IP Library Patent Application 13279200
Patent Application
App. No. 13/279,200

System and Method for Providing Diverse Secure Data Communication Permissions to Trusted Applications on a Portable Communication Device

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/279,200
Abstract

A system for providing first and second trusted applications diverse permission to communicate via a secure element. The system comprising first digital identifier and digital token operably associated with the first trusted application; a second digital identifier and digital token operably associated with the second trusted application. The system further includes a card services module that provides an application programming interface to the secure element supported by a secure data table including first and second sets of permissions. The card services module issues one or more commands to the secure element based on a first action requested by the first trusted application in conjunction with the presentation of the first digital token only if the one or more commands will not violate the first set of permissions. A method is also disclosed.

Claims (24)

1 . A system for providing first and second trusted applications diverse permission to communicate via a secure element associated with a portable communication device, the system comprising:

a first digital identifier and a first digital token operably associated with the first trusted application;

a second digital identifier and a second digital token operably associated with the second trusted application;

a card services module disposed on the portable communication device and operably associated with the secure element to provide an application programming interface to the secure element; and

a secure data table electronically associated with the card service module, the secure data table including a first entry pairing the first digital identifier with the first digital token and a second entry pairing the second digital identifier with the second digital token, the first entry further including a first set of permissions and the second entry further including a second set of permissions,

wherein the card services module issues one or more commands to the secure element based on a first action requested by the first trusted application in conjunction with the presentation of the first digital token only if the one or more commands will not violate the first set of permissions and the card services module issues one or more commands to the secure element based on a second action requested by the second trusted application in conjunction with the presentation of the second digital token only if the one more commands will not violate the second set of permissions.

2 . The system according to claim 1 wherein the first and second sets of permissions are different.

3 . The system according to claim 2 wherein the first and second sets of permissions govern reading, writing, activating/deactivating and downloading credentials.

4 . The system according to claim 3 wherein the first and second set of permissions apply independently to three categories: all credentials, own credentials and extended issuer credentials.

5 . The system according to claim 1 wherein the first and second sets of permissions govern reading, writing, activating/deactivating and downloading credentials.

6 . The system according to claim 5 wherein the first and second set of permissions apply independently to three categories: all credentials, own credentials and extended issuer credentials.

7 . A method for providing first and second trusted applications diverse permission to communicate via a secure element associated with a portable communication device, the method comprising:

assigning a first set of permissions to the first trusted application;

assigning a second set of permissions to the second trusted application;

requesting from the first trusted application that a card services module operably associated with the secure element implement a first action; and

issuing one or more commands to the secure element based on the first action requested by the first trusted application only if the one or more commands will not violate the first set of permissions.

8 . The method of claim 7 further comprising:

requesting from the second trusted application that a card services module operably associated with the secure element implement a second action; and

issuing one or more commands to the secure element based on the second action requested by the second trusted application only if the one or more commands will not violate the second set of permissions.

9 . The method according to claim 8 wherein the first and second sets of permissions are different.

10 . The method according to claim 9 wherein the first and second sets of permissions govern reading, writing, activating/deactivating and downloading credentials.

11 . The method according to claim 10 wherein the first and second set of permissions apply independently to three categories: all credentials, own credentials and extended issuer credentials.

12 . The method according to claim 7 wherein the first and second sets of permissions govern reading, writing, activating/deactivating and downloading credentials.

13 . The system according to claim 12 wherein the first and second set of permissions apply independently to three categories: all credentials, own credentials and extended issuer credentials.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2023
From: SEQUENT SOFTWARE, INC.
To: TIS INC.
Reel/Frame 064105/0348 →
RELEASE OF SECURITY INTEREST Recorded Jun 11, 2019
From: COMERICA BANK
To: SEQUENT SOFTWARE INC.
Reel/Frame 049437/0802 →
SECURITY AGREEMENT Recorded Jul 11, 2012
From: SEQUENT SOFTWARE INC.
To: COMERICA BANK, A TEXAS BANKING ASSOCIATION
Reel/Frame 028542/0846 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2012
From: BRUDNICKI, DAVID; CRAFT, MICHAEL; REISGIES, HANS; WEINSTEIN, ANDREW
To: SEQUENT SOFTWARE INC.
Reel/Frame 027516/0484 →