Smart Secure Platform Certificate Verification for 5G IoT
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a demand for efficient methods and apparatuses to select and verify valid certificates and certificate issuer information during the download and installation of bundles between a terminal and a server in wireless communication systems, particularly in the context of 5G communication systems and IoT environments.
Innovation Solution
A smart secure platform (SSP) is provided with a method for remotely installing a control module in an electronic device, enabling the selection and verification of certificates using a secondary platform bundle family identifier and custodian identifier, ensuring secure communication through mutual authentication and encryption between a terminal and a secondary platform bundle manager.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate verification is performed for each bundle download, then security and reliability are improved, but processing time and system complexity increase
Solution Approach 1:
The system performs preliminary actions by pre-establishing a trusted certificate authority (CA) hierarchy and pre-validating bundle manager certificates before actual bundle downloads occur. The terminal stores verified CA certificates and bundle manager certificates in advance, enabling rapid verification during subsequent bundle operations without repeated time-consuming validation processes.
Solution Approach 2:
The patent introduces a bundle manager as an intermediary entity that handles certificate verification on behalf of the terminal. The bundle manager receives bundles from servers, verifies their certificates against trusted CAs, and only transfers verified bundles to the terminal. This intermediary approach shifts the verification burden from the terminal to a dedicated service, reducing terminal processing time while maintaining security.
2Adaptability or versatility
If multiple certificates are managed for different bundle types, then adaptability is improved, but device complexity increases
Solution Approach 1:
The patent segments certificate management by separating different certificate types into distinct categories: root CA certificates, intermediate CA certificates, and bundle manager certificates. Each segment is managed independently with specific storage locations and verification procedures. This segmentation allows the system to handle multiple certificate types for different bundle types (e.g., software bundles, security patches) without creating a monolithic complex management system.
Solution Approach 2:
The patent implements a universal certificate verification framework that can handle multiple bundle types through a common CA hierarchy. The same trusted CA certificates and verification algorithms serve multiple purposes across different bundle types (software updates, security patches, configuration files). This multi-functional approach enables adaptability to various bundle formats while avoiding the need for separate verification systems for each type.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of managing and verifying a certificate of a terminal is provided. The method includes obtaining certificate information that is usable when downloading and installing a specific bundle corresponding to at least one of a secondary platform bundle family identifier or a secondary platform bundle family custodian identifier, transmitting, to a secondary platform bundle manager, the certificate information corresponding to the at least one of the secondary platform bundle family identifier or the secondary platform bundle family custodian identifier of the specific bundle, and receiving, from the secondary platform bundle manager, at least one of a certificate of the secondary platform bundle manager, certificate information to be used by a smart secure platform (SSP), the secondary platform bundle family identifier, or the secondary platform bundle family custodian identifier.