IP Library Granted Patent US 8,782,767
Granted Patent B2
US 8,782,767 · App. 12/095,483 · Granted Jul 15, 2014

Upgradable security module

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,782,767
App. No.
12/095,483
Granted
Jul 15, 2014
Kind
B2
Abstract

The aim of the present invention is to provide a security module capable of supporting the different functions of the latest and the previous generations, by avoiding any possible attack due to this adaptability. This aim is attained by a security module comprising first communication means to a host device, first storage means and first decryption means, characterized in that it includes a state module and second communication means and physical activation or deactivation means of said second means, such activation or deactivation being managed by the state module.

Claims (21)

1. A security module comprising:

a first communication port connectable to a host device;

a first storage device;

a first decryption means;

a hardware or software state module, which is configured to detect activity on a communication port and to determine, according to the activity, a state of said state module;

a second communication port; and

an insulating circuit placed in series with the second communications port and configured to electronically isolate said second communication port, said insulating circuit being controlled by the state module;

wherein the insulating circuit includes tri-state or bidirectional MOSFET elements; and

where at least a portion of a physical connection path including the first communication port is different from at least a portion of a connection path including the second communication port;

wherein the security module is configured to receive a security message via the first or second communication port, and modify a state of said state module defining an accessibility of the security module to the host device via the second communication port in response to the security message.

2. The security module according to claim 1 , wherein the second communication port is connected to the host device by a contact physically different from a contact of the first communication port.

3. The security module according to claim 1 , wherein a second insulating circuit is placed in series with said first communication port, the second insulating circuit being operable to electrically isolate said first communication port, the second insulating circuit including tri-state or bidirectional MOSFET elements.

4. The security module according to claim 1 , wherein a third insulating circuit is also placed in series with at least one connection path configured to carry operating signals of the security module, the third insulating circuit being operable to electrically isolate said at least one connection path.

5. The security module according to claim 1 , wherein the security module comprises a second storage device, the state module being configured to activate or deactivate said second storage device.

6. The security module according to claim 1 , wherein the state module comprises modules and/or functions that are authorized or forbidden according to the state of the state module.

7. The security module according to claim 6 , wherein the state of the state module is configured to limit an access level to a second storage device to read only, write only, and read/write mode.

8. The security module according to claim 1 , wherein the security module includes second decryption means, these second decryption means being activated/deactivated by the state module.

9. The security module according to claim 8 , wherein power is supplied to the second decryption means under control of the state module.

10. The security module according to claim 1 , wherein the state module includes a supervision logic module configured to monitor current working parameters of all connection paths of the security module and to allow the state of the state module to be changed according to a supervision result.

11. The security module according to claim 10 , wherein the supervision logic module is connected to the connection paths of said security module.

12. The security module according to claim 10 , wherein the supervision logic module comprises a supervision profile of communication paths that can be specific to each state of the state module.

Assignments (2)
MERGER Recorded Jul 27, 2012
From: NAGRACARD S.A.
To: NAGRAVISION S.A.
Reel/Frame 028658/0550 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2008
From: HILL, MICHAEL JOHN
To: NAGRACARD S.A.
Reel/Frame 021025/0468 →