IP Library Granted Patent US 8,321,923
Granted Patent B2
US 8,321,923 · App. 10/591,496 · Granted Nov 27, 2012

Secure sharing of resources between applications in independent execution environments in a retrievable token (e.g. smart card)

Assignee: Gemalto SA
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,321,923
App. No.
10/591,496
Granted
Nov 27, 2012
Kind
B2
Abstract

The invention relates to an authentication and/or rights containing retrievable token such as an IC card comprising at least one physical channel of communication to at least one apparatus and at least two logical channels of communication with said at least one apparatus wherein each logical channel of communication is associated with a different execution environment.

Claims (26)

1. A retrievable token comprising:

one or more physical channels of communication to at least one apparatus;

a first logical channel of communication to the at least one apparatus, wherein the first logical channel is associated with a physical channel of the one or more physical channels of communication, wherein the first logical channel is associated with a first protocol stack and a first execution environment on the retrievable token; and

a second logical channel of communication to the at least one apparatus, wherein the second logical channel is associated with the physical channel of the one or more physical channels of communication, wherein the second logical channel is associated with a second protocol stack and a second execution environment on the retrievable token,

wherein the retrievable token is configured to concurrently execute the first execution environment and the second execution environment, and

wherein executing the first execution environment comprises executing the first protocol stack and executing the second execution environment comprises executing the second protocol stack.

2. The retrievable token of claim 1 , wherein the retrievable token is a Multi Media Memory card.

3. The retrievable token of claim 1 , wherein the at least one apparatus is a mobile communication handset.

4. The retrievable token of claim 1 , wherein the at least one apparatus is a personal computer.

5. The retrievable token of claim 1 , wherein the physical channel of the one or more physical channels of communication is configured to use USB protocol.

6. The retrievable token of claim 1 , wherein the physical channel of the one or more physical channels of communication is configured to use SPI protocol.

7. The retrievable token of claim 1 , wherein physical channel of the one or more physical channels of communication is configured to use MMC protocol.

8. The retrievable token of claim 1 , wherein the physical channel of the one or more physical channels of communication is configured to use a protocol for contactless smart card.

9. The retrievable token of claim 8 , wherein the protocol of communication is defined in the ISO (FCD) 15693.

10. The retrievable token of claim 8 , wherein the protocol is defined in the ISO 14443.

11. The retrievable token of claim 1 , wherein the physical channel of the one or more physical channels of communication is configured to use at least one protocol defined in the TS 102.221 standard.

12. The retrievable token of claim 1 , wherein the physical channel of the one or more physical channels of communication is configured to use at least one protocol defined in the ISO 7816 standard.

13. The retrievable token of claim 1 , wherein said retrievable token includes at least two independent physical channels.

14. The retrievable token of claim 1 , wherein said retrievable token comprises a first application and a second application, wherein the retrievable token is configured to execute the first application in the first execution environment and the second application in the second execution environment, and wherein said retrievable token comprises a resource that is shared between the first application and the second application.

15. The retrievable token of claim 14 , wherein the retrievable token comprises an access condition list (ACL) and said resource is shared by the first application and the second application on the basis of said access condition list (ACL).

16. The retrievable token of claim 15 , wherein the resource is a shared file, and wherein said access conditions of the access conditions list (ACL) associates respective applications with respective operations on the shared file thereby authorizing said respective applications to perform said respective operations on the shared file.

17. The retrievable token of claim 15 , wherein the resource is a shared object on which data is written in a “first in first out” (FIFO) manner and wherein access conditions are defined in the access conditions list (ACL) associating respective applications with respective operations on the shared object thereby authorizing said respective applications to perform said respective operations on the shared object.

18. The retrievable token of claim 15 , wherein the retrievable token stores and runs an operating system which is common to the first application and the second application and wherein the resource is a shared function that is implemented by the operating system and for which access conditions are defined in the access conditions list (ACL) which specify respective rights of the applications to invoke said shared function.

19. The retrievable token of claim 14 , wherein the first application of the is configured to share a function with the second application by allowing the second application to invoke the function and where access conditions list (ACL) are defined in the retrievable token for the second application to access the shared function.

20. The retrievable token of claim 14 , wherein the retrievable token is configured to execute the first application and the second application simultaneously.

21. The retrievable token of claim 14 , wherein the retrievable token is configured to implement a communication protocol between the first application and the second application, wherein the communication protocol enables secure sharing of data and/or functions between the first application and the second application.

Assignments (2)
CHANGE OF NAME Recorded Nov 11, 2011
From: AXALTO SA
To: GEMALTO SA
Reel/Frame 027215/0659 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2006
From: MAHALAL, ILAN; RHELIMI, ALAIN
To: AXALTO SA
Reel/Frame 018287/0290 →
Priority Claims (1)
EP 04290597 · Mar 4, 2004 · regional
Continuity (1)
Related Publication 20070180517A1 · Aug 2, 2007