IP Library Granted Patent US 10,515,352
Granted Patent B2
US 10,515,352 · App. 14/987,507 · Granted Dec 24, 2019

System and method for providing diverse secure data communication permissions to trusted applications on a portable communication device

Inventors: David Brudnicki (Duvall, WA); Michael Craft (Carlsbad, CA); Hans Reisgies (San Jose, CA); Andrew Weinstein (San Francisco, CA)
G06Q20/3226G06F21/34G06F21/74G06Q20/204G06Q20/3567G06Q20/3574G06Q20/401H04L63/08H04L63/0807H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,515,352
App. No.
14/987,507
Granted
Dec 24, 2019
Kind
B2
Abstract

A system for providing first and second trusted applications diverse permission to communicate via a secure element. The system comprising first digital identifier and digital token operably associated with the first trusted application; a second digital identifier and digital token operably associated with the second trusted application. The system further includes a card services module that provides an application programming interface to the secure element supported by a secure data table including first and second sets of permissions. The card services module issues one or more commands to the secure element based on a first action requested by the first trusted application in conjunction with the presentation of the first digital token only if the one or more commands will not violate the first set of permissions. A method is also disclosed.

Claims (11)

1. A system for providing first and second trusted applications diverse permission to communicate via a secure element associated with a portable communication device, the system comprising:

a first digital identifier and a first digital token operably associated with the first trusted application;

a second digital identifier and a second digital token operably associated with the second trusted application;

a card services module disposed on the portable communication device and operably associated with the secure element to provide an application programming interface to the secure element; and

a secure data table electronically associated with the card services module, the secure data table including a first entry pairing the first digital identifier with the first digital token and a second entry pairing the second digital identifier with the second digital token, the first entry further including a first set of permissions and the second entry further including a second set of permissions,

wherein the card services module issues one or more commands to the secure element based on a first action requested by the first trusted application in conjunction with the presentation of the first digital token only if the one or more commands will not violate the first set of permissions and the card services module issues one or more commands to the secure element based on a second action requested by the second trusted application in conjunction with the presentation of the second digital token only if the one more commands will not violate the second set of permissions.

2. The system according to claim 1 wherein the first and second sets of permissions are different.

3. The system according to claim 2 wherein the first and second sets of permissions govern reading, writing, activating/deactivating and downloading credentials.

4. The system according to claim 3 wherein the first and second set of permissions apply independently to three categories: all credentials, own credentials and extended issuer credentials.

5. The system according to claim 1 wherein the first and second sets of permissions govern reading, writing, activating/deactivating and downloading credentials.

6. The system according to claim 5 wherein the first and second set of permissions apply independently to three categories: all credentials, own credentials and extended issuer credentials.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2023
From: SEQUENT SOFTWARE, INC.
To: TIS INC.
Reel/Frame 064105/0348 →
SECURITY INTEREST Recorded Dec 22, 2022
From: SEQUENT SOFTWARE INC.
To: TIS INC.
Reel/Frame 062179/0639 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2019
From: GFA WORLDWIDE, INC.
To: SEQUENT SOFTWARE, INC.
Reel/Frame 051089/0938 →
SECURITY INTEREST Recorded Jun 27, 2019
From: SEQUENT SOFTWARE INC.; GFA WORLDWIDE, INC.
To: TIS INC.
Reel/Frame 049623/0638 →
RELEASE OF SECURITY INTEREST Recorded Jun 11, 2019
From: COMERICA BANK
To: SEQUENT SOFTWARE INC.
Reel/Frame 049437/0802 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2017
From: SEQUENT SOFTWARE, INC.
To: GFA WORLDWIDE, INC.
Reel/Frame 044432/0366 →
Continuity (4)
Continuation 14250720 · Apr 11, 2014
Continuation 13279200 · Oct 21, 2011
Provisional Application 61414847 · Nov 17, 2010
Related Publication 20160224961A1 · Aug 4, 2016
Cited By (1)
US 12,591,882