IP Library Granted Patent US 11,556,673
Granted Patent B2
US 11,556,673 · App. 16/621,781 · Granted Jan 17, 2023

Method for managing an instance of a class

Inventors: Guillaume Chi-Dan Phan (Gemenos, FR); Xavier Minette De Saint Martin (Gemenos, FR); Nicolas Vienne (Gemenos, FR)
Assignee: THALES DIS FRANCE SAS
G06F21/71G06F21/12G06F21/77G06F2221/0797
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,556,673
App. No.
16/621,781
Granted
Jan 17, 2023
Kind
B2
Abstract

The invention is a method for managing an instance of a class in a secure element embedded in a hosting machine and including a Central Processing Unit, a storage area and a virtual machine. The method comprises a step of receiving by the secure element a load file containing a binary representation of a package of the class and a step of instantiating the instance from the package and storing the instance in the storage area. The load file includes a specific component which is a custom component within the meaning of Java Card™ specifications and which contains executable data. The instance requests the execution of a subset of the executable data by directly invoking the subset of executable data through an Application Programming Interface.

Claims (15)

1. A method for managing an instance of a class in a secure element embedded in a hosting machine, said secure element including a central processing unit, a storage area and a virtual machine, the method comprising a step of receiving by the secure element a load file containing a binary representation of a package of the class and a step of instantiating the instance from said package and storing the instance in the storage area, said load file including a specific component, which is a custom component within the meaning of Java Card specifications, and which contains executable data separate from said instance,

wherein said executable data are executable in a same format as bytecode, and the instance, after said instantiating and storing, the method includes initiating an execution of a subset of said executable data by directly invoking said subset of executable data through an Application Programming Interface (API) under control of said instance to trigger execution of said executable data during runtime of said instance, which is designed to personalize said instance.

2. The method according to claim 1 , wherein the specific component contains pre-linked heap data in addition to executable data, and wherein said pre-linked heap data are copied from storage area to a heap of the virtual machine to personalize said instance,

wherein said pre-linked heap data is executable bytecode by said instance adapted by said secure element to compute a final location in said heap and correctly associate with said instance.

3. The method according to claim 1 , wherein the load file includes a Setup component containing an installation parameter which triggers an automatic installation of said instance, said Setup component being a custom component within the meaning of Java Card specifications.

4. The method according to claim 3 , wherein the installation parameter triggers at least one of the following actions: an automatic installation of the instance, an automatic association of the instance to a security domain and an automatic creation of a security domain.

5. The method according to claim 1 , wherein the load file includes a Security Domain component containing Security Domain parameters which are required to securely initialize a Security Domain to which the package is associated, said Security Domain component being a custom component within the meaning of Java Card specifications.

6. The method according to claim 1 , wherein the load file includes a Group component containing a group parameter which defines a group of packages sharing at least one security attribute, said package belonging to said group of packages and said Group component being a custom component within the meaning of Java Card specifications.

7. The method according to claim 6 , wherein said at least one security attribute is a Firewall Context ID.

8. The method according to claim 1 , wherein the load file includes a Security component containing a security parameter which is required to verify the genuineness of the package or to decipher part of the load file, said Security component being a custom component within the meaning of Java Card specifications.

9. A secure element embedded in a hosting machine and including an operating system, a central processing unit, a storage area, a virtual machine, a loader and a linker, said secure element being configured to receive a load file containing a binary representation of a package of a class and to create an instance of the class from said package, said loader being configured to retrieve from the load file and to handle a specific component which is a custom component within the meaning of Java Card specifications,

wherein said specific component comprises executable data which are executable in a same format as bytecode designed to personalize said instance and wherein after said instantiating and storing, the instance is configured to initiate the execution of a subset of said executable data by directly invoking said subset of executable data through an Application Programming Interface (API) under control of said instance to trigger execution of said executable data during runtime of said instance.

10. The secure element according to claim 9 , wherein the load file includes a Setup component containing an installation parameter which triggers an automatic installation of said instance by the loader, said Setup component being a custom component within the meaning of Java Card specifications.

11. The secure element according to claim 9 , wherein the load file includes a Security Domain component containing Security Domain parameters which are used by the loader to securely initialize a Security Domain to which the package is associated, said Security Domain component being a custom component within the meaning of Java Card specifications.

12. The secure element according to claim 9 , wherein the load file includes a Security component containing a security parameter which is used by the loader to verify the genuineness of the package or to decipher part of the load file, said Security component being a custom component within the meaning of Java Card specifications.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2022
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 058960/0713 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2020
From: PHAN, GUILLAUME CHI-DAN; MINETTE DE SAINT-MARTIN, XAVIER; VIENNE, NICOLAS
To: THALES DIS FRANCE SA
Reel/Frame 053697/0815 →
Priority Claims (1)
EP 17305731 · Jun 15, 2017 · regional
Continuity (1)
Related Publication 20200151365A1 · May 14, 2020