Applet Distribution via Stakeholder Certification and Encrypted Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for distributing applets in secure environments do not provide mechanisms for stakeholders to obtain revenue and lack access control configuration, leading to underutilization of secure hardware and increased collaboration costs between developers and OS vendors.
Innovation Solution
A method where a stakeholder certifies applets, generates an applet key, and issues an encrypted token to a host for installation in a secure environment, allowing the secure environment to configure access control without sharing the secure environment key, enabling stakeholders to control access and revenue generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the ObC approach is used for applet distribution, then applets can be installed in secure environments, but stakeholders cannot obtain revenue and lack control over access
Solution Approach 1:
The patent applies preliminary action by requiring stakeholders to pre-certify applets and pre-configure access control policies before distribution. The stakeholder certifies the applet and creates an access control policy that specifies which applications can access the applet, establishing control mechanisms in advance rather than allowing unrestricted installation as in ObC
Solution Approach 2:
The patent introduces a stakeholder as an intermediary between the applet developer and the secure environment. The stakeholder acts as a mediator that controls the distribution process, issues certificates, and manages access policies, preventing direct unrestricted access that would eliminate revenue opportunities
2Reliability
If OS vendors control access to secure code, then security is maintained, but developers face additional collaboration costs and reduced flexibility
Solution Approach 1:
The patent extracts access control functionality from the OS vendor domain and places it in the stakeholder domain. Instead of requiring OS vendors to configure and manage access control policies for each applet, the stakeholder independently manages access control, separating these responsibilities and reducing collaboration complexity
Solution Approach 2:
The stakeholder assumes multiple roles including applet certification, access control policy management, and distribution coordination, making the stakeholder a universal authority that handles previously分散 responsibilities across multiple parties
3Ease of operation
If secure environment keys are shared for applet installation, then installation is simplified, but security control is reduced
Solution Approach 1:
The patent applies local quality by providing different levels of access control to different applications. The access control policy specifies which applications can access which applets, creating localized security permissions rather than universal access, maintaining security while enabling controlled distribution
Data Source
Figure 1~2
AI summary
The application discloses a method and a system, as well as entities for distributing applets. In one embodiment, the method includes certifying an applet, a, by a stakeholder, S, by (a) submitting, by a developer, D, the applet, a, and an applet policy, P, to the stakeholder, S, for certification; (b) generating, by the stakeholder, an applet key, Ka, certifying the applet, and storing the applet key, Ka, and the certified applet, ea; and installing the applet in a secure environment, E, connectable to a host, H, by (a) sending, by the host, a secure environment identifier, idE, and an applet identifier, ida, to the stakeholder and requesting, by the host, a token, Ta, from the stakeholder, wherein the token is encrypted using a secure environment key, KE, and the encrypted token includes at least the applet key; (b) receiving the token, by the host; (c) sending, by the host, the certified applet and the token to the secure environment; (d) installing, by the secure environment, the certified applet in the secure environment using information extracted from the token.