Smart Secure Platform Certificate Verification for 5G IoT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a demand for efficient methods and apparatuses to select and verify valid certificates and certificate issuer information during the download and installation of bundles between a terminal and a server in wireless communication systems, particularly in the context of 5G communication systems and IoT environments.

Innovation Solution

A smart secure platform (SSP) is provided with a method for remotely installing a control module in an electronic device, enabling the selection and verification of certificates using a secondary platform bundle family identifier and custodian identifier, ensuring secure communication through mutual authentication and encryption between a terminal and a secondary platform bundle manager.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate verification is performed for each bundle download, then security and reliability are improved, but processing time and system complexity increase

Engineering Contradiction:
Improvecertificate validityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing a trusted certificate authority (CA) hierarchy and pre-validating bundle manager certificates before actual bundle downloads occur. The terminal stores verified CA certificates and bundle manager certificates in advance, enabling rapid verification during subsequent bundle operations without repeated time-consuming validation processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a bundle manager as an intermediary entity that handles certificate verification on behalf of the terminal. The bundle manager receives bundles from servers, verifies their certificates against trusted CAs, and only transfers verified bundles to the terminal. This intermediary approach shifts the verification burden from the terminal to a dedicated service, reducing terminal processing time while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple certificates are managed for different bundle types, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvebundle compatibilityVSAvoidcertificate management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments certificate management by separating different certificate types into distinct categories: root CA certificates, intermediate CA certificates, and bundle manager certificates. Each segment is managed independently with specific storage locations and verification procedures. This segmentation allows the system to handle multiple certificate types for different bundle types (e.g., software bundles, security patches) without creating a monolithic complex management system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal certificate verification framework that can handle multiple bundle types through a common CA hierarchy. The same trusted CA certificates and verification algorithms serve multiple purposes across different bundle types (software updates, security patches, configuration files). This multi-functional approach enables adaptability to various bundle formats while avoiding the need for separate verification systems for each type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3906637B1Method and apparatus for managing and verifying certificate
Publication Date: 2024.11.06 SAMSUNG ELECTRONICS CO LTD
  • EP3906637B1 patent drawingFigure 1
  • EP3906637B1 patent drawingFigure 2
  • EP3906637B1 patent drawingFigure 3

AI summary

A method of managing and verifying a certificate of a terminal is provided. The method includes obtaining certificate information that is usable when downloading and installing a specific bundle corresponding to at least one of a secondary platform bundle family identifier or a secondary platform bundle family custodian identifier, transmitting, to a secondary platform bundle manager, the certificate information corresponding to the at least one of the secondary platform bundle family identifier or the secondary platform bundle family custodian identifier of the specific bundle, and receiving, from the secondary platform bundle manager, at least one of a certificate of the secondary platform bundle manager, certificate information to be used by a smart secure platform (SSP), the secondary platform bundle family identifier, or the secondary platform bundle family custodian identifier.