IP Library › Granted Patent US 10,270,776
Granted Patent B2
US 10,270,776 · App. 15/247,193 · Granted Apr 23, 2019

Secure zone for secure transactions

Inventors: Sergey Ignatchenko (Innsbruck, AT); Dmytro Ivanchykhin (Kiev, UA)
Assignee: OLogN Technologies AG
H04L63/10G06F9/468G06F21/51G06F21/53G06F21/54G06F21/602H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,270,776
App. No.
15/247,193
Granted
Apr 23, 2019
Kind
B2
Abstract

An apparatus according to the present disclosure may comprise a secure zone configured to execute a task having a subtask. The task and subtask may have respective executable code and may be digitally signed by respective code providers. The secure zone may be further configured to apply respective sets of permissions while the respective executable code of the task and subtask are executed. The respective set of permissions for the task may be based on at least one of information associated with the signed task and information in a digital certificate of the respective code provider for the task. The respective set of permissions for the subtask may be based on at least one of information associated with the signed subtask and information in a digital certificate of the respective code provider for the subtask.

Claims (18)

1. An apparatus, comprising:

a memory configured to store data;

a secure zone comprising an interface and configured to execute a task comprising a subtask that communicates one or more data packets over a network, wherein the memory is cleared of data related to the subtask after executing the subtask; and

a non-secure zone coupled to the secure zone via the interface, wherein the secure zone is configured to use network capabilities of the non-secure zone to communicate the one or more data packets over the network according to the subtask, and wherein the network capabilities of the non-secure zone receive the data packets communicated from the secure zone via the interface.

2. The apparatus of claim 1 , wherein the network capabilities of the non-secure zone include a TCP/IP stack.

3. An apparatus, comprising:

a secure zone comprising an interface and configured to execute a task comprising a subtask that communicates one or more data packets over a network, and

a non-secure zone coupled to the secure zone via the interface, wherein the secure zone is configured to use network capabilities of the non-secure zone to communicate the one or more data packets over the network according to the subtask, and wherein the network capabilities of the non-secure zone receive the data packets communicated from the secure zone via the interface, wherein the task and the subtask have respective executable code, and the task and the subtask are digitally signed by respective code providers, and

wherein the secure zone is configured to apply respective sets of permissions while the respective executable code of the task and subtask are executed, wherein the respective set of permissions for the task are based on at least one of information associated with the signed task and information in a digital certificate of the respective code provider for the task, and wherein the respective set of permissions for the subtask are based on at least one of information associated with the signed subtask and information in a digital certificate of the respective code provider for the subtask.

4. A method, comprising:

receiving a task at a secure zone of an apparatus coupled to a non-secure of the apparatus via an interface;

executing a subtask of the task by the secure zone, wherein execution of the subtask comprises communicating one or more data packets over a network using network capabilities provided by the non-secure zone, and wherein the network capabilities of the non-secure zone receive the data packets communicated from the secure zone via the interface; and

clearing a memory of data related to the subtask after executing the subtask.

5. The method of claim 4 , wherein the network capabilities of the non-secure zone include a TCP/IP stack.

6. A method, comprising:

receiving a task at a secure zone of an apparatus coupled to a non-secure of the apparatus via an interface;

executing a subtask of the task by the secure zone, wherein execution of the subtask comprises communicating one or more data packets over a network using network capabilities provided by the non-secure zone, and wherein the network capabilities of the non-secure zone receive the data packets communicated from the secure zone via the interface; and

applying respective sets of permissions while the respective executable code of the task and subtask are executed, wherein the task and the subtask have respective executable code, and the task and the subtask are digitally signed by respective code providers, wherein the respective set of permissions for the task are based on at least one of information associated with the signed task and information in a digital certificate of the respective code provider for the task, and wherein the respective set of permissions for the subtask are based on at least one of information associated with the signed subtask and information in a digital certificate of the respective code provider for the subtask.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2024
From: OLOGN TECHNOLOGIES AG
To: FINGON LLC
Reel/Frame 067333/0104 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2016
From: IGNATCHENKO, SERGEY; IVANCHYKHIN, DMYTRO
To: OLOGN TECHNOLOGIES AG
Reel/Frame 039542/0150 →
Continuity (3)
Division 13866687 · Apr 19, 2013
Provisional Application 61636201 · Apr 20, 2012
Related Publication 20160366139A1 · Dec 15, 2016
Cited By (2)
US 12,288,208 US 12,307,448