IP Library Granted Patent US 10,440,056
Granted Patent B2
US 10,440,056 · App. 15/185,827 · Granted Oct 8, 2019

Method for deploying an application in a secure element

Inventor: Jean-Baptiste Ratier (Issy-les-Moulineaux, FR)
Assignee: Idemia Identity & Security
H04L63/168G06F21/72G06Q20/3227G06Q20/3278G06Q20/3552H04L63/0457H04L63/061H04L63/0853G06F2221/2115H04W4/50H04W12/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,440,056
App. No.
15/185,827
Granted
Oct 8, 2019
Kind
B2
Abstract

Method for deploying an authentication application in a secure element of a communication terminal comprising a non-secure processing unit executing a program for calling the authentication applications. The method comprises the step of transferring via at least one communication network data between a first trusted server associated with a provider of the security element so as to execute a first program for managing the security element, a second trusted server associated with at least one provider of authentication applications so as to execute a program for managing authentication applications, and the communication terminal, so as to create in the secure element a secure domain and install the authentication application therein.

Claims (17)

1. A method for deploying an application in a secure element of a communication terminal comprising a non-secure processing unit executing a program for calling the applications of the secure element; the method comprising the step of transferring via at least one communication network data between a first trusted server associated with a provider of the secure element so as to execute a first program for managing the security element, a second trusted server associated with at least one applications provider so as to execute a program for managing applications of the secure element, and the communication terminal, so as to create in the secure element a secure domain and install the application therein; characterized in that the method comprises the steps of:

establishing a first exchange of data between the applications provider and the calling program so as to obtain an application installation authorization;

establishing a second exchange of data between the first management program and the calling program so as to create the secure domain in the secure element and transfer a key for access to the secure domain to the calling program,

establishing a third exchange of data between the second management program and the calling program so as to transfer the access key to the second management program and have the second management program download and install the application in the secure domain,

prohibiting the use of the access key by any other than the second management program to access the secure domain,

data exchanges being opened between the calling program and the management programs of the trusted servers so that the trusted servers have no direct dialogue with one another.

2. The method according to claim 1 , in which the prohibition of use results from a modification of the key by the second management program after the latter has accessed the secure domain a first time.

3. The method according to claim 1 , in which the prohibition of use of the key is performed just after the second manager program has taken possession of the key before the downloading of the application into the secure domain.

4. The method according to claim 1 , comprising the step, at the end of at least one of the exchanges of data, of having the calling program send a message to a supervisor to report on the proper progress of the data exchange in question.

5. The method according to claim 1 , in which the second exchange of data is used to create at least two secure domains in the secure element.

6. The method according to claim 1 , wherein during the second exchange of data:

the calling program sends a request seeking the creation of the secure domain in the secure element, the request comprising an identifier of a mobile telephone and an identifier of the application to be installed;

the first manager program verifies the technical compatibility of the mobile payment application with the secure element of the mobile telephone;

if the application is compatible with the secure element, the first manager program sends via a GSM network an SMS short message directly to the secure element to create therein the secure domain;

once the secure domain SD has been created, the first manager program transmits the key for access to the secure domain to the calling program.

7. The method according to claim 6 , wherein the first manager program verifies the technical compatibility of the application with the secure element by using a database matching identifiers of applications with technical characteristics of the latter and a database matching identifiers of mobile telephones with technical characteristics of the latter.

8. The method according to claim 6 , wherein the first manager program transmits the request seeking the creation of the secure domain in the secure element to the provider of the secure element.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2025
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA FRANCE
Reel/Frame 070632/0157 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 048039 FRAME 0605. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 066343/0143 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 066343/0232 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE ERRONEOUSLY NAME PROPERTIES/APPLICATION NUMBERS PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066365/0151 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE REMOVE PROPERTY NUMBER 15001534 PREVIOUSLY RECORDED AT REEL: 055314 FRAME: 0930. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066629/0638 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Feb 17, 2021
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055314/0930 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Oct 29, 2020
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055108/0009 →
CHANGE OF NAME Recorded Jan 9, 2019
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 048039/0605 →
CHANGE OF NAME Recorded Aug 30, 2018
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 047529/0948 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2016
From: RATIER, JEAN-BAPTISTE
To: MORPHO
Reel/Frame 039371/0410 →
Priority Claims (1)
FR 15 55552 · Jun 17, 2015 · national
Continuity (1)
Related Publication 20170099320A1 · Apr 6, 2017