IP Library Granted Patent US 9,860,740
Granted Patent B2
US 9,860,740 · App. 15/040,410 · Granted Jan 2, 2018

Apparatuses, methods and systems for configuring a trusted java card virtual machine using biometric information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,860,740
App. No.
15/040,410
Granted
Jan 2, 2018
Kind
B2
Abstract

Apparatuses, methods, and systems are provided for securely configuring a Java Card virtual machine operating on a cellular device's application processor. In one embodiment, a connected device with an integrated cellular modem, a virtual universal integrated circuit chip and an integrated fingerprint scanner are used. In another embodiment, the cellular device's built-in camera is used, instead of an integrated fingerprint scanner, to capture the user's facial image.

Claims (65)

1. A mobile station comprising:

a modem and at least one antenna configured to communicate with a plurality of cellular networks; and

one or more memories storing computer-executable instructions that, when executed, configure a mobile application running on a processor that facilitates communication between the modem and a virtual reprogrammable universal integrated circuit chip (eUICC) that is not physically or electrically connected to the modem,

wherein security of the virtual eUICC is maintained using user-provided biometric information,

wherein the computer-executable instructions, when executed, further cause configuration of a virtual machine to host the virtual eUICC by causing

initialization of a data storage module of the virtual machine with the user-provided biometric information as a parameter to create encryption, decryption, and signature keys,

loading of the data storage module upon each device boot-up,

digital signing of data associated with the virtual machine using the signature key, and

storage of the digitally signed data in a storage memory.

2. The mobile station of claim 1 , further comprising:

a biometric information capturing element,

wherein the user-provided biometric information is captured by the biometric information capturing element.

3. The mobile station of claim 2 , wherein the biometric information capturing element comprises a built-in fingerprint scanner or camera device.

4. The mobile station of claim 1 , wherein the computer-executable instructions, when executed, cause configuration of the virtual machine by further causing

encryption and decryption of data associated with the virtual machine using the encryption and decryption keys.

5. The mobile station of claim 4 ,

wherein the digitally signed data comprises at least one of a GSM file system, one or more Java Card applications, or one or more network authentication keys, and

wherein the digitally signed data is formatted into data blocks.

6. The mobile station of claim 5 , wherein the storage memory maintains the data blocks in a journaling file system.

7. The mobile station of claim 4 , wherein digitally signing the data comprises signing checksums or hashes of the data with the signature key.

8. The mobile station of claim 4 , wherein digitally signing the data comprises:

calculating redundancy check values for the data; and

signing the redundancy check values with random keys.

9. A method for communicating in multi-active mode with a plurality of cellular networks, the method comprising:

providing a mobile device having a modem and at least one antenna configured to communicate with a plurality of cellular networks; and

configuring a mobile application running on a processor to facilitate communication between the modem and a virtual reprogrammable universal integrated circuit chip (eUICC) that is not physically or electrically connected to the modem,

wherein security of the virtual eUICC is maintained using user-provided biometric information,

wherein the method further includes causing configuration of a virtual machine to host the virtual eUICC by causing

initialization of a data storage module of the virtual machine with the user-provided biometric information as a parameter to create encryption, decryption, and signature keys,

loading of the data storage module upon each device boot-up,

digital signing of data associated with the virtual machine using the signature key, and

storage of the digitally signed data in a storage memory.

10. The method of claim 9 , wherein the mobile device further includes a biometric information capturing element, and wherein the method includes capturing the user-provided biometric information using the biometric information capturing element.

11. The method of claim 9 , wherein causing configuration of the virtual machine further includes causing:

encryption and decryption of data associated with the virtual machine using the encryption and decryption keys.

12. The method of claim 11 ,

wherein the digitally signed data comprises at least one of a GSM file system, one or more Java Card applications, or one or more network authentication keys, and

wherein the digitally signed data is formatted into data blocks.

13. The method of claim 12 , further comprising:

maintaining the data blocks in a journaling file system in the storage memory.

14. The method of claim 11 , wherein digitally signing the data comprises signing checksums or hashes of the data with the signature key.

15. The method of claim 11 , wherein digitally signing the data comprises:

calculating redundancy check values for the data; and

signing the redundancy check values with random keys.

16. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by a mobile station having a modem and at least one antenna configured to communicate with a plurality of cellular networks, cause the mobile station to:

configure a mobile application running on a processor to facilitate communication between the modem and a virtual reprogrammable universal integrated circuit chip (eUICC) that is not physically or electrically connected to the modem,

wherein security of the virtual eUICC is maintained using user-provided biometric information,

wherein the computer-executable instructions, when executed by the mobile station, further cause configuration of a virtual machine to host the virtual eUICC by causing

initialization of a data storage module of the virtual machine with the user-provided biometric information as a parameter to create encryption, decryption, and signature keys,

loading of the data storage module upon each device boot-up,

digital signing of data associated with the virtual machine using the signature key, and

storage of the digitally signed data in a storage memory.

17. The one or more non-transitory computer-readable media of claim 16 ,

wherein the mobile station further includes a biometric information capturing element, and

wherein the user-provided biometric information is captured by the biometric information capturing element.

18. The one or more non-transitory computer-readable media of claim 16 , wherein the computer-executable instructions, when executed by the mobile station, cause the mobile station to cause configuration of a virtual machine by further causing:

encryption and decryption of data associated with the virtual machine using the encryption and decryption keys.

19. The one or more non-transitory computer-readable media of claim 18 ,

wherein the digitally signed data comprises at least one of a GSM file system, one or more Java Card applications, or one or more network authentication keys, and

wherein the digitally signed data is formatted into data blocks.

20. The one or more non-transitory computer-readable media of claim 19 , wherein the storage memory maintains the data blocks in a journaling file system.

21. The one or more non-transitory computer-readable media of claim 18 , wherein digitally signing the data comprises signing checksums or hashes of the data with the signature key.

22. The one or more non-transitory computer-readable media of claim 18 , wherein digitally signing the blocks comprises:

calculating redundancy check values for the data; and

signing the redundancy check values with random keys.

Assignments (3)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 26, 2024
From: GIGSKY, INC.
To: HIGHLANDS ADVISORY LLC
Reel/Frame 066679/0403 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2021
From: SIMLESS, INC.
To: GIGSKY, INC.
Reel/Frame 056921/0788 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2016
From: WANE, ISMAILA
To: SIMLESS, INC.
Reel/Frame 037711/0505 →