首页> 外国专利> Using a trusted-platform-based shared-secret derivation and WWAN infrastructure-based enrollment to establish a secure local channel

Using a trusted-platform-based shared-secret derivation and WWAN infrastructure-based enrollment to establish a secure local channel

机译:使用基于受信任平台的共享秘密派生和基于WWAN基础结构的注册来建立安全的本地通道

摘要

A system and method for establishing a trusted connection on a mobile computing device (102). A shared secret is generated on a trusted platform (106) of the mobile computing device. The shared secret is transported to a secure channel application (118). The secure channel application establishes a secure local communication channel between the trusted platform and a SIM (subscriber identity module)/Smartcard (104) on the mobile computing device. The shared secret is received by the SIM/Smartcard. In one embodiment, the mobile computing device includes a GSM (Global Systems for Mobile Communications) 03.48 application (120) that sends the shared secret to a GSM 03.48 network infrastructure (122) for storage, management, and verification by the GSM 03.48 network infrastructure, and in turn sends the shared secret to the SIM/Smartcard on the mobile computing device.; In an alternative embodiment, a Diffie-Hellman key exchange is performed by the trusted platform to send the shared secret to the SIM/Smartcard. The shared secret, after being received by the SIM/Smartcard, is provided to a secure channel applet (112) on the SIM/Smartcard. The secure channel applet establishes the local communication channel between the SIM/Smartcard and the trusted platform. Once the secure channel application on the trusted platform and the secure channel applet on the SIM/Smartcard both have the shared secret, a transport layer security (TLS)-based handshake can take place to establish the secure local communication channel.
机译:一种用于在移动计算设备上建立信任连接的系统和方法(102)。在移动计算设备的可信平台(106)上生成共享秘密。共享秘密被传输到安全通道应用程序(118)。安全通道应用程序在可信平台和移动计算设备上的SIM(用户标识模块)/智能卡(104)之间建立安全本地通信通道。共享密钥由SIM /智能卡接收。在一个实施例中,移动计算设备包括GSM(全球移动通信系统)03.48应用程序(120),该应用程序将共享秘密发送到GSM 03.48网络基础设施(122),以用于由GSM 03.48网络基础设施进行存储,管理和验证。 ,然后将共享的机密发送到移动计算设备上的SIM /智能卡。在替代实施例中,由可信平台执行Diffie-Hellman密钥交换,以将共享秘密发送到SIM /智能卡。在被SIM /智能卡接收之后,共享秘密被提供给SIM /智能卡上的安全通道小应用程序(112)。安全通道小程序在SIM /智能卡和可信平台之间建立本地通信通道。一旦可信平台上的安全通道应用程序和SIM /智能卡上的安全通道小程序都具有共享密钥,就可以进行基于传输层安全性(TLS)的握手,以建立安全的本地通信通道。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号