents).
[0205] A cryptogram can contain a payload encrypted using a private key (CryptogramSK).
[0206] To verify the cryptogram, the reader can derive a private key (CryptogramSK) using the cryptogram matching value (kpersistent). To verify the cryptogram, the reader can decrypt the payload contained in the cryptogram using the derived private key (CryptogramSK).
[0207] The reader ID may include a reader group sub ID and a reader group ID.
[0208] A user device may include a transceiver and a control unit. The control unit of the user device may receive a matching ID from a credential issuer server to identify a cryptogram matching value (kpersistent). The control unit of the user device may map the matching ID to a reader group sub ID assigned to the user device. The control unit of the user device may receive an authentication command (AUTH0 command) from a reader that includes a temporary public key (Reader.ePK) and a reader ID generated for each transaction. The control unit of the user device may encrypt the matching ID using the temporary public key (Reader.ePK). The control unit of the user device may be configured to transmit an authentication response (AUTH0 response) to the reader that includes a cryptogram associated with the encrypted matching ID and the reader group sub ID.
[0209] The matching ID may include at least one of an access credential identifier for identifying one cryptogram matching value (kpersistent) or a grouping ID for identifying at least two cryptogram matching values (kpersistents).
[0210] A cryptogram may contain a payload encrypted using a private key (CryptogramSK). A user device may generate a cryptogram matching value (kpersistent) capable of deriving the private key (CryptogramSK).
[0211] A reader may include a transmitting / receiving unit and a control unit. The control unit of the reader may receive a second matching ID from a credential issuer server for identifying a cryptogram matching value (kpersistent). The control unit of the reader may transmit an authentication command (AUTH0 command) to a user device that includes a temporary public key (Reader.ePK) generated for each transaction and a reader ID. The control unit of the reader may receive an authentication response (AUTH0 response) from the user device that includes a first matching ID and a cryptogram encrypted using the temporary public key (Reader.ePK). If the first matching ID and the second matching ID match, the control unit of the reader may verify the cryptogram matching value (kpersistent) corresponding to the second matching ID. The control unit of the reader may be configured to include a step of verifying a cryptogram using a cryptogram matching value (kpersistent).
[0212] Each of the first matching ID and the second matching ID may include at least one of an access credential identifier for identifying one cryptogram matching value (kpersistent) or a grouping ID for identifying at least two cryptogram matching values (kpersistents).
[0213] A cryptogram may include a payload encrypted using a private key (CryptogramSK). In other words, a first cryptogram may include a payload encrypted using a private key (CryptogramSK).
[0214] FIG. 11 is a block diagram illustrating a user device according to one embodiment of the present disclosure.
[0215] Referring to FIG. 11, the user device (1101) exemplified in FIG. 9 may be the user device exemplified in the present disclosure. The user device (1101) may include at least one of a transceiver (1102), a processor (1103), or a memory (1104). The transceiver (1102) of the user device may refer to a transceiver that performs signal transmission and reception with other user devices, UEs, or network entities. The transceiver (1102) may support 5G networks following 4G networks and next-generation communication technologies, for example, new radio access technology (NR access technology). NR access technology may support high-speed transmission of high-capacity data (enhanced mobile broadband (eMBB)), minimization of terminal power and connection of multiple terminals (massive machine type communications (mMTC)), or high reliability and low latency (ultra-reliable and low-latency communications (URLLC)). The transceiver (1102) may support a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate, for example. The transceiver (1102) may support various technologies for securing performance in the high-frequency band, for example, beamforming, massive MIMO (multiple-input and multiple-output), full-dimensional MIMO (FD-MIMO), array antenna, analog beamforming, or large-scale antenna. The transceiver (1102) may also be referred to as a transceiver or a communication module.
[0216] The processor (1103) of the user device may also be referred to as a control unit or a controller. The processor (1103) of the user device may include at least one processor that controls at least one operation of the user device (1101). All operations or methods in the user device described above in this disclosure may be understood as being performed under the control of said processor (1103).
[0217] The memory (1103) can store various data used by at least one component of the user device (1101) (e.g., processor (1103) or transceiver (1102)). The data may include, for example, input data or output data for software and related commands. The memory (1103) may include volatile memory and / or non-volatile memory.
[0218] The processor (1103), the transceiver (1102), and the memory (1104) do not necessarily have to be implemented as separate devices, and can, of course, be implemented as a single component in the form of a single chip. The control unit can be implemented as a single processor within the user device (1101).
[0219] FIG. 12 is a block diagram illustrating a reader according to one embodiment of the present disclosure.
[0220] Referring to FIG. 12, the reader (1201) may include at least one of a transceiver (1202), a processor (1203), and a memory (1204). The reader (1201) may include at least one of a transceiver (1202), a processor (1203), or a memory (1204). The transceiver (1202) of the user device may refer to a transceiver that performs signal transmission and reception with other user devices, UEs, or network entities. The transceiver (1202) may support 5G networks and next-generation communication technologies following 4G networks, for example, new radio access technology. NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The transceiver (1202) can support a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate, for example. The transceiver (1202) can support various technologies for securing performance in the high-frequency band, for example, beamforming, massive MIMO (multiple-input and multiple-output), full-dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large-scale antenna. The transmitting and receiving unit (1202) may also be referred to as a transceiver or a communication module.
[0221] The processor (1203) of the user device may also be referred to as a control unit or a controller. The processor (1203) of the user device may include at least one processor that controls at least one operation of the reader (1201). All operations or methods in the user device described above in this disclosure may be understood as being performed under the control of said processor (1203).
[0222] The memory (1203) can store various data used by at least one component of the reader (1201) (e.g., processor (1203) or transceiver (1202)). The data may include, for example, input data or output data for software and related commands. The memory (1203) may include volatile memory and / or non-volatile memory.
[0223] The processor (1203), the transceiver (1202), and the memory (1204) do not necessarily have to be implemented as separate devices, and can, of course, be implemented as a single component in the form of a single chip. The control unit can be implemented as a single processor within the reader (1201).
[0224] It should be noted that the system configuration diagrams, method example diagrams, device configuration diagrams, etc., illustrated in FIGS. 1 to 12 above are not intended to limit the scope of the rights of the present disclosure. That is, all configurations or operations described in FIGS. 1 to 9 above should not be interpreted as essential components for the implementation of the present disclosure, and may be implemented within a scope that does not impair the essence of the present disclosure even if only some components are included.
[0225] Methods according to the claims or embodiments described in the specification of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.
[0226] When implemented in software, a computer-readable storage medium may be provided for storing one or more programs (software modules). One or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. One or more programs may include instructions that cause the electronic device to execute methods according to the claims or embodiments described in the specification of this disclosure.
[0227] Such programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, ROM (Read Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), magnetic disc storage devices, CD-ROM (Compact Disc-ROM), Digital Versatile Discs (DVDs), or other forms of optical storage devices, magnetic cassettes. Alternatively, they may be stored in memory composed of some or all of these. Additionally, each constituent memory may include multiple units.
[0228] Additionally, the program may be stored on an attachable storage device accessible via a communication network such as the Internet, Intranet, Local Area Network (LAN), Wide LAN (WLAN), or Storage Area Network (SAN), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure through an external port. Additionally, a separate storage device on a communication network may be connected to a device performing an embodiment of the present disclosure.
[0229] In the specific embodiments of the present disclosure described above, the components included in the present disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.
[0230] Meanwhile, although specific embodiments have been described in the detailed description of the present disclosure, it is understood that various modifications are possible within the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims set forth below as well as equivalents thereof.
Claims
1. In a method of a user device, A step of receiving a matching ID from a credential issuer server to identify a cryptogram matching value (kpersistent); A step of mapping the above matching ID to a reader group sub ID assigned to the user device; A step of receiving an authentication command (AUTH0 command) from a reader that includes a temporary public key (Reader.ePK) and a reader ID generated for each transaction; A step of encrypting the above matching ID using the above temporary public key (Reader.ePK); and A method comprising the step of transmitting an authentication response (AUTH0 response) to the reader, the response including an encrypted matching ID and a cryptogram associated with the reader group sub-ID.
2. In Paragraph 1, The above matching ID is, A method comprising at least one of an access credential identifier for identifying one cryptogram matching value (kpersistent) or a grouping ID for identifying at least two cryptogram matching values (kpersistents).
3. In Paragraph 1, The above cryptogram includes a payload encrypted using a private key (CryptogramSK), and The above user device is a method for generating the cryptogram matching value (kpersistent) capable of deriving the private key (CryptogramSK).
4. In Paragraph 1, The above reader ID is, A method including the above-mentioned reader group sub ID and reader group ID.
5. Regarding the method of the reader, A step of receiving a second matching ID from a credential issuer server to identify a cryptogram matching value (kpersistent); A step of transmitting an authentication command (AUTH0 command) to a user device that includes a temporary public key (Reader.ePK) and a reader ID generated for each transaction; A step of receiving an authentication response (AUTH0 response) from the user device that includes a first matching ID and a cryptogram encrypted using the above temporary public key (Reader.ePK); If the first matching ID and the second matching ID match, a step of verifying the cryptogram matching value (kpersistent) corresponding to the second matching ID; and A method comprising the step of verifying the cryptogram using the cryptogram matching value (kpersistent).
6. In paragraph 5, each of the first matching ID and the second matching ID is, A method comprising at least one of an access credential identifier for identifying one cryptogram matching value (kpersistent) or a grouping ID for identifying at least two cryptogram matching values (kpersistents).
7. In Paragraph 5, A method in which the above cryptogram includes a payload encrypted using a private key (CryptogramSK).
8. In claim 7, the step of verifying the cryptogram is, A step of deriving the private key (CryptogramSK) using the cryptogram matching value (kpersistent); and A method comprising the step of decrypting the payload contained in the cryptogram using the derived private key (Cryptogram SK).
9. In paragraph 5, the above reader ID is, A method including a reader group sub ID and a reader group ID.
10. In a user device, Transmitter / receiver; and It includes a control unit, and the control unit, Receive a matching ID from a credential issuer server to identify a cryptogram matching value (kpersistent), and The above matching ID is mapped to a reader group sub ID assigned to the user device, and Receive an authentication command (AUTH0 command) from the reader that includes a temporary public key (Reader.ePK) and a reader ID generated for each transaction, and The above matching ID is encrypted using the above temporary public key (Reader.ePK), and Configured to transmit an authentication response (AUTH0 response) to the reader, the response including an encrypted matching ID and a cryptogram associated with the reader group sub-ID. device.
11. In Paragraph 10, The above matching ID is, including at least one of an access credential identifier for identifying one cryptogram matching value (kpersistent) or a grouping ID for identifying at least two cryptogram matching values (kpersistents), device.
12. In Paragraph 10, The above cryptogram includes a payload encrypted using a private key (CryptogramSK), and The user device generates the cryptogram matching value (kpersistent) capable of deriving the private key (CryptogramSK), device.
13. Regarding readers, Transmitter / receiver; and It includes a control unit, and the control unit, A second matching ID for identifying a cryptogram matching value (kpersistent) is received from a credential issuer server, and Send an authentication command (AUTH0 command) containing a temporary public key (Reader.ePK) and a reader ID generated for each transaction to the user device, and Receive an authentication response (AUTH0 response) from the user device that includes a first matching ID and a cryptogram encrypted using the above temporary public key (Reader.ePK), and If the first matching ID and the second matching ID match, check the cryptogram matching value (kpersistent) corresponding to the second matching ID, and A method configured to include a step of verifying the cryptogram using the cryptogram matching value (kpersistent). device.
14. In Paragraph 13, Each of the above first matching ID and the above second matching ID is, Includes at least one of an access credential identifier for identifying one cryptogram matching value (kpersistent) or a grouping ID for identifying at least two cryptogram matching values (kpersistents). device.
15. In Paragraph 13, The above cryptogram is, A payload containing an encrypted payload using a private key (CryptogramSK), device.
Citation Information
Patent Citations
Display device
KR1020240083005A
Dryer
KR1020260031940A
Digital key service method and system thereof
KR102175408B1
Secure authentication of user and mobile device
US10116447B2
Authentication apparatus based on public key cryptosystem, mobile device having the same and authentication method
US11070380B2