IP Library Patent Application 14645061
Patent Application
App. No. 14/645,061

METHOD FOR SECURED COMMUNICATION BETWEEN AN OPERATING SYSTEM OF A TERMINAL AND A DEVICE DISTINCT FROM THE TERMINAL

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/645,061
Abstract

Disclosed are methods, systems, and devices for secure communication between an operating system of a terminal and a device distinct from the terminal, the terminal further including a reliable execution environment. In various implementations, authentication of said device by said reliable execution environment initiated by said operating system may occur prior to the secure communication. Some embodiments include a terminal and a system comprising the terminal.

Claims (26)

1 . A secured communication method between an operating system of a terminal and a device distinct from the terminal, the terminal further including a reliable execution environment, the method comprising:

authenticating, prior to the secured communication, said device by said reliable execution environment initiated by said operating system.

2 . The method according to claim 1 , further comprising:

performing a mutual authentication of the device and of the reliable execution environment, the mutual authentication comprising:

the authenticating of said device by said reliable execution environment and

authenticating of the reliable execution environment by said device.

3 . The method according to claim 2 , wherein said mutual authentication includes an exchange through said operating system of cryptograms between said device and said reliable execution environment, the authentication being obtained on the basis of a verification by said device and of a verification by said reliable execution environment in which the device and the reliable execution environment check that both cryptograms are identical.

4 . The method according to claim 3 , wherein an elaboration of each of the cryptograms is carried out on the basis of a datum provided by said reliable execution environment, of a datum provided by said device, and of a ciphering key both elaborated by said device and by said reliable execution environment.

5 . The method according to claim 4 , wherein said ciphering key is elaborated by said device on the basis of a derived key specific to said device, and said ciphering key is elaborated by said reliable execution environment on the basis of a derived key obtained from a master key and from additional data of said device.

6 . The method according to claim 4 , wherein said secured communication uses at least said ciphering key.

7 . The method according to claim 1 , wherein said secured communication further includes communication of a code for authenticating said secured communication, and an elaboration of the code using a code elaboration key obtained beforehand within said device and said reliable execution environment.

8 . The method according to claim 1 , wherein said secured communication includes communication of personal data of a user.

9 . The method according to claim 8 , wherein said personal data are obtained by means of a reliable user interface executed by said reliable execution environment.

10 . The method according to claim 1 , wherein said authenticating is applied upon request from an application executed by said operating system.

11 . The method according to claim 10 , wherein said application communicates with said reliable execution environment by means of a transport layer.

12 . The method according to claim 1 , wherein the device is a secure element.

13 . A terminal comprising:

an operating system; and

a reliable execution environment that includes a module for authentication of a device distinct from the terminal upon request from the operating system.

14 . A system comprising:

a terminal comprising:

an operating system, and

a reliable execution environment that includes a module for authentication of a device distinct from the terminal upon request from the operating system; and

a device distinct from the terminal, wherein the device includes a module for authenticating the reliable execution environment upon request from the operating system.

15 . A computer program comprising instructions for executing the steps of a secured communication method between a terminal and a device distinct from the terminal according to claim 1 , when said program is executed on a processor of the terminal.

16 . A non-transitory recording medium readable by a processor, on which is recorded a computer program comprising instructions for executing the steps of a secured communication method between a terminal and a device distinct from the terminal according to claim 1 .

Assignments (2)
CHANGE OF NAME Recorded Apr 13, 2018
From: OBERTHUR TECHNOLOGIES
To: IDEMIA FRANCE
Reel/Frame 047169/0413 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2015
From: PHILIPPOT, YANN; LEVENES, RAPHAEL
To: OBERTHUR TECHNOLOGIES
Reel/Frame 035257/0814 →