Remote Security Module Management With LBA Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a method and device that allows a terminal to select and verify a certificate issuer and a valid certificate for remotely managing security services, particularly in the context of 5G communication systems and IoT networks, to efficiently provide various services such as mobile communication and machine-to-machine communication.

Innovation Solution

A method and device utilizing a Local Bundle Assistant (LBA) and a Secondary Platform Bundle Loader (SPBL) to manage and verify remote management certificates, enabling the selection and installation of security service modules and bundles on terminals, including certificate verification and management through a security service module management server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a terminal remotely installs and manages security service modules without certificate verification, then the ease of operation is improved, but the reliability deteriorates due to security risks

Engineering Contradiction:
Improveease of remote managementVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a certificate authority (CA) and certificate verification mechanism as an intermediary between the terminal and the security service module management server. The terminal obtains and verifies certificates issued by the CA to authenticate the server's identity, ensuring secure remote management operations without requiring manual intervention for each security-critical action.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a terminal implements comprehensive certificate verification for remote management, then the reliability is improved, but the device complexity increases due to additional verification steps

Engineering Contradiction:
Improvesecurity verification reliabilityVSAvoidcomplexity of verification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the terminal with certificate authority information and establishing certificate verification mechanisms before remote management operations begin. The terminal proactively obtains certificates from the CA and sets up verification routines in advance, so that when remote management commands are received, the verification process is already in place and can operate automatically without adding complexity to the user interface or operational流程.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a terminal selects and verifies multiple certificate issuer information, then the reliability is improved through better authentication, but the loss of time increases due to additional verification steps

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidtime for certificate verification
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The terminal performs preliminary actions by pre-obtaining and caching certificate information from trusted certificate authorities during device initialization or before anticipated remote management operations. This allows the terminal to have verification data ready in advance, reducing the time required during actual remote management operations while maintaining high authentication reliability through multiple certificate issuer verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4094401B1Method and device for remote management and verification of remote management authority
Publication Date: 2025.07.02 SAMSUNG ELECTRONICS CO LTD
  • EP4094401B1 patent drawingFigure 1
  • EP4094401B1 patent drawingFigure 2
  • EP4094401B1 patent drawingFigure 3

AI summary

The present disclosure relates a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. A method for remote management and remote management authority verification by a terminal includes: receiving a remote management instruction package; obtaining certificate information configured for a security module, which may be used when remotely managing a security service module corresponding to at least one identifier among a plurality of identifiers; and verifying a remote security service module management certificate of a bundle management server and the remote management instruction package by using the obtained certificate information.