Local Bundle Assistant Certificate Negotiation in 5G IoT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in effectively managing and installing valid certificates and certificate issuer information in 5G communication systems, particularly for IoT networks, which are crucial for secure data transmission and device authentication.

Innovation Solution

A method and apparatus that enable a local bundle assistant (LBA) to negotiate certificates with a secondary platform bundle manager (SPBM) in a wireless communication system, involving the transmission and reception of certificate information and public key identifiers to establish secure key agreements and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificates and certificate issuer information are managed and installed in 5G communication systems for IoT networks, then security and authentication reliability is improved, but device complexity and management overhead increases

Engineering Contradiction:
Improvesecurity and authentication reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a bundle manager as an intermediary component that centralizes the management of certificates and certificate issuer information. This mediator handles the complex tasks of certificate installation, validation, and updates, thereby improving security reliability while shielding individual devices from the complexity of cryptographic management. The bundle manager coordinates between certificate authorities, devices, and security modules, resolving the contradiction by centralizing control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the certificate management system into distinct functional components: certificate issuance by authorities, bundle creation by the bundle manager, certificate installation by devices, and validation by security modules. This segmentation allows each component to specialize in specific tasks, improving overall system reliability while reducing the complexity burden on individual devices by distributing management responsibilities across the architecture.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple certificates and certificate issuers are negotiated and managed between LBA and SPBM, then authentication capability and security service versatility is improved, but information management complexity increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidinformation management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The bundle manager is designed as a universal component that can negotiate and manage multiple types of certificates from different certificate issuers. It provides multi-functional capabilities including certificate selection, validation, installation, and updates across various 5G IoT scenarios. This universality enables the system to support diverse authentication requirements and security services while the bundle manager handles the underlying information management complexity centrally, reducing the burden on individual devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure key agreement and authentication are established through certificate negotiation, then data transmission security is improved, but communication overhead and time consumption increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the bundle manager negotiate and install certificates and certificate issuer information before actual data transmission occurs. This advance preparation ensures that security credentials are already in place and validated, so when secure communication is needed, the key agreement and authentication processes can proceed efficiently without delays. The preliminary certificate installation resolves the contradiction by trading initial setup time for faster subsequent secure communications.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12238515B2Apparatus and method for SSP device and server to negotiate digital certificates
Publication Date: 2025.02.25 SAMSUNG ELECTRONICS CO LTD
  • US12238515B2 patent drawing
  • US12238515B2 patent drawing
  • US12238515B2 patent drawing

AI summary

A method of a local bundle assistant (LBA) negotiating a certificate with a secondary platform bundle manager (SPBM) in a wireless communication system including: transmitting a request message requesting information of certificates supported by a secondary secure platform (SSP) to a secondary platform bundle loader (SPBL) of the SSP; receiving the information of certificates supported by the SSP including information of certificate issuers corresponding to a family identifier from the SPBL; transmitting the information of certificates supported by the SSP to the SPBM; and receiving a certificate of the SPBM for key agreement, information of public key identifiers of certificate issuers to be used by the SSP, and information of the family identifier from the SPBM.