Method and electronic device for managing digital keys

US11563730B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11563730-B2
Application numberUS-202017113969-A
CountryUS
Kind codeB2
Filing dateDec 7, 2020
Priority dateDec 6, 2019
Publication dateJan 24, 2023
Grant dateJan 24, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Provided is a method, performed by an electronic device, of managing keys for accessing a plurality of services in an integrated manner to improve interoperability and secure security. The method includes transmitting, by a secure domain (SD) in a secure area of the electronic device, a certificate of the SD to a plurality of service providers (SPs); receiving, by an application installed in the electronic device, a certificate of each of the plurality of SPs from the plurality of SPs; receiving, by the application, first signed data from a first SP among the plurality of SPs; authenticating, by the application, the first signed data by using a certificate of the first SP received from the first SP and obtaining an encrypted key of the first SP from the first signed data; decrypting, by the SD, the encrypted key of the first SP by using a private key of the SD; and storing the decrypted key of the first SP in a first instance corresponding to the first SP among a plurality of instances of the SD.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, performed by an electronic device, of managing keys for accessing a plurality of services, the method comprising: transmitting, by a secure domain (SD) in a secure area of the electronic device, a certificate of the SD to a plurality of service providers (SPs); receiving, by an application installed in the electronic device, a certificate of each of the plurality of SPs from the plurality of SPs; receiving, by the application, first signed data from a first SP among the plurality of SPs; authenticating, by the application, the first signed data by using a certificate of the first SP received from the first SP and obtaining an encrypted key of the first SP from the first signed data; decrypting, by the SD, the encrypted key of the first SP by using a private key of the SD; and storing the decrypted key of the first SP in a first instance corresponding to the first SP among a plurality of instances of the SD. 2. The method of claim 1 , further comprising generating, by the application, the plurality of instances of the SD corresponding to the plurality of SPs. 3. The method of claim 2 , wherein generating the plurality of instances comprises: installing, by the application, the SD in the secure area, based on information received from a secure area issuer; and generating the plurality of instances by instantiating the SD. 4. The method of claim 1 , wherein the certificate of the SD comprises a public key of the SD, wherein the certificate of each of the plurality of SPs comprises a public key of each of the plurality of SPs, and wherein the key of the first SP is a symmetric key for the first SP to use to provide an access service through a secure channel. 5. The method of claim 1 , wherein the first signed data received from the first SP comprises: the key of the first SP encrypted using a public key of the SD; and a signature using a private key of the first SP. 6. The method of claim 1 , wherein obtaining the encrypted key of the first SP from the first signed data comprises authenticating the first signed data by using a public key of the first SP. 7. The method of claim 1 , further comprising: receiving, by the application, second signed data from a second SP among the plurality of SPs; authenticating, by the application, the second signed data by using a certificate of the second SP received from the second SP and obtaining an encrypted key of the second SP from the second signed data; decrypting, by the SD, the encrypted key of the second SP by using the private key of the SD; and storing the decrypted key of the second SP in a second instance corresponding to the second SP among the plurality of instances of the SD. 8. The method of claim 1 , further comprising: performing mutual authentication between a first device providing an access service related to the first SP and the first instance by using the key of the first SP stored in the first instance, and setting up a secure channel; generating, by the first instance, a session key by using the key of the first SP, and transmitting the session key to the first device through the secure channel; generating an ultra-wide band (UWB) session key by using the session key; and performing ranging by transmitting or receiving a ranging frame including a scrambled timestamp sequence (STS) code generated using the UWB session key. 9. The method of claim 8 , wherein setting up the secure channel comprises setting up the secure channel by using a Bluetooth communication method, and wherein performing the ranging comprises transmitting or receiving the ranging frame by using a UWB communication method. 10. The method of claim 1 , further comprising: performing mutual authentication between a first device providing an access service related to the first SP and the first instance by using the key of the first SP stored in the first instance, and setting up a secure channel; generating, by the first instance, a session key by using the key of the first SP, and transmitting the session key to the first device through the secure channel; receiving an ultra-wide band (UWB) session key through the secure channel; and performing ranging by transmitting or receiving a ranging frame including a scrambled timestamp sequence (STS) code generated using the UWB session key. 11. An electronic device comprising: a secure area configured to store keys for the electronic device to access a plurality of services; and a processor connected to the secure area, wherein a secure domain installed in the secure area is configured to transmit a certificate of the secure domain to a plurality of service providers (SPs), wherein the processor is configured to control an application installed in the electronic device to: receive a certificate of each of the plurality of SPs from the plurality of SPs; receive first signed data from a first SP among the plurality of SPs; and authenticate the first signed data by using a certificate of the first SP received from the first SP and obtain an encrypted key of the first SP from the first signed data, and wherein the secure domain installed in the secure area is further configured to: decrypt the encrypted key of the first SP by using a private key of the secure domain, and store the decrypted key of the first SP in a first instance corresponding to the first SP among a plurality of instances of the secure domain. 12. The electronic device of claim 11 , wherein the processor is further configured to control the application to generate the plurality of instances of the secure domain corresponding to the plurality of SPs. 13. The electronic device of claim 12 , wherein the processor is further configured to control the application to: install the secure domain in the secure area, based on information received from a secure area issuer, and generate the plurality of instances by instantiating the secure domain. 14. The electronic device of claim 11 , wherein the certificate of the secure domain comprises a public key of the secure domain, wherein the certificate of each of the plurality of SPs comprises a public key of each of the plurality of SPs, and wherein the key of the first SP is a symmetric key for the first SP to use to provide an access service through a secure channel. 15. The electronic device of claim 11 , wherein the first signed data received from the first SP comprises the key of the first SP encrypted using a public key of the secure domain and a signature using a private key of the first SP. 16. The electronic device of claim 11 , wherein the processor is further configured to control the application to authenticate the first signed data by using a public key of the first SP to obtain the encrypted key of the first SP from the first signed data. 17. The electronic device of claim 11 , wherein the processor is further configured to control the application to: receive second signed data from a second SP among the plurality of SPs, authenticate the second signed data by using a certificate of the second SP received from the second SP, and obtain an encrypted key of the second SP from the second signed data, and wherein the secure domain installed in the secure area is further configured to: decrypt the encrypted key of the second SP by using the private key of the secure domain, and store the decrypted key of the second SP in a second instance corresponding to the second SP among the plurality of instances of the secure domain. 18. The electronic device of claim 11 , wherein the fir

Assignees

Inventors

Classifications

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

  • wherein the sending and receiving network entities apply hybrid encryption, i.e. combination of symmetric and asymmetric encryption (cryptographic mechanisms or cryptographic arrangements using a plurality of keys or algorithms H04L9/14) · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11563730B2 cover?
Provided is a method, performed by an electronic device, of managing keys for accessing a plurality of services in an integrated manner to improve interoperability and secure security. The method includes transmitting, by a secure domain (SD) in a secure area of the electronic device, a certificate of the SD to a plurality of service providers (SPs); receiving, by an application installed in th…
Who is the assignee on this patent?
Samsung Electronics Co Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/0823. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 24 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 11 related publications on this page (citations in our corpus or others sharing the same primary CPC).