Efficient key generator for distribution of sensitive material from mulitple application service providers to a secure element such as a universal integrated circuit card (uicc)
Abstract
A method provides end-to-end security for transport of a profile to a target device (e.g., a mobile computing device) over at least one communications network that includes a plurality of nodes. In accordance with the method, the profile is encrypted for transport between the target device and an initial node of the network through which the profile is transported. The encryption is an end-to-end inner layer encryption performed prior to hop-to-hop encryption. The encrypting uses a public key of a public, private key pair. The private key is derivable from a seed securely provisioned in the target device using a public key algorithm. The encrypted profile is transmitted over the communications network to the target device.
Claims
exact text as granted — not AI-modified1 . A method for providing end-to-end security for transport of a profile to a target device over at least one communications network that includes a plurality of nodes, the method comprising:
encrypting the profile between the target device and an initial node of the network through which the profile is transported, the encryption being an end-to-end inner layer encryption performed prior to hop-to-hop encryption, the encrypting using a public key of a public, private key pair, the private key being derivable from a seed securely provisioned in the target device using a public key algorithm; and causing the encrypted profile to be transmitted over the at least one communications network to the target device.
2 . The method of claim 1 wherein the seed is unique to a secure element located in the target device.
3 . The method of claim 1 wherein the public key algorithm is based on Elliptic Curve Cryptography (ECC), the public key being derivable from the private key and an ECC curve.
4 . The method of claim 2 wherein the private key is derivable from the seed and an identifier associated with a manufacturer or vendor of the secure element.
5 . The method of claim 1 wherein the seed is common to particular population of secure elements.
6 . The method of claim 3 wherein the public key algorithm is implemented using hardware.
7 . The method of claim 4 further comprising maintaining in secret a list of public keys that includes the public key of the public, private key pair, the list of public keys being received by a service provider delivering at least one service to a plurality of target devices in which a plurality of secure elements are respectively located, the list of public keys being received from the manufacturer or vendor of the plurality of secure elements.
8 . The method of claim 7 wherein the list of public keys is digitally signed by the manufacturer or vendor.
9 . The method of claim 1 further comprising:
generating an ECC key pair associated with a service provider delivering at least one service to the target device;
using an ECC private key in the ECC key pair and the public key of the public, private key pair to perform a local Diffie-Hellman (DH) exchange to create a profile encryption key that is used to encrypt the profile.
10 . The method of claim 9 wherein the ECC key pair is unique to a particular population of secure elements respectively located in a population of target devices.
11 . The method of claim 9 wherein the ECC public key in the ECC key pair is pre-provisioned in the target device.
12 . The method of claim 9 wherein the ECC public key in the ECC key pair is transmitted to the target device along with the encrypted profile.
13 . The method of claim 1 wherein the public key algorithm is based on a DH algorithm.
14 . The method of claim 1 further comprising:
receiving a request for the profile from the target device, the request including a nonce;
encrypting the nonce with the profile; and
causing the encrypted profile and the encrypted nonce to be transmitted over the at least one communications network to the target device.
15 . The method of claim 1 wherein the encrypted profile includes a timestamp or a sequence number.
16 . The method of claim 1 wherein the profile is encrypted by a mobile network provider and the seed is located in a secure element in the target device.
17 . The method of claim 16 wherein the secure element is a Universal Integrated Circuit Card (UICC).
18 . A computer readable storage medium encoded with computer executable instructions which, when executed by a processor, performs a method for decrypting a profile transmitted to a target device in a secure manner by a service provider over a communications network, comprising:
receiving an encrypted rendition of the profile over the communications network; accessing a seed securely provisioned in the target device; deriving a first private key of a first public, private key pair from the seed; obtaining a second public key in a second public, private key pair associated with the service provider; using the second public key and the first private key derived from the seed to perform a local DH exchange to create a symmetric key; and decrypting the encrypted rendition of the profile using the symmetric key.
19 . The computer readable storage medium of claim 18 wherein the second public, private key pair is generated using an ECC algorithm.
20 . The computer readable storage medium of claim 18 further comprising obtaining the second public key from the service provider over the communications network.
21 . The computer readable storage medium of claim 18 wherein the seed is unique to a secure element located in the target device.
22 . The computer readable storage medium of claim 18 wherein the seed is common to a particular population of secure elements respectively located in a population of target devices.
23 . The computer readable storage medium of claim 22 further comprising deriving the first private key of the first public, private key pair using the seed and an identifier associated with a manufacturer or vendor of the secure elements.
24 . The computer readable storage medium of claim 22 further comprising deriving the first private key of the first public private key pair using the seed, a first identifier associated with a manufacturer or vendor of the secure elements and a second identifier associated with the secure element in the target device.Join the waitlist — get patent alerts
Track US2014082358A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.