IP Library Granted Patent US 11,172,352
Granted Patent B2
US 11,172,352 · App. 16/235,778 · Granted Nov 9, 2021

Apparatuses, methods, and systems for configuring a trusted java card virtual machine using biometric information

Inventor: Ismaila Wane (Mountain View, CA)
Assignee: Gigsky, Inc.
H04W8/205G06F9/45533G06F21/32G06F21/53G06F21/64G06F21/77H04B1/3816H04L63/0861H04L67/30H04L67/306H04M15/56H04M15/63H04M15/7556H04M15/7657H04M15/8038H04W4/24H04W4/50H04W4/60H04W8/183H04W12/04H04W12/041H04W12/06H04W12/069H04W84/042H04W88/06H04W88/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,172,352
App. No.
16/235,778
Granted
Nov 9, 2021
Kind
B2
Abstract

Apparatuses, methods, and systems are provided for securely configuring a Java Card virtual machine operating on a cellular device's application processor. In one embodiment, a connected device with an integrated cellular modem, a virtual universal integrated circuit chip and an integrated fingerprint scanner are used. In another embodiment, the cellular device's built-in camera is used, instead of an integrated fingerprint scanner, to capture the user's facial image.

Claims (63)

1. A mobile station comprising:

a modem and at least one antenna configured to communicate with a plurality of cellular networks; and

one or more memories storing computer-executable instructions that, when executed, configure a mobile application running on a processor that facilitates communication between the modem and a virtual reprogrammable universal integrated circuit chip (eUICC) that is not physically or electrically connected to the modem, and

cause configuration of a virtual machine to host the virtual eUICC, wherein causing configuration of the virtual machine includes causing:

initialization of a data storage module of the virtual machine with user-provided biometric information as a parameter to create encryption, decryption, and signature keys;

loading of the data storage module upon each device boot-up;

encryption and decryption of data associated with the virtual machine using the encryption and decryption keys;

digital signing of data associated with the virtual machine using the signature key; and

storage of the digitally signed data in a storage memory,

wherein security of the virtual eUICC is maintained using the user-provided biometric information and without reliance on a trusted execution environment of the mobile station.

2. The mobile station of claim 1 , further comprising:

a biometric information capturing element,

wherein the user-provided biometric information is captured by the biometric information capturing element.

3. The mobile station of claim 2 , wherein the biometric information capturing element comprises a built-in fingerprint scanner or camera device.

4. The mobile station of claim 1 ,

wherein the digitally signed data comprises at least one of a GSM file system, one or more Java Card applications, or one or more network authentication keys, and

wherein the digitally signed data is formatted into data blocks.

5. The mobile station of claim 4 , wherein the storage memory maintains the data blocks in a journaling file system.

6. The mobile station of claim 1 , wherein digitally signing the data comprises signing checksums or hashes of the data with the signature key.

7. The mobile station of claim 1 , wherein digitally signing the data comprises:

calculating redundancy check values for the data; and

signing the redundancy check values with random keys.

8. A method for communicating in multi-active mode with a plurality of cellular networks, the method comprising:

providing a mobile device having a modem and at least one antenna configured to communicate with a plurality of cellular networks;

configuring a mobile application running on a processor to facilitate communication between the modem and a virtual reprogrammable universal integrated circuit chip (eUICC) that is not physically or electrically connected to the modem; and

causing configuration of a virtual machine to host the virtual eUICC, wherein causing configuration of the virtual machine includes causing:

initialization of a data storage module of the virtual machine with user-provided biometric information as a parameter to create encryption, decryption, and signature keys;

loading of the data storage module upon each device boot-up;

encryption and decryption of data associated with the virtual machine using the encryption and decryption keys;

digital signing of data associated with the virtual machine using the signature key; and

storage of the digitally signed data in a storage memory,

wherein security of the virtual eUICC is maintained using the user-provided biometric information and without reliance on a trusted execution environment of a mobile station.

9. The method of claim 8 , wherein the mobile device further includes a biometric information capturing element, and wherein the method includes capturing the user-provided biometric information using the biometric information capturing element.

10. The method of claim 8 ,

wherein the digitally signed data comprises at least one of a GSM file system, one or more Java Card applications, or one or more network authentication keys, and

wherein the digitally signed data is formatted into data blocks.

11. The method of claim 10 , further comprising:

maintaining the data blocks in a journaling file system in the storage memory.

12. The method of claim 8 , wherein digitally signing the data comprises signing checksums or hashes of the data with the signature key.

13. The method of claim 8 , wherein digitally signing the data comprises:

calculating redundancy check values for the data; and

signing the redundancy check values with random keys.

14. One or more non-transitory computer-readable media storing computer executable instructions that, when executed by a mobile station having a modem and at least one antenna configured to communicate with a plurality of cellular networks, cause the mobile station to:

configure a mobile application running on a processor to facilitate communication between the modem and a virtual reprogrammable universal integrated circuit chip (eUICC) that is not physically or electrically connected to the modem; and

cause configuration of a virtual machine to host the virtual eUICC by causing:

initialization of a data storage module of the virtual machine with user-provided biometric information as a parameter to create encryption, decryption, and signature keys;

loading of the data storage module upon each device boot-up;

encryption and decryption of data associated with the virtual machine using the encryption and decryption keys;

digital signing of data associated with the virtual machine using the signature key; and

storage of the digitally signed data in a storage memory,

wherein security of the virtual eUICC is maintained using the user-provided biometric information and without reliance on a trusted execution environment of the mobile station.

15. The one or more non-transitory computer-readable media of claim 14 ,

wherein the mobile station further includes a biometric information capturing element, and

wherein the user-provided biometric information is captured by the biometric information capturing element.

16. The one or more non-transitory computer-readable media of claim 15 , wherein the biometric information capturing element comprises a built-in fingerprint scanner or camera device.

17. The one or more non-transitory computer-readable media of claim 14 ,

wherein the digitally signed data comprises at least one of a GSM file system, one or more Java Card applications, or one or more network authentication keys, and

wherein the digitally signed data is formatted into data blocks.

18. The one or more non-transitory computer-readable media of claim 14 , wherein digitally signing the data comprises signing checksums or hashes of the data with the signature key.

19. The one or more non-transitory computer-readable media of claim 14 , wherein digitally signing the data comprises:

calculating redundancy check values for the data; and

signing the redundancy check values with random keys.

20. The one or more non-transitory computer-readable media of claim 17 , wherein the data blocks are maintained in a journaling file system in the storage memory.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 26, 2024
From: GIGSKY, INC.
To: HIGHLANDS ADVISORY LLC
Reel/Frame 066679/0403 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2021
From: WANE, ISMAILA
To: GIGSKY, INC.
Reel/Frame 056644/0076 →
Continuity (12)
Continuation In Part 15838611 · Dec 12, 2017
Continuation 15040410 · Feb 10, 2016
Continuation 16235778
Continuation In Part 16124136 · Sep 6, 2018
Continuation In Part 15838611 · Dec 12, 2017
Continuation 15040410 · Feb 10, 2016
Continuation In Part 14856991 · Sep 17, 2015
Provisional Application 62051311 · Sep 17, 2014
Provisional Application 62078006 · Nov 11, 2014
Provisional Application 62162740 · May 16, 2015
Provisional Application 62171246 · Jun 5, 2015
Related Publication 20190230496A1 · Jul 25, 2019