IP Library Granted Patent US 11,409,914
Granted Patent B2
US 11,409,914 · App. 16/765,199 · Granted Aug 9, 2022

Method of managing a tamper-proof device comprising several software containers

Inventors: Fabien Courtiade (Gemenos, FR); Florent Labourie (Gemenos, FR); Denis Dubois (Gemenos, FR); Syarif Ahmad (Gemenos, FR); Jianrong Yang (Gemenos, FR); Nopiga Pahala (Gemenos, FR); Shier Loon Sharon Yong (Gemenos, FR)
Assignee: THALES DIS FRANCE SAS
G06F21/71G06F21/77H04L63/0263H04L63/166H04W4/60H04W12/086H04W12/35H04W12/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,409,914
App. No.
16/765,199
Granted
Aug 9, 2022
Kind
B2
Abstract

The invention is a method for managing a tamper-proof device comprising a plurality of software containers and an operating system. The operating system is able to handle a set of communication protocols with external entities. The operating system accesses a pairing data in which each communication protocol of said set has been associated with a single software container and upon receipt of a message from one of the external entities, the operating system uses the pairing data to route the message to the software container associated with the communication protocol used to convey the message.

Claims (27)

1. A method for managing a secure element comprising a plurality of software containers and an operating system, said operating system being configured to handle a set of communication protocols with external entities,

wherein the operating system accesses a pairing data comprising a description of an association between each communication protocol of said set and a software container belonging to the plurality of software containers, each of said communication protocols being associated with a single software container in the secure element, and wherein upon receipt of a message from one of said external entities,

the operating system identifies a particular communication protocol used to convey the message then uses the particular communication protocol identified as a discriminator to route the message to a particular software container, of the plurality of software containers in the secure element, which is declared in the pairing data as being associated with the particular communication protocol, of the set of communication protocols, used to convey the message.

2. The method according to claim 1 , wherein each software container of said plurality of software containers in the secure element comprises a file which is targeted by said external entities by means of a same identifier.

3. The method according to claim 1 , wherein each software container of said plurality of software containers comprises a root file which is targeted by said external entities by means of a common identifier,

wherein said route targets said root file such that the message is routed to the root file a main security domain of said particular software container in the secure element.

4. The method according to claim 2 , wherein the operating system uses the pairing data to route the message only in case the message targets said common identifier.

5. The method according to claim 1 , wherein the plurality of software containers comprises both a security domain compliant with GlobalPlatform Card Specification standard and a Telecom profile compliant with GSMA SGP 0.22 RSP Technical Specification standard.

6. The method according to claim 1 , wherein the secure element is an embedded secure element, an integrated secure element, a secure enclave, a smart card or a Machine-To-Machine device.

7. The method according to claim 1 , wherein the set of communication protocols comprises T=0 or T=1 as defined by ETSI ISO7816-3 and at least one: SWP contactless type A, SWP contactless type B, APDU Gate or SPI.

8. A secure element comprising a hardware processor, a plurality of software containers and an operating system, said operating system being configured to handle a set of communication protocols with external entities,

wherein the operating system comprises a pairing data comprising a description of an association between each communication protocol of said set and a software container belonging to the plurality of software containers in the secure element, each of said communication protocols being associated with a single software container, and wherein

the operating system comprises a routing agent configured to, upon receipt of a message from one of said external entities, identify a particular communication protocol used to convey the message, then uses the particular communication protocol identified as a discriminator to route the message to a particular software container, of the plurality of software containers in the secure element, which is declared in the pairing data as being associated with the particular communication protocol, of the set of communication protocols, used to convey the message.

9. The secure element according to claim 8 , wherein each software container of said plurality of software containers comprises a file which is targeted by said external entities by means of a same identifier.

10. The secure element according to claim 8 , wherein each software container of said plurality of software containers comprises a root file which is targeted by said external entities by means of a common identifier,

wherein said route targets said root file such that the message is routed to the root file a main security domain of said particular software container managed my the secure element.

11. The secure element according to claim 9 , wherein the routing agent is configured to use the pairing data to route the message to the particular software container associated with the particular communication protocol used to convey the message only in case the message targets said common identifier.

12. The secure element according to claim 8 , wherein the plurality of software containers comprises both a security domain compliant with GlobalPlatform Card Specification standard and a Telecom profile compliant with GSMA SGP 0.22 RSP Technical Specification standard.

13. The secure element according to claim 8 , wherein the secure element is an embedded secure element, an integrated secure element, a secure enclave, a smart card or a Machine-To-Machine device.

14. The secure element according to claim 8 , wherein the set of communication protocols comprises T=0 or T=1 as defined by ETSI ISO7816-3 and at least one:

SWP contactless type A, SWP contactless type B, APDU Gate or SPI.

15. The secure element according to claim 8 , wherein the secure element is embedded in a host device.

16. A method for managing a secure element comprising a plurality of software containers and an operating system, said operating system being configured to handle a set of communication protocols with external entities,

wherein the operating system accesses a pairing data comprising a description of an association between each communication protocol of said set and a software container belonging to the plurality of software containers, each of said communication protocols being associated with a single software container in the secure element, and wherein upon receipt of a message from one of said external entities,

the operating system identifies a particular communication protocol used to convey the message then uses the particular communication protocol identified as a discriminator to route the message to a particular software container container, of the plurality of software containers in the secure element, which is declared in the pairing data as being associated with a particular communication protocol, of the set of communication protocols, used to convey the message

wherein each software container of said plurality of software containers comprises a root file which is targeted by said external entities by means of a common identifier,

wherein said route targets said root file such that the message is routed to the root file a main security domain of said particular software container in the secure element.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2022
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 058884/0238 →
CHANGE OF NAME Recorded Apr 7, 2021
From: GEMALTO SA
To: THALES DIS FRANCE SA
Reel/Frame 056748/0822 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2021
From: COURTIADE, FABIEN
To: THALES DIS FRANCE SA
Reel/Frame 055848/0882 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2021
From: GEMALTO PTE LTD
To: GEMALTO SA
Reel/Frame 055830/0925 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2021
From: YANG, JIANRONG; PAHALA, NOPIGA; YONG, SHIER LOON SHARON; AHMAD, SYARIF; LABOURIE, FLORENT
To: THALES DIS (SINGAPORE) PTE LTD (FORMERLY KNOWN AS GEMALTO PTE LTD)
Reel/Frame 055818/0959 →
Priority Claims (2)
EP 17306605 · Nov 21, 2017 · regional
EP 18305181 · Feb 21, 2018 · regional
Continuity (1)
Related Publication 20200279059A1 · Sep 3, 2020