IP Library Granted Patent US 9,361,470
Granted Patent B2
US 9,361,470 · App. 14/349,047 · Granted Jun 7, 2016

Secure element comprising separated containers and corresponding method

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,361,470
App. No.
14/349,047
Granted
Jun 7, 2016
Kind
B2
Abstract

The invention is a secure element comprising a virtual machine able to work in admin mode and in runtime mode. The secure element comprises two enhanced containers. Each of said enhanced containers can be either in an activated state or in a disabled state. Only one of the enhanced containers can be in activated state at any given time. The virtual machine is adapted to access each of the enhanced containers when working in admin mode. The virtual machine cannot access an enhanced container which is in disabled state when working in runtime mode.

Claims (32)

1. A secure element comprising:

two enhanced containers, where (i) each of said enhanced containers can be either in an activated state or in a disabled state and (ii) only one of said enhanced containers can be in the activated state at any given time; and

an object-oriented virtual machine able to work in an admin mode and in a runtime mode,

the virtual machine being able to access each of said enhanced containers when working in admin mode, irrespective of the state of said enhanced containers,

wherein the virtual machine cannot access an enhanced container which is in disabled state when working in runtime mode; and

an admin means configured to store an instance of a same first application in each of said enhanced containers using a same identifier,

wherein said secure element comprises a global registry containing an identifier associated with a second application, wherein the virtual machine is configured to access the global registry when working in runtime mode, and wherein each of said enhanced containers comprises its own associated local registry, each local registry containing the identifier of said first application.

2. A secure element according to claim 1 , wherein said secure element comprises a common container which is always in the activated state independently of said enhanced containers, and wherein the virtual machine is configured to access said common container when working in runtime mode.

3. A secure element according to claim 1 , wherein said secure element comprises a communication interface and a switch means configured to activate one of said enhanced containers in response to a dedicated command received through the communication interface.

4. A secure element according to claim 1 , wherein each of said enhanced containers comprises data related to a subscription.

5. A secure element according to claim 1 , wherein each of said enhanced containers is managed via a security domain as defined by GlobalPlatform® standard.

6. A secure element according to claim 1 , wherein said secure element is a smart card, an eUICC or a Machine-To-Machine device.

7. A system comprising a machine and a secure element,

wherein the secure element is according to claim 1 and said machine comprises a selection means adapted to generate a dedicated command for triggering the activation of one of the enhanced containers of the secure element.

8. A system according to claim 7 , wherein said machine comprises a manager means configured to generate a specific command for triggering the creation of a new enhanced container in the secure element.

9. A secure element comprising:

two enhanced containers, where (i) each of said enhanced containers can be either in an activated state or in a disabled state and (ii) only one of said enhanced containers can be in the activated state at any given time; and

a virtual machine able to work in an admin mode and in a runtime mode,

the virtual machine being able to access each of said enhanced containers when working in admin mode, and

wherein the virtual machine cannot access an enhanced container which is in disabled state when working in runtime mode;

an admin means configured to store an instance of a same first application in each of said enhanced containers using a same identifier; and

a global registry containing an identifier associated with a second application,

wherein the virtual machine is configured to access the global registry when working in runtime mode, and

wherein each of said enhanced containers comprises its own associated local registry, each local registry containing the identifier of said first application.

10. A secure element according to claim 9 , wherein said secure element comprises a common container which is always in the activated state independently of said enhanced containers, and wherein the virtual machine is configured to access said common container when working in runtime mode.

11. A secure element according to claim 9 , wherein said secure element comprises a communication interface and a switch means configured to activate one of said enhanced containers in response to a dedicated command received through the communication interface.

12. A secure element according to claim 9 , wherein each of said enhanced containers comprises data related to a subscription.

13. A secure element according to claim 9 , wherein each of said enhanced containers is managed via a security domain as defined by Global Platform® standard.

14. A secure element according to claim 9 , wherein said secure element is a smart card, an eUICC or a Machine-to-Machine device.

15. A system comprising a machine and a secure element,

wherein the secure element is according to claim 9 and said machine comprises a selection means adapted to generate a dedicated command for triggering the activation of one of the enhanced containers of the secure element.

16. A system according to claim 15 , wherein said machine comprises a manager means configured to generate a specific command for triggering the creation of a new enhanced container in the secure element.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2023
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 062727/0379 →
CHANGE OF NAME Recorded Jan 30, 2023
From: GEMALTO SA
To: THALES DIS FRANCE SA
Reel/Frame 064163/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2014
From: BERARD, XAVIER; ROUSSEL, NICOLAS; PICO, RICHARD; FAURE, FREDERIC; GONZALVO, BENOIT
To: GEMALTO SA
Reel/Frame 033054/0548 →